// offensive security portfolio

Benjamin Spoolstra

Aspiring offensive security professional specializing in web application and internal network penetration testing across Active Directory and cloud environments. Documenting the labs, CTFs, and projects along the way.

bash — benjamin-spoolstra@vps
$ whoami
pentester, ctf player, security researcher
$ cat focus.txt
web app + internal network pentesting, AD, cloud
$ cat goals.txt
red teaming, adversary emulation, CPTS
$
Top 10%
Cylab Academy 2026
+30%
Vulns Found vs Baseline
-28%
Attack Surface (STIG)
100+
Attacks Detected (SOC)
02

Writeups & Labs

Full collections on GitHub

03

Certifications

[✓]
PenTest+
CompTIA
[✓]
CySA+
CompTIA
[✓]
Security+
CompTIA
[✓]
Network+
CompTIA
[✓]
A+
CompTIA
[✓]
AZ-900
Microsoft Azure
[✓]
AWS CCP
Amazon Web Services
04

Roadmap

// upcoming certifications

  • CWES
    HackTheBox Certified Web Exploitation Specialist
    In progress
  • CPTS
    HackTheBox Certified Penetration Testing Specialist
    Planned

// planned projects

  • HashCat Cracking Rig with NVIDIA GPUs
    Centralized Location for Password and Hash Cracking
    Planned
  • Autonomous AI Penetration Testing Framework
    AI Penetration Testing Framework to Speed up Bug Bounty Hunting
    Planned
05

About

I'm an aspiring offensive security professional with about a year of technical experience in web application and internal network penetration testing across Active Directory and cloud environments. My background spans technical support in higher education and pentest engagements for finance and healthcare clients at a growing cybersecurity firm.

I care about understanding security tools to a deep level rather than running them with default settings, so I can conduct quiet, deliberate testing that emulates real, advanced adversaries. I'm not here to check a compliance box. I want to help organizations meaningfully strengthen their true security posture by finding gaps before real attackers do.

Currently working toward red teaming and adversary emulation, with emerging interest in IoT/hardware security, low-level programming, and malware reverse engineering. B.S. in Cybersecurity at Grand Canyon University (President's List), expected graduation April 2027.

  • Web App Pentesting████████░░
  • Network Pentesting████████░░
  • Active Directory███████░░░
  • Cloud (AWS / Azure)███████░░░
  • Blue Team / SIEM██████░░░░
  • GRC / Risk Mgmt██████░░░░