SKIP TO CONTENT

// 17 Year Old Cybersecurity Specialist // Aspiring Red Teamer

MORGANBARBER

ETHICAL HACKING // RED TEAMING // PENETRATION TESTING // CAPTURE THE FLAG // HACKTHEBOX // SYSTEM HARDENING // COMPTIA SECURITY+ // ETHICAL HACKING // RED TEAMING // PENETRATION TESTING // CAPTURE THE FLAG // HACKTHEBOX // SYSTEM HARDENING // COMPTIA SECURITY+ // ETHICAL HACKING // RED TEAMING // PENETRATION TESTING // CAPTURE THE FLAG // HACKTHEBOX // SYSTEM HARDENING // COMPTIA SECURITY+ // ETHICAL HACKING // RED TEAMING // PENETRATION TESTING // CAPTURE THE FLAG // HACKTHEBOX // SYSTEM HARDENING // COMPTIA SECURITY+ //

ABOUT ME

THINK LIKE
AN ATTACKER
ACT ETHICALLY

Attackers only need one way in. I train to find it first — legally, with permission, and with the goal of getting it closed.

I build offensive security skills the hands-on way: enumerating, exploiting and escalating privileges on HackTheBox lab machines, and writing my own tooling in Python. A background in defense — system hardening, network security and CyberPatriot — means I know what I'm up against and how findings get fixed. Everything I do is authorized and in scope.

READ FULL ABOUT ME →
CAPABILITIES

OFFENSIVESECURITY

The path an engagement takes, from agreeing the scope to handing over the fix.

  1. PENETRATION TESTING

    Scoped, methodical testing from first scan to final report, with findings written so they can actually be fixed.

    $cat rules-of-engagement.txt
  2. RECON & ENUMERATION

    Mapping the attack surface before touching it: ports, services, directories, subdomains and public information.

    $nmap -sC -sV -p- $TARGET
  3. WEB EXPLOITATION

    Finding and proving OWASP Top 10 flaws — injection, broken access control, authentication bypasses — with Burp Suite.

    $ffuf -w common.txt -u http://$TARGET/FUZZ
  4. PRIVILEGE ESCALATION

    Turning a foothold into root or SYSTEM on Linux and Windows through misconfigurations, weak permissions and vulnerable services.

    $sudo -l && ./linpeas.sh
  5. VULNERABILITY ASSESSMENT

    Auditing systems against frameworks like NIST — the work I did reviewing my school district's security.

    $nmap --script vuln $TARGET
  6. OFFENSIVE TOOLING

    Writing Python to automate the repetitive parts of an attack, like my own web vulnerability scanner.

    $python3 scanner.py --target $TARGET
PROFESSIONAL EXPERIENCE

WORKEXPERIENCE

IT Specialist Intern

[2026]
@SVVSD Innovation Center

Completed a two-week internship auditing my local school district's cybersecurity using the NIST framework, working alongside mentors and networking with industry professionals.

STUDENT WORKER

[2024 - 2025]
@ST. VRAIN VALLEY SCHOOL DISTRICT

Developed and maintained a computer vision based system for identifying fish and fish habitats in underwater footage.

ARSENAL

OFFENSIVETOOLKIT

morgan@kali: ~/arsenal
ls --color
  • kali-linux (platform)
  • nmap (recon)
  • burp-suite (exploitation)
  • metasploit (exploitation)
  • python3 (scripting)
  • bash (scripting)
  • ffuf (recon)
  • netcat (post-exploitation)
  • sqlmap (exploitation)
  • hashcat (post-exploitation)
  • wireshark (recon)
  • linpeas (post-exploitation)
  • ■platform
  • ■recon
  • ■exploitation
  • ■scripting
  • ■post-exploitation
OFFENSIVE PRACTICE

HACK THEBOX

Where the red-team skills get built: enumerating, exploiting and escalating on live lab machines.

@MorganBarber(HackTheBox profile, opens in a new tab)

~/htb/MorganBarber $ whoami --rank

Current rank

Script Kiddie

Next: Hacker31%

10 points//hacking since Sep 2025

Root / system owns
12
User / foothold owns
14
Challenges solved
8
Sherlock solved24 tasks answered
1
Where I've been solving
  • Satellite · challenges8/9
  • DFIR · sherlocks1/156

// live from HackTheBox · refreshed every 6 hours

COMPETITIONS

CAPTURETHE FLAG

Offense under a clock in CTFs, defense under a clock in CyberPatriot. Competitions are where the practice gets tested.

01

picoCTF(opens in a new tab)

Carnegie Mellon University

Carnegie Mellon's capture-the-flag competition: web exploitation, cryptography, reverse engineering, forensics and binary exploitation challenges.

Jeopardy-style CTF
02

Lockheed Martin CYBERQUEST

Lockheed Martin

Lockheed Martin's cyber competition for high school teams, solving security challenges alongside Lockheed Martin cyber professionals.

Capture the flag
03

CyberPatriot(opens in a new tab)

Air & Space Forces Association

The national youth cyber defense competition: teams find and fix vulnerabilities in Windows and Linux systems under time pressure.

Cyber defense
EDUCATION

EDUCATIONHISTORY

  1. 2023 - 2027

    ASSOCIATES OF GENERAL STUDIES / CYBERSECURITY CERTIFICATE

    AIMS Community College

    Hands-on cybersecurity program covering network defense, system hardening, threat analysis and incident response, delivered alongside industry certification tracks.

  2. 2022 - 2026

    HIGH SCHOOL DIPLOMA

    ST. VRAIN VALLEY SCHOOL DISTRICT

    Concurrent enrollment coursework through PTECH with a focus on information security and information technology.

0x002 // PROJECTS

SELECTED WORK

  1. // FULL STACK · IN PROGRESS

    psti.io

    A custom pastebin designed with security in mind.

  2. // WEB DESIGN · COMPLETED

    morganbarber.me

    Modern portfolio app built with Next and Tailwind.

LATEST
BLOG

Analysis of emerging threats and operational techniques. Knowledge is the only sustainable advantage.

LET'S WORK TOGETHER