~ / services

Services

Independent offensive-security work for teams that want a real adversary's perspective. Each service below lists what it covers and how I approach it.

Web App Penetration Testing

Black/grey-box testing of web apps and APIs, mapped to OWASP, with a clear and reproducible report.

approachRecon & mapping → content/endpoint discovery → test by vuln class (access control, injection, XSS, SSRF, logic) → PoC & report.

Network Penetration Testing

External and internal infrastructure testing to find and prove exploitable exposure across your estate.

approachHost & port discovery → service enumeration → exploitation & pivoting → post-exploitation → reporting.

Mobile App Penetration Testing

iOS and Android assessments covering the app binary, local storage, and its backend APIs.

approachStatic analysis → dynamic instrumentation (Frida/Objection) → traffic tampering → API testing → report.

Wireless Penetration Testing

Assessment of Wi-Fi networks, rogue-AP exposure, and client-side wireless attacks.

approachSurvey & capture → handshake/auth attacks → offline cracking → rogue-AP / client attacks → remediation.

Red Team & Adversary Simulation

Goal-based engagements that emulate a real threat actor end to end — access, C2, lateral movement, impact.

approachRecon & initial access → C2 & evasion → lateral movement → objective & impact → detection-gap report.

Active Directory Assessment

Deep review of a Windows/AD estate — misconfigurations, privilege paths, and a prioritised remediation plan.

approachEnumeration → credential access → escalation & lateral movement → domain dominance → remediation plan.

Source Code Review

Whitebox review to find the bugs black-box testing misses — auth flaws, injection sinks, insecure design.

approachThreat-model → trace inputs to sinks → identify vulnerable patterns → verify exploitability → report.

Bug Bounty Advisory

Program design, triage support, and severity calibration for teams running or scaling a bounty program.

approachScope & policy review → triage workflow → severity calibration → researcher engagement → reporting.

Training & Workshops

Hands-on sessions on web exploitation, AD attacks, and AI-app security for internal security teams.

approachTailored curriculum → live hands-on labs → guided exploitation → takeaways & follow-up.

Discovery Call · 1:1

A paid 1:1 session to scope your problem, review findings, or get focused advice. Booked via Topmate.

approachPick a slot → 1:1 call → scoped advice & clear next steps.

Have a project in mind?

Book a paid 1:1 discovery call, or send me the scope and I'll come back with an approach and a quote.

❯ Book a Discovery Callget in touch