About

About

whoami

I'm Mostafa Toumi, known online as EmSec. a cybersecurity practitioner focused on offensive security, penetration testing, and Active Directory attack research. I'm an HTB Content Creator, contributing original machine ideas and attack chains to the Hack The Box platform. I love simulating real-world attacks in my home lab, especially complex Active Directory environments where I can design, break, and harden infrastructure end-to-end. On this blog website, I publish writeups, security tutorials, and occasionally deep-dive walkthroughs. My weekly rhythm: every Friday and Sunday I sharpen my skills by practicing on Hack The Box.

HTB Contributions

Machines I’ve authored and contributed to on Hack The Box:

MachineDifficultyOSRelease Date
InfiltratorInsaneWindows2024-08-31
SightlessEasyLinux2024-09-07
TricksterMediumLinux2024-09-21
HazeHardWindows2025-03-29
ScepterHardWindows2025-04-19
RustyKeyHardWindows2025-06-28
MirageHardWindows2025-07-19
NanoCorpHardWindows2025-11-08
DevAreaMediumLinux2026-03-28
DanglingTreeMediumWindows2026-06-18

HTB Business:

MachineDifficultyOSRelease Date
EdgeAiMediumLinux2025-01-22

Core Expertise

Offensive Security & Penetration Testing

Active Directory attacks (Kerberoasting, RBCD, DACL abuse, ADCS ESC chains, Kerberos delegation), NTLM relay, DCOM lateral movement, GPO abuse, web application vulnerabilities (OWASP Top 10), and network protocol exploitation.

Networking

TCP/IP, routing protocols (OSPF, BGP), VLANs, firewall configuration, VPNs, and network security hardening.

Development & Scripting

Python3, Bash, C, HTML/CSS — used primarily for security tooling, CTF automation, and lab infrastructure. Experience with Scapy for packet-level scripting.

Operating Systems

Kali Linux, Ubuntu, Windows Server (2016/2019), Parrot OS, CentOS — comfortable administering and attacking both Linux and Windows environments.

Certifications


Profiles


What You'll Find on This Blog

  • HTB machine writeups and walkthroughs
  • Active Directory attack technique breakdowns
  • Security tooling and scripting
  • CTF challenge solutions
  • Linux and Windows lab setup guides

Get in Touch

Find me on:Email: Mostafatoumi0@gmail.com Have a question about a writeup or want to discuss a technique? Feel free to reach out.