jean@heretek:~#

I’m Jean Romero (aka Heretek), an OSCP+ certified Cyber Field Engineer at Pentera. I made the jump from the SOC to offensive security, and I still break boxes every hour I’m not at work.

This is where I document what I learn: the boxes I root, the techniques I pick up, the mistakes I make, and the methodology that got me through OSCP+.

Security+ | CEH | eJPT | eCPPT | OSCP+ ✅ June 2026 | 49+ boxes rooted

Mission Complete: I'm a Cyber Field Engineer at Pentera

Yesterday was my first day as a Cyber Field Engineer at Pentera. From googling ‘what is an IP address’ to getting paid to run offense: every Journey post on this blog was building toward this one.

August 25, 2026 · 3 min

I Passed OSCP+ — What Actually Got Me There

I earned OSCP+ on June 18, 2026. No exam spoilers — just the prep, the grind, and what actually worked for a working SOC analyst who not long ago was googling ‘what is an IP address.’

June 20, 2026 · 5 min

HTB Certified Writeup — Shadow Credentials, ACL Chains & ADCS ESC9 (2026)

Assumed breach AD box. WriteOwner abuse on a group, double shadow credentials chain, and ADCS ESC9 certificate abuse to Domain Admin.

March 28, 2026 · 6 min

AD Attack Methodology — From Zero to Domain Admin

Step-by-step methodology for attacking Active Directory — the chain I follow on every AD box.

March 24, 2026 · 11 min

BloodHound — Setup and Usage Guide

How I set up and use BloodHound CE for AD enumeration — collection, import, and finding attack paths.

March 24, 2026 · 6 min

From SOC Graveyard Shifts to Pentesting — Why I'm Doing This

The story behind the career switch. Graveyard shifts, 10-hour lab days, and why I won’t stop until OSCP is done.

March 24, 2026 · 3 min

HTB Active Writeup — Kerberoasting & GPP Passwords (2026)

My first AD box ever. Null session on SMB → GPP password in SYSVOL → Kerberoasting the Administrator → Domain Admin.

March 24, 2026 · 2 min

HTB Blackfield Writeup — LSASS Dump & VSS Shadow Copies (2026)

Hard AD box. AS-REP Roasting → BloodHound → ForceChangePassword → lsass.DMP → SeBackupPrivilege → VSS snapshot → NTDS.dit → Domain Admin.

March 24, 2026 · 4 min

HTB Forest Writeup — AS-REP Roasting, BloodHound & DCSync (2026)

Second AD box. AS-REP Roasting with no creds, BloodHound attack path through 5 nested groups, ACL abuse to DCSync.

March 24, 2026 · 3 min

HTB Monteverde Writeup — Azure AD Connect Exploit (2026)

Active Directory box — password spraying → Azure AD Connect credential extraction → Domain Admin.

March 24, 2026 · 2 min