Engagement scope for sonnycroco. Read-only.
target:
name: Nikos Pitsilishandle: sonnycrocoorigin: Greecerole: Security Researcherapproach:
language: pythondeps: noneoutputs: [tools, writeups]contact:
linkedin: https://www.linkedin.com/in/nikos-pitsilis/hackthebox: https://app.hackthebox.com/public/users/3376923in_scope:
published tools:
- id: h1grepsummary: grep for disclosed HackerOne reports from the terminalfilters: [keyword, severity, cwe, program, votes, bounty]edge: reverse-engineered GraphQL — encodes crash-avoidance rulesfor query shapes H1's endpoint rejectsinstall: pip install h1grepsocket: https://socket.dev/pypi/package/h1grep
- id: nuclei-indexsummary: map a CVE id to local nuclei-templates, emit the exactrate-limited nuclei commandtraits: [indexes-once, cached, "--json", "stdlib-only", "py>=3.9"]install: pip install nuclei-indexsocket: https://socket.dev/pypi/package/nuclei-indexwriteups:
- box: HTB Reactorchain: CVE-2025-55182 -> shell -> exposed Node.js debugger -> root
- box: HTB MonitorsFourchain: PHP type-juggling -> leaked hashes -> admin -> Cacti RCE in Docker -> exposed Docker API -> Windows host
- box: HTB Piratechain: pre-Windows 2000 machine account -> gMSA read -> WinRM foothold -> ligolo pivot -> NTLM relay/RBCD -> WEB01 local admin -> ForceChangePassword -> constrained-delegation SPN injection -> Domain Adminadjacent:
# cloud surface the tooling gets pointed at
- aws-ssm-secure-parameter-retrieval
- S3-filesize-checkerout_of_scope:
- anything not public on github.com/sonnycroco
