SurfaceScope — Enterprise Web Estate Monitoring
Architecture & lead • Uptime, TLS, exposure mapping, alerting
Led design for a platform monitoring large web estates: HTTP(S) checks, TLS expiry funnel, scheduled port & banner scans, keyword integrity, and exposure heatmaps. Produced actionable inventories for IT teams and proactive risk alerts.
Go + Python workersRedis queueDockerPostgreSQL
APT Infrastructure Simulation
Red Team • National-level engagement (confidential)
Planned and executed an APT-style adversary simulation against a critical infrastructure target. Full lifecycle: recon → initial access → persistence → objective completion. Exposed critical network segmentation failures that triggered emergency patching at the national level.
Adversary EmulationC2 InfrastructureEDR EvasionMITRE ATT&CK
Active Directory Attack Chain Research
Research • AD Exploitation
Mapped a full Domain Admin compromise path using Kerberoasting, Pass-the-Hash, DCSync, and ACL-based privilege escalation. Full attack chain documented; BloodHound graph shared with defensive teams for detection engineering. Findings remediated pre-exploitation.
BloodHoundKerberosACL AbuseDCSync
Havoc C2 — Custom Modules & Evasion R&D
R&D lab • Tradecraft hardening
Implemented custom agent functionality and OPSEC improvements: staged loaders, sleep masking, indirect syscall prototypes. Integrated operator helpers for credential dumping, enumeration, and lateral movement.
C/C++WinAPIEDR TestingBOF
Web & API Pentests — Fintech & SaaS
Multiple assessments • International clients
Found and documented impactful issues: IDOR in billing APIs, SSRF in file import, auth bypass in legacy endpoints, and misconfigured S3 bucket policies. Provided reproducible PoCs and developer-friendly remediation guidance.
Burp Suite ProOWASP Top 10Threat Modeling
Spear-Phishing Campaign → MFA Rollout
Social Engineering • Private (confidential)
Designed and executed a targeted spear-phishing campaign against high-privilege accounts as part of a red team engagement. Human risk assessment directly drove enterprise-wide MFA implementation across sensitive systems.
GoPhishPretextingHuman Risk Quantification