Rooted
Verified credential - AccessCurrent

BM::m3y4

Yash

@m3y4 · Operator · India

Offsec Engineer

EnglishHindi
ACCESS2RANK
RANK
2 · Operator
Verified points
399
Hack The Box
Script Kiddie · 31 owns
Issued
2026-08-24
Valid until
2027-08-27
Standing
36 of 132
Certifications held
Security+
Demonstrated knowledge

Skills

Every channel comes from unique Daily answers. Difficulty and sustained evidence move the signal; repeats never do.

15unique answers
Strongest signal · Active Directory · 51/100 · Operational
WEB

Web & AppSec

40/100
Operational100% accuracy3/3 correctMedium clearedsteady

22 signal points to Strong · early signal

NETWORK

Networks & protocols

36/100
Developing67% accuracy2/3 correctHard clearedsteady

4 signal points to Operational · early signal

AD

Active Directory

51/100
Operational67% accuracy6/9 correctMedium cleared↑ improving

11 signal points to Strong · growing evidence

Annex — how this was earned

13 entries. Nothing scores without one.

399 total
Credentials324

2 entries

Quizzes and labs75

11 entries

13 ledger entries back these totals. The full derivation is visible to the holder and to Rooted review.

Where your proof lands

Derived from what each verified ledger entry actually covers. You have nothing in cryptography, forensics & dfir, recon & osint, code & tooling, cloud & containers.

  • Networks & protocols221
    Evidence
    Security +
    2153481
    A workstation sends hundreds of long, unique TXT queries under one domain every 30 seconds
    First night on a hospital SOC: a scan shows TCP 443 open on the patient portal. Which serv
  • Active Directory162
    Evidence
    SMB signing is optional on several servers and LDAP signing/channel binding is not enforce
    A backup operators group unexpectedly holds Replicating Directory Changes and Replicating
    2153481
    A typo in a network path makes Windows ask the local network for the name and an attacker
    A legacy application server is marked TRUSTED_FOR_DELEGATION and domain administrators per
    BloodHound shows Helpdesk-L1 has GenericAll over the Server Admins group, although the tea
    A service account has an SPN and a weak password. Which common attack tries to crack its s
  • Web & AppSec16
    Evidence
    A page on another site can submit a form that changes your email while you are logged in.
    An image-from-URL feature can fetch http://127.0.0.1/admin from the server. What is this?
    During an authorised pentest, GET /api/invoices/184 returns your invoice. Changing 184 to
  • Cryptographyno proof yet
  • Forensics & DFIRno proof yet
  • Recon & OSINTno proof yet
  • Code & toolingno proof yet
  • Cloud & containersno proof yet

The road to Hacker

501 pts short

Everything below is priced. Pick the cheapest one and the gap closes.

  1. Claim a CVE

    Any published advisory with your name on the credit line.

    +260
    points
    52% of the gap
  2. Connect TryHackMe

    Points and completed rooms.

    +180
    points
    36% of the gap
  3. Connect GitHub

    Public tooling, exploits and the code you shipped.

    +160
    points
    32% of the gap
  4. Clear another lab

    11 lab entries scored. 1,925 points left before the lab ceiling.

    +60
    points
    12% of the gap
  5. Publish a write-up

    Explain the bug, impact and fix. Peer-reviewed write-ups score after approval.

    +180
    points
    36% of the gap
  6. Submit a vulnerability report

    A confirmed low, medium, high or critical report is the cleanest path up the ladder.

    +160
    points
    32% of the gap

Not one figure above was typed in by m3y4.

Read how points are earned
Get your credential
Rank requirements beyond points
  • Rank 4+ - One verified credential or one confirmed report
  • Rank 7+ - One confirmed report or one credited CVE
  • Rank 9+ - A credited CVE at CVSS 9.0+, or three critical confirmed reports