Offensive security
Assess the attack paths that matter to the client.
Assess web applications, on-premises Active Directory, cloud configurations and physical boundaries. Follow on-site assessments that exposed guest data and tested routes to authenticated internal access, alongside threat-informed scoping, application findings, payload work and reconnaissance automation.
All cards in this section are viewed.
Guest data exposure and authenticated internal access
Physical Security AssessmentAcross assessments, we exposed guest data through weak Wi-Fi segmentation, demonstrated employee QR-code interaction and gained authenticated internal access.
Read the storyTesting application exposure and restricted Windows environments
Offensive Security AssessmentI assessed applications, Active Directory and infrastructure, and developed payload approaches for restricted Windows environments.
Read the storyFrom external attack surface to assumed-breach testing
Offensive Scoping & Threat ModellingI used external discovery and internal assessments to shape testing priorities around email, Active Directory, critical systems and the telemetry needed to investigate an intrusion.
Read the storyFrom an organisation name to repeatable reconnaissance
Offensive Security AutomationI built a tool that started with an organisation name and automated reconnaissance and lightweight checks, making repeated assessment preparation reusable.
Read the storyTechnical oversight of 50+ monthly offensive engagements
Offensive Security LeadershipI oversaw a team portfolio of more than fifty offensive engagements per month, reviewing technical delivery and reports while helping clients act on the findings.
Read the storySkills used in these cases