Independent penetration tester available for direct engagements, overflow, and subcontract work — remote-first, with travel available Australia-wide.
Primary focus. Manual testing for OWASP Top 10 and beyond — auth flaws, IDOR, injection chains, and business logic vulnerabilities.
Perimeter assessments against internet-facing infrastructure and services.
Remote or on-site internal assessments — privilege escalation, lateral movement, and domain compromise paths.
Android application security testing. iOS available on request.
AWS and Azure configuration reviews — IAM misconfigurations, exposed storage, and container breakout paths.
Full-scope red team engagements available by request — not a core focus, but certified and experienced (CRTO, SpecterOps Adversary Tactics).
We define attack surfaces, establish rules of engagement, and map your threat landscape to real adversary TTPs before a single packet is sent.
OSINT, passive footprinting, and active discovery. We build a complete picture of your exposure — the same one your adversaries have.
Manual exploitation chained with privilege escalation and pivoting to demonstrate real business impact, not just CVSS scores.
Executive and technical reports with risk-prioritised findings, proof-of-concept reproductions, and a remediation roadmap your team can act on.
Retest of critical and high findings after remediation, so an engagement isn't considered closed until the vulnerabilities are gone.
Happy to talk through it — signed agreement, clear scope, and I can start within days.