focus area
Offensive Security
Security proves itself under fire. I test it the way real attackers operate: methodically, patiently, and with one goal, to find the paths that work in reality. Over six years I have led more than 150 tests, from a targeted web assessment to a full-scope red team operation.
What this covers
- Full-scope red teaming & adversary emulation
- Social engineering, phishing & physical access
- OSINT-driven reconnaissance (GOSINTCon speaker, 2023)
- Web & API testing, Active Directory, assumed breach
- Threat-led along MITRE ATT&CK, TIBER-EU / TLPT
- Clear reports, prioritized findings, retests
My focus is full-scope red teaming assessments and social engineering. These operations simulate a real adversary, for example APTs and nation-state threat actors, across the whole attack path: from reconnaissance through initial access to the actual objective. What gets tested is not only the technology, but the entire chain of people, processes and detection capabilities.
It almost always starts with OSINT. A company’s digital footprint often decides which paths are realistically open, long before an attacker’s first packet reaches the network. I spoke on exactly this at the German OSINT Conference (GOSINTCon) in November 2023, in a talk titled „From Shadows to Strategies: OSINT im Vorfeld von proaktiven Red-Teaming-Maßnahmen“, explaining how I operate as a hacker, how I prepare red teaming assessments and the patterns that keep standing out to me.
Alongside my red teaming assessments I test web applications and APIs, internal networks and Active Directory structures, and physical entry paths. The goal is rarely just surfacing vulnerabilities, but a full picture that includes detection and response capabilities.
For this I use a state-of-the-art technical toolkit, such as C2 infrastructure, alongside my own tooling and malware development to bypass common defenses.
The real insight from these engagements is rarely whether and how an attacker gets in. For most organizations the bigger challenge is usually reliable detection, especially against an attacker under no time pressure who moves quietly. And the true maturity of a defensive setup only shows afterwards, in the response: containing an incident cleanly and durably evicting the attacker succeeds to differing degrees in practice. That gap is what I make visible.
Methodically I work along established frameworks: MITRE ATT&CK, TIBER-EU and TLPT for threat-led testing, OWASP on the web, complemented by PTES and OSSTMM. It is backed by relevant GIAC certifications, among them GXPN, GRTP, GWAPT, GOSI and GDAT.
Selected engagements
Full-scope red team, financial sector
An interesting OSINT finding and a follow-up targeted spear-phishing campaign yielded initial access, without standing out or tripping an alert. From there, weeks of quiet movement up to domain-wide privileges and access to a business-critical system (a critical and important function). The core finding was not the break-in itself, but that the access stayed undetected until disclosure.
Social engineering & physical access, critical infrastructure
A combination of open-source reconnaissance (OSINT), a targeted on-site pretext and physical entry all the way into the server room. The engagement showed how technical controls are undone when the human factor is used as the lever to take a shortcut.
A web flaw as a bridgehead, defense supplier
From a single vulnerability in an externally exposed web application in a lightly monitored DMZ, through lateral movement, to the internal crown jewels. This engagement proved that an overlooked web vulnerability in a seemingly unimportant system can become the way into the internal network.