Tim Sonner
Cybersecurity · Systems · Security Tooling · AI Agent Integration
GitHub · Gists · LinkedIn · Email · timsonner.com
Summary
Security-focused builder and practitioner working across offensive security research, Windows/Active Directory administration, Linux systems, and practical automation. Comfortable shipping tooling end-to-end — from lab exploit paths and recon utilities to MCP servers that let AI agents operate safely in real environments.
Hands-on across Linux and Windows, with a strong bias toward reproducible labs, clear write-ups, and working proofs of concept over slideware.
Certifications
- CompTIA Security+
- CompTIA Network+
- CompTIA Linux+
Core skills
Security & offensive research
- Active Directory attack paths: enumeration, Kerberoasting, pass-the-hash, privilege escalation
- Web/app exploitation labs: LFI, PHP filter chains, RCE, disabled_functions bypasses
- Malware research & tradecraft notes: process/DLL injection, payload encoding, EDR-aware experiments
- CVE research and lab PoCs
- Password spraying / auth testing tooling
- Client-side recon helpers (DNS, WHOIS/RDAP, headers, framing/CSP checks)
Linux systems & networking
- Daily-driver and lab Linux administration, hardening, and troubleshooting
- Networking fundamentals aligned with CompTIA Network+ and Linux+ skill areas
- Virtualization and homelab ops: Proxmox, KVM/libvirt, networking failover (Ethernet/Wi-Fi)
- Containers and service isolation (Docker, Kali-in-Docker workflows)
- Shell automation, package/driver recovery, ZFS and system tuning notes
Windows & Active Directory
- AD lab builds and domain administration
- PowerShell for local/AD account management, diagnostics, and security event work
- Windows internals exploration: services, injection patterns, admin automation
- Remote access and tunnel troubleshooting in mixed environments
AI agents, MCP & automation
- Model Context Protocol (MCP) servers and VS Code-oriented templates
- Agent skills / orchestration patterns for security and ops workflows
- Kali-oriented agent tooling and Docker-backed execution environments
- Bridges and gateways for agent collaboration (chat/signal-style integrations)
- Computer-use / desktop-agent prototypes
Languages & platforms
- Languages: Go, Python, PowerShell, C# / .NET, JavaScript/TypeScript, Shell
- Platforms: Linux, Windows Server / AD, Docker, Proxmox
- Web: Jekyll, vanilla JS, SCSS, small full-stack utilities
- Security stack: Nmap, Metasploit, Impacket-style AD tradecraft, custom PoCs
Selected work (from public repos)
Security tooling & research
- autonomous-pentest-agent — autonomous pentest agent pattern with Kali Docker + MCP / Copilot CLI control plane
- kali-mcp-server / dotnet-docker-kali-mcp-server — run security tooling inside Kali containers via MCP
- React2Shell-CVE-2025-55182 — CVE lab setup and PoC work
- CVE-2025-49144-Research — vulnerability research notes/code
- encode-decode-payloads — payload encoding/decoding utilities (PowerShell)
- svg-image-javascript-malware — SVG/JS payload generation research
- multi-vpn-spray — multi-VPN password spray helper
- winring0-research — low-level Windows research (C#)
- red-team-tools-usage — red-team tool usage notes
AI agents & developer tooling
- mcp-vscode-template — reusable MCP server template for VS Code
- agent-skills — packaged agent skills for security/ops tasks
- docker-mcp-manager — Docker-oriented MCP management
- dotnet-mcp-skeleton-project-vscode — .NET MCP skeleton for VS Code
- opencode-plugins / opencode-agents — OpenCode agent/plugin work
- antigravity-slack-gateway, antigravity-signal-bridge, antigravity-hermes-collab — agent collaboration bridges
- claude-screen-agent — Wayland desktop stream prototype for agent computer-use
Systems, AD & infrastructure
- admin-powershell — AD/sysadmin PowerShell: accounts, diagnostics, security events, M365 odds and ends
- proxmox-debian-laptop-install-scripts — Proxmox on laptop with Ethernet/Wi-Fi switching
- pangolin-proxmox-guacamole-runbook — remote access / homelab runbook
- Blog lab notes: AD DC setup in VirtualBox, TryHackMe AD and Linux privesc paths
Public site & client-side tools
- timsonner.github.io — cybersecurity blog plus browser tools:
- interactive recon terminal
- local email header/body parser
- proxy / X-Frame inspection browser
- in-browser Python (Pyodide)
Technical writing
Lab and research write-ups covering:
- TryHackMe attack paths (Blue, Ice, Cheese CTF, Soupedecode, and others)
- Active Directory lab construction
- Go-based malware/injection research notes
- Exploit PoC translation and payload development
- Practical Linux/Windows ops snippets via Gists
Contact
- Email: tim@timsonner.com
- GitHub: github.com/timsonner
- Gists: gist.github.com/timsonner
- LinkedIn: linkedin.com/in/timsonner
- Site: timsonner.com