Services
Independent offensive-security work for teams that want a real adversary's perspective. Each service below lists what it covers and how I approach it.
Web App Penetration Testing
Black/grey-box testing of web apps and APIs, mapped to OWASP, with a clear and reproducible report.
Network Penetration Testing
External and internal infrastructure testing to find and prove exploitable exposure across your estate.
Mobile App Penetration Testing
iOS and Android assessments covering the app binary, local storage, and its backend APIs.
Wireless Penetration Testing
Assessment of Wi-Fi networks, rogue-AP exposure, and client-side wireless attacks.
Red Team & Adversary Simulation
Goal-based engagements that emulate a real threat actor end to end — access, C2, lateral movement, impact.
Active Directory Assessment
Deep review of a Windows/AD estate — misconfigurations, privilege paths, and a prioritised remediation plan.
Source Code Review
Whitebox review to find the bugs black-box testing misses — auth flaws, injection sinks, insecure design.
Bug Bounty Advisory
Program design, triage support, and severity calibration for teams running or scaling a bounty program.
Training & Workshops
Hands-on sessions on web exploitation, AD attacks, and AI-app security for internal security teams.
Discovery Call · 1:1
A paid 1:1 session to scope your problem, review findings, or get focused advice. Booked via Topmate.
Have a project in mind?
Book a paid 1:1 discovery call, or send me the scope and I'll come back with an approach and a quote.
❯ Book a Discovery Callget in touch