CTF Event BSides Limburg
Built the full infrastructure for a real-world Capture The Flag competition platform for BSides Limburg on a self-hosted Kubernetes cluster.
Try DemoRecent Applied Computer Science graduate specialized in Ethical Hacking, with a strong focus on IT infrastructure, cybersecurity, Active Directory security, and detection engineering. I enjoy turning complex security challenges into clean, reliable, and practical solutions.
A curious mind driven by technology, creativity, and a love for building things.
I am a recent graduate in Applied Computer Science, specialized in Ethical Hacking at Thomas More in Geel. My interests span offensive and defensive cybersecurity, with a particular focus on Active Directory security, detection engineering, vulnerability research, networking, and infrastructure. I enjoy understanding how systems fail, building practical solutions, and continuously expanding my technical knowledge.
Outside of technology, I enjoy photography, capturing unique moments and landscapes. I also have a strong interest in strategy and board games, which keep me thinking critically and working well with others.
Those interests, alongside my passion for IT, keep me curious, practical, and creative in the way I approach technical challenges.
Bachelor in Applied Computer Science
Specialization in Ethical Hacking
Thomas More, Geel Campus · 2023–2026 · Graduated 2026
Pentesting · Cybersecurity · Infrastructure · Kubernetes · Networking
Photography · Strategy & board games · Homelab tinkering · Building things
In 2026, I completed a full-time Cybersecurity Internship where I designed and delivered a production-grade detection engineering project around Active Directory.
Resilix · Cybersecurity Internship · 2026
For my internship at Resilix I built an end-to-end detection engineering project around Active Directory. I deployed a deliberately vulnerable AD lab (GOAD, Game of Active Directory) and a Microsoft Sentinel SIEM, then worked through a full attack chain from reconnaissance and enumeration all the way to domain compromise, so that every offensive technique could be paired with a reliable detection.
On the offensive side I executed and documented techniques such as Kerberoasting and AS-REP roasting, password spraying, NTLM relay and coercion (PetitPotam), LLMNR and NBT-NS poisoning, MITM6, BloodHound enumeration, AD CS abuse, LSASS and LSA secret dumping, DCSync, SMB-based code execution, and DNS A record injection (CVE‑2025‑33073). For each technique I engineered KQL analytics rules in Microsoft Sentinel, calibrated thresholds against baseline traffic to limit false positives, and verified that each rule fired against live attack traffic.
Alongside the detections I wrote a remediation guide covering hardening measures for every attack class, and delivered a full realization document as the formal internship deliverable.
This internship taught me that a detection only has value once it survives contact with real attack traffic and real background noise. Writing the queries was the easy part. The hard part was calibrating thresholds so a password spray rule alerts on an actual attack without drowning the analyst in failed logon noise from everyday users. Forcing myself to attack first and detect second changed how I think. I stopped writing rules for the textbook version of a technique and started writing them for the messy events that Windows actually logs. I also learned how much the deliverable itself matters, because a finding that a colleague cannot reproduce or remediate from my documentation simply does not exist. That is why I paired every detection with a concrete remediation and clear evidence.
A selection of projects I've built, contributed to, or am proud of. Click any card to read more.
Built the full infrastructure for a real-world Capture The Flag competition platform for BSides Limburg on a self-hosted Kubernetes cluster.
Try Demo
Presented an introduction to DLL injection in Windows, including a short live demonstration.
Designed and built a full Security Operations Center on a home lab with Security Onion, OPNsense, TLS inspection, and custom alerting software.
A custom Kubernetes monitoring dashboard with real-time cluster visibility, per-user isolated instance management, and automated Docker Compose-to-Kubernetes conversion.
Try Demo
A complete hosting platform with automated deployments, containerised services, and scalable infrastructure built from the ground up.
Try Demo
A secure NFC-based digital voting system with card authentication, a management dashboard, and real-time result tallying.
Try Demo
Self-hosted infrastructure running Proxmox with multiple VMs and containers, used for learning, experimentation, and as the backbone for other projects.
A demo project showing how REST APIs can be consumed in Windows PowerShell to retrieve real-time public transport data.
Designed and assembled a custom drone from scratch, including electronics, soldering, flight controller programming, and calibration.
A fully local security scanner that runs inside VS Code, active web scanning, a Burp-style HTTPS recording proxy, and static analysis (SAST/SCA/IaC/container) driven through a custom MCP server.
Select a domain below to explore my technical competences in depth.
This section documents my independent security research, conducted in my own time outside of coursework and employment. All findings are responsibly disclosed to vendors before publication.
A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME (Windows 64-bit) allows a local attacker to escalate privileges via DLL side-loading. The application loads DLL dependencies using the default Windows search order, which includes directories writable by unprivileged users. Because the application always executes with administrative privileges and performs no integrity or signature verification on loaded libraries, an attacker can plant a crafted DLL in a user-writable path that is searched before trusted system locations, causing attacker-controlled code to run with elevated privileges. Affects all versions up to and including 2.0.5.
Beyond the published CVE, I actively research Windows desktop software attack surfaces, focusing on privilege escalation chains, insecure service configurations, and DLL loading weaknesses in consumer applications.
Several additional findings are currently in active vendor coordination and have not yet been publicly disclosed. Details will be published here once the responsible disclosure process is complete.
All research follows responsible disclosure practices: vendors are contacted privately and given adequate time to patch before any public release.
Professional experience and the education that built my foundation in cybersecurity, infrastructure, networking, and development.
Resilix – Limburg
Specialization in Ethical Hacking · Thomas More, Geel Campus · Graduated 2026
Interested in cybersecurity, security engineering, or infrastructure? Feel free to reach out via email or connect with me on LinkedIn.
Interested in cybersecurity, security engineering, or infrastructure? Feel free to reach out via email or connect with me on LinkedIn.
Send an Email Download PGP