About
This is a personal blog. My opinions are my own and not connected to any of the entities I have worked with or worked for. The materials presented here are for educational and research purposes only. Neither the administration of this server, the authors of this material, nor anyone else affiliated in any way will accept responsibility for your actions. Stay legal and ethical!
I am Lucian Nitescu, a cybersecurity specialist working in offensive security. This blog is where I write up what I break, build and learn.
What I do
Since 2017 I have been part of the BIT SENTINEL team, working on Red Teaming, Penetration Testing, Cyber Threat Intelligence (CTI) and Incident Response projects.
Community
Outside of client work, most of my time goes into security competitions — organising them, training for them, and writing the challenges:
- DefCamp CTF — I help organise the event.
- Romanian Cyber Security Challenge (ROCSC) — organiser and trainer since 2018.
- European Cyber Security Challenge (ECSC) 2019 — one of the coaches of the Romanian national team, which won that year.
- CyberEDU — I develop the exercises used in competitions such as the Romanian OSC, ROCSC, ECSC, DefCamp CTF and UNbreakable.
Bug bounty
The same curiosity pulled me into the bug bounty community, where I have found a few bugs and helped companies around the world secure their infrastructure:
…among others.
Certifications
OSWE, OSCP, OSWP, eCPPT v2 and eCPPT Gold.
Elsewhere
There is plenty more from before 2017, but you are not here for a full CV — and no, I have not listed everything just to make your OSINT easier.
These days I keep working across all of the above while expanding into newer fields. Your cybersecurity addict, essentially.
Some of the materials presented here need to be updated, some are left outdated on purpose, and some are kept purely for historical value. A lot has changed since 2018 — that evolution is inevitable.