Services Approach About Get in touch
$ _

Find the vulnerabilities
before attackers do.

Freelance penetration tester helping businesses secure their infrastructure, applications, and people through offensive security assessments.

What I offer

Web Application Testing

In-depth assessment of web applications for OWASP Top 10 vulnerabilities, business logic flaws, authentication bypasses, and more.

  • OWASP Top 10
  • API Security
  • Auth Bypass

Network Penetration Testing

Internal and external network assessments to identify misconfigurations, exposed services, and privilege escalation paths.

  • Internal/External
  • Active Directory
  • Pivoting

Red Team & Phishing

Realistic adversary simulation end-to-end — from targeted phishing campaigns and social engineering through lateral movement to objective completion, with awareness metrics and training recommendations.

  • Adversary Simulation
  • Phishing
  • Social Engineering
  • Physical

Custom Security Solutions

Tailored security tooling and automation — SCAP compliance scanning, continuous vulnerability assessments, and custom-built solutions to fit your environment.

  • SCAP
  • Automated Scanning
  • Custom Tooling

How I work

01

Scoping

We define objectives, targets, rules of engagement, and timeline. Clear scope means focused results.

02

Reconnaissance

Mapping the attack surface — enumerating assets, identifying technologies, and discovering entry points.

03

Exploitation

Manual testing combined with targeted tooling to identify and validate real-world vulnerabilities.

04

Reporting

Detailed findings with severity ratings, proof-of-concept evidence, and actionable remediation guidance — no filler.

Who I am

I'm a freelance penetration tester focused on helping organizations understand and reduce their real-world risk. I combine manual testing expertise with a deep understanding of how attackers think and operate.

Every engagement gets my full attention — no junior handoffs, no recycled scan output. You get thorough, hands-on testing and a report that your developers can actually act on.

OSCP
CVE Researcher
CTF Player

Let's talk security

Have a project in mind or want to discuss your security needs? Reach out and I'll get back to you within 24 hours.

$ curl vuln.lt/pgp.txt