Offensive Security Assessment

Hands-on application and infrastructure testing

I delivered application, Active Directory and infrastructure assessments, with source-code review, simulated phishing and payload work using LOLBins and DLL hijacking.

Growing MSSP with Offensive ServicesSecurity Engineer2 min read

I led and carried out solo and team engagements covering web applications, source-code review, internal and external infrastructure, Active Directory and cloud configuration. My involvement ran from scoping through technical testing, findings, reporting and client briefings.

I used OWASP Top 10 and MITRE ATT&CK to guide offensive testing methodology and risk assessment. The engagement type and client environment shaped which tests were relevant, across application weaknesses, infrastructure configuration and simulated attack activity.

My technical work included simulated phishing campaigns and payload/stager approaches for environments where PowerShell and Command Prompt were blocked. I worked with living-off-the-land binaries and DLL hijacking as part of that payload development, alongside the wider assessment work.

In one application assessment, I identified an exposure of personal and payment information in a client site. I documented the technical concern and actionable findings for the client's remediation decisions.

Closer to the work

Breadth of assessment

I worked on web applications, source-code review, internal and external infrastructure, Active Directory and cloud-configuration assessments, both alone and within a team. OWASP Top 10 and MITRE ATT&CK informed the testing methodology and risk assessment; I selected tests according to the environment and agreed scope.

Open this detail ↗
Simulation and payload work

I ran simulated phishing campaigns and worked on payload/stager approaches for target environments with PowerShell and Command Prompt blocked. My documented techniques include living-off-the-land binaries and DLL hijacking. These methods formed part of the assessment work and informed the findings I reported to clients.

Open this detail ↗
An application finding

I identified an exposure of personal and payment information during an application assessment and reported the technical concern with actionable findings. The report gave the client the technical findings needed to plan remediation.

Open this detail ↗

Skills established through this work

This work connects to

Offensive security

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.