Map high-risk group privileges
Enumeration and relationship mapping identified a DNSAdmins privilege path in the controlled domain.
Evidence in the report
BloodHound and directory enumeration documented in the 24-page Active Directory assessment.Lawrence, Kansas · Open to offensive security opportunities
I’m Jacob Hill. I validate vulnerabilities, trace attack paths, build practical security tooling, and turn the evidence into reporting teams can act on.
Evidence-led work across
01 / SELECTED EVIDENCE
Filter by discipline or search for a technique, tool, or topic. Every item links to published work or source code.
No artifacts match that filter.
02 / ATTACK PATH CASE STUDY
Select a discipline to see how discovery becomes impact, evidence, and remediation. Every example comes from published TrillCyber work in a controlled or authorized environment.
Enumeration and relationship mapping identified a DNSAdmins privilege path in the controlled domain.
Evidence in the report
BloodHound and directory enumeration documented in the 24-page Active Directory assessment.03 / CAPABILITY + RESUME
I focus on reproducible evidence, business impact, and specific remediation—not tool output without context.
ASSESSMENT LOOP
Enumerate identities, services, permissions, trust relationships, and exposed application behavior.
Reproduce vulnerabilities in authorized environments and connect individual weaknesses into defensible attack paths.
Document evidence, impact, CVSS/CWE context, reproduction steps, and actionable remediation guidance.
Azure & Entra ID · Active Directory & Kerberos · Web & API · Network · AI/LLM · Containers
Nmap · Burp Suite · BloodHound · Impacket · CrackMapExec · Metasploit · Wireshark · RoadRecon · GraphRunner · SQLMap
Bash · Python · PowerShell · Terraform · Git · Docker · structured agent workflows
RESUME SNAPSHOT
Offensive Security Practitioner
Elevate Cyber · assessments spanning web, API, Active Directory, network, Azure cloud, and AI environments.
TrillCyber · technical research, assessment reports, lab write-ups, and open-source security projects.
Johnson County Community College · expected January 2027.
A current role-specific résumé is available on request.
04 / FREELANCE SERVICES
I take on carefully scoped, authorized projects where the objective, environment, and rules of engagement are clear. These services reflect work already documented in my reports and public projects.
WEB APPLICATIONS
Manual and tool-assisted validation of common web risks, with reproduction steps, impact, and remediation guidance.
Evidence: 29-page web assessmentNETWORK + IDENTITY
Scoped enumeration and attack-path validation across exposed services, permissions, Kerberos, and identity controls in authorized environments.
AI + LLM
Focused testing for prompt injection, insecure output handling, excessive agency, and related control gaps.
Evidence: 26-page AI assessmentSECURITY AUTOMATION
Bash or Python tooling that organizes repeatable enumeration, evidence collection, and reporting for defined security workflows.
Evidence: recon report generator05 / CONTACT
I’m open to select freelance engagements and offensive security opportunities where evidence, clear communication, and practical reporting matter.