// 17 Year Old Cybersecurity Specialist // Aspiring Red Teamer
MORGANBARBER
ABOUT ME
THINK LIKE
AN ATTACKER
ACT ETHICALLY
Attackers only need one way in. I train to find it first — legally, with permission, and with the goal of getting it closed.
I build offensive security skills the hands-on way: enumerating, exploiting and escalating privileges on HackTheBox lab machines, and writing my own tooling in Python. A background in defense — system hardening, network security and CyberPatriot — means I know what I'm up against and how findings get fixed. Everything I do is authorized and in scope.
READ FULL ABOUT ME →OFFENSIVESECURITY
The path an engagement takes, from agreeing the scope to handing over the fix.
PENETRATION TESTING
Scoped, methodical testing from first scan to final report, with findings written so they can actually be fixed.
$cat rules-of-engagement.txtRECON & ENUMERATION
Mapping the attack surface before touching it: ports, services, directories, subdomains and public information.
$nmap -sC -sV -p- $TARGETWEB EXPLOITATION
Finding and proving OWASP Top 10 flaws — injection, broken access control, authentication bypasses — with Burp Suite.
$ffuf -w common.txt -u http://$TARGET/FUZZPRIVILEGE ESCALATION
Turning a foothold into root or SYSTEM on Linux and Windows through misconfigurations, weak permissions and vulnerable services.
$sudo -l && ./linpeas.shVULNERABILITY ASSESSMENT
Auditing systems against frameworks like NIST — the work I did reviewing my school district's security.
$nmap --script vuln $TARGETOFFENSIVE TOOLING
Writing Python to automate the repetitive parts of an attack, like my own web vulnerability scanner.
$python3 scanner.py --target $TARGET
WORKEXPERIENCE
IT Specialist Intern
[2026]Completed a two-week internship auditing my local school district's cybersecurity using the NIST framework, working alongside mentors and networking with industry professionals.
STUDENT WORKER
[2024 - 2025]Developed and maintained a computer vision based system for identifying fish and fish habitats in underwater footage.
OFFENSIVETOOLKIT
- kali-linux (platform)
- nmap (recon)
- burp-suite (exploitation)
- metasploit (exploitation)
- python3 (scripting)
- bash (scripting)
- ffuf (recon)
- netcat (post-exploitation)
- sqlmap (exploitation)
- hashcat (post-exploitation)
- wireshark (recon)
- linpeas (post-exploitation)
- ■platform
- ■recon
- ■exploitation
- ■scripting
- ■post-exploitation
HACK THEBOX
Where the red-team skills get built: enumerating, exploiting and escalating on live lab machines.
~/htb/MorganBarber $ whoami --rank
Script Kiddie
10 points//hacking since Sep 2025
- Root / system owns
- 12
- User / foothold owns
- 14
- Challenges solved
- 8
- Sherlock solved24 tasks answered
- 1
- Satellite · challenges8/9
- DFIR · sherlocks1/156
// live from HackTheBox · refreshed every 6 hours
CAPTURETHE FLAG
Offense under a clock in CTFs, defense under a clock in CyberPatriot. Competitions are where the practice gets tested.
picoCTF(opens in a new tab)
Carnegie Mellon University
Carnegie Mellon's capture-the-flag competition: web exploitation, cryptography, reverse engineering, forensics and binary exploitation challenges.
Lockheed Martin CYBERQUEST
Lockheed Martin
Lockheed Martin's cyber competition for high school teams, solving security challenges alongside Lockheed Martin cyber professionals.
CyberPatriot(opens in a new tab)
Air & Space Forces Association
The national youth cyber defense competition: teams find and fix vulnerabilities in Windows and Linux systems under time pressure.
EDUCATIONHISTORY
- 2023 - 2027
ASSOCIATES OF GENERAL STUDIES / CYBERSECURITY CERTIFICATE
AIMS Community College
Hands-on cybersecurity program covering network defense, system hardening, threat analysis and incident response, delivered alongside industry certification tracks.
- 2022 - 2026
HIGH SCHOOL DIPLOMA
ST. VRAIN VALLEY SCHOOL DISTRICT
Concurrent enrollment coursework through PTECH with a focus on information security and information technology.
LATEST
BLOG
Analysis of emerging threats and operational techniques. Knowledge is the only sustainable advantage.