Engagement scope for sonnycroco. Read-only.
target:
name: Nikos Pitsilis
handle: sonnycroco
origin: Greece
role: Security Researcher
approach:
language: python
deps: none
outputs: [tools, writeups]
contact:
linkedin: https://www.linkedin.com/in/nikos-pitsilis/
hackthebox: https://app.hackthebox.com/public/users/3376923
in_scope:
published tools:
- id: h1grep
summary: grep for disclosed HackerOne reports from the terminal
filters: [keyword, severity, cwe, program, votes, bounty]
edge: reverse-engineered GraphQL — encodes crash-avoidance rules
for query shapes H1's endpoint rejects
install: pip install h1grep
socket: https://socket.dev/pypi/package/h1grep
- id: nuclei-index
summary: map a CVE id to local nuclei-templates, emit the exact
rate-limited nuclei command
traits: [indexes-once, cached, "--json", "stdlib-only", "py>=3.9"]
install: pip install nuclei-index
socket: https://socket.dev/pypi/package/nuclei-index
writeups:
- box: HTB Reactor
chain: CVE-2025-55182 -> shell -> exposed Node.js debugger -> root
- box: HTB MonitorsFour
chain: PHP type-juggling -> leaked hashes -> admin -> Cacti RCE in Docker -> exposed Docker API -> Windows host
- box: HTB Pirate
chain: pre-Windows 2000 machine account -> gMSA read -> WinRM foothold -> ligolo pivot -> NTLM relay/RBCD -> WEB01 local admin -> ForceChangePassword -> constrained-delegation SPN injection -> Domain Admin
adjacent:
# cloud surface the tooling gets pointed at
- aws-ssm-secure-parameter-retrieval
- S3-filesize-checker
out_of_scope:
- anything not public on github.com/sonnycroco
