Offensive security
Think like an adversary
Assess external attack surfaces, on-prem Active Directory, web applications and cloud configurations. Explore assumed-breach testing, physical assessments and threat modelling that connects an intrusion path to the controls a client needs.
All cards in this section are viewed.
Hands-on application and infrastructure testing
Offensive Security AssessmentI delivered application, Active Directory and infrastructure assessments, with source-code review, simulated phishing and payload work using LOLBins and DLL hijacking.
Read the storyScoping assessments around the client's threats
Offensive Scoping & Threat ModellingI scoped external, internal and assumed-breach assessments around attack-surface discovery, Active Directory, email defences and EDR/network visibility, informed by incident-response work.
Read the storyTest physical and network boundaries at client workplaces
Physical Security AssessmentI tested hotel guest/TV network segmentation, restricted-area access and employee QR scenarios, including Raspberry Pi placement tests for a controlled C2 connection.
Read the storyTechnical oversight of an offensive security service
Offensive Security LeadershipOversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.
Read the storyOrganisation-led reconnaissance automation
Offensive Security AutomationI built an organisation-name-driven reconnaissance tool for discovery and lightweight checks, alongside offensive automation in Python, Bash and PowerShell.
Read the storyFollow a skill into the work