Benjamin Spoolstra
Aspiring offensive security professional specializing in web application and internal network penetration testing across Active Directory and cloud environments. Documenting the labs, CTFs, and projects along the way.
Projects
Bug Bounty VPS
OffensiveA hardened Kali Linux VPS built from scratch as a dedicated remote platform for bug bounty hunting, penetration testing, and CTFs.
Azure Cloud SOC Home Lab
DefensiveA cloud-based SOC built from scratch in Azure with Terraform with an attacker VM, a misconfigured victim VM, and a Wazuh 4.14 SIEM, which are all used to run a full attack-and-detect cycle with custom detection rules mapped to the MITRE ATT&CK framework.
Azure Risk Management & DISA STIG Hardening Lab
GRCI built a cloud-based GRC lab executing the full NIST RMF lifecycle against an Active Directory domain hosted in Azure. I ran a baseline scan using Nessus and the SCAP Security Compliance Checker (SCC) to enumerate existing vulnerabilities and then hardened the domain with the PowerSTIG utility and manual GPO hardening. Finally, I mapped each control applied to the NIST 800-171 and CMMC 2.0 Level 2 controls.
Writeups & Labs
Forge Coupon
hardAn OWASP Juice Shop web exploitation challenge where a player must forge arbitrary discount coupons by reverse-engineering a z85-encoded coupon structure.
Quizploit: Binary Analysis
easyA CyLab Academy CTF challenge where a stack buffer overflow vulnerability gates a flag behind 13 questions about the executable's structure and mitigations. It can be solved by static analysis with file, checksec, and nm utilities in Linux.
OverTheWire: Bandit (0–33)
easyA series of Linux command line challenges with 34 levels in total. Challenges cover Linux fundamentals, from file system navigation and data encodings to networking, SSH keys, cron-based privilege escalation, and git forensics.
Gandalf Prompt Injection
hardThis challenge is a set of 7 levels in Lakera's AI Gandalf chatbot, which is designed to never reveal a password. Each level gets progressively harder with more safeguards put in place. The goal is to bypass the safeguards and retrieve the hidden password using any means necessary.
Full collections on GitHub
CTF Writeups
CloudGoat, CyLab Academy, GOAD, Lakera AI, OWASP Juice Shop, OverTheWire
Lab Writeups
TryHackMe, HackTheBox, PortSwigger, HackSmarter
CTF Resources
Curated tooling and references by category
Certification Resources
Everything used to pass Sec+, CySA+, PenTest+, and more
Cyber Career Resources
Hub for all cybersecurity career resources
Red Team Resources
Collection of tools and cheat sheets for red teaming engagements
Certifications
Roadmap
// upcoming certifications
- CWESHackTheBox Certified Web Exploitation SpecialistIn progress
- CPTSHackTheBox Certified Penetration Testing SpecialistPlanned
// planned projects
- HashCat Cracking Rig with NVIDIA GPUsCentralized Location for Password and Hash CrackingPlanned
- Autonomous AI Penetration Testing FrameworkAI Penetration Testing Framework to Speed up Bug Bounty HuntingPlanned
About
I'm an aspiring offensive security professional with about a year of technical experience in web application and internal network penetration testing across Active Directory and cloud environments. My background spans technical support in higher education and pentest engagements for finance and healthcare clients at a growing cybersecurity firm.
I care about understanding security tools to a deep level rather than running them with default settings, so I can conduct quiet, deliberate testing that emulates real, advanced adversaries. I'm not here to check a compliance box. I want to help organizations meaningfully strengthen their true security posture by finding gaps before real attackers do.
Currently working toward red teaming and adversary emulation, with emerging interest in IoT/hardware security, low-level programming, and malware reverse engineering. B.S. in Cybersecurity at Grand Canyon University (President's List), expected graduation April 2027.
- Web App Pentesting████████░░
- Network Pentesting████████░░
- Active Directory███████░░░
- Cloud (AWS / Azure)███████░░░
- Blue Team / SIEM██████░░░░
- GRC / Risk Mgmt██████░░░░