Offensive Security · Adversary Emulation

AE

Offensive Security Consultant | Red Team | Penetration Testing | Purple Team | Cloud Security

Offensive Security Consultant with keyboard-level experience targeting Red Team, Penetration Tester, Purple Team, and Cloud Penetration Tester roles.

How I work

Conducts and supports MITRE ATT&CK‑aligned adversary emulation, security assessments, and detection / response validation across identity, endpoint, network, application and cloud attack surfaces.

  • Identity
  • Endpoint
  • Network
  • Application
  • Cloud

Selected Work

Featured: REDxGRIDxAEV

An umbrella adversary‑emulation‑validation project. Its first completed engagement, RG‑AE‑001, is an authorized, controlled Windows post‑compromise micro‑emulation built to test detection and response, not to demonstrate compromise itself.

RG‑AE‑001 · Windows post‑compromise micro‑emulation

Scope & objective

A contained, authorized study of whether a realistic sequence of post‑compromise techniques is observed and understood by the detection stack. The objective is visibility and response validation, measured against a defined telemetry baseline.

Controlled workflow

Executed as a custom eight‑step CALDERA campaign in a controlled environment. Each step is mapped, time‑stamped against the evidence timeline, and tied to an observable artifact for validation.

Tools & telemetry

  • MITRE Caldera (campaign operator)
  • PowerShell Script Block Logging
  • Sysmon telemetry
  • Wazuh detection & alerting

Evidence‑backed findings

Campaign activity was correlated against the logging baseline to assess what the stack surfaced, what it missed, and where detection/response tuning is warranted. Findings and sanitized evidence are documented per step.

Asset slot · awaiting approved image

Architecture diagram — REDxGRIDxAEV / RG‑AE‑001

Placeholder until an approved, sanitized diagram is supplied. No private topology, IPs, or raw telemetry will be published here.

Limits & safe framing

This engagement does not demonstrate, and is not claimed to have achieved: initial access, persistence, credential theft, lateral movement, exfiltration, or production-system access. It is a bounded, authorized validation exercise.

The REDxGRIDxAEV repository is private. Full sanitized evidence and the write‑up are available on request.

Additional projects will be listed here as they are completed and approved for publication.

About

Background & strengths

Cyber Consultant | Technical Strategy Partner, Security Architecture & Workforce Development

My work centers on translating adversary behavior into measurable detection and response outcomes — emulating techniques along MITRE ATT&CK, running assessments across identity, endpoint, network, application and cloud surfaces, and turning what the stack observes (or fails to observe) into concrete improvements.

Profile details pending your approval

These appear in site-content.md but were left blank, so nothing is invented here. Supply them and they will be added verbatim:

  • Prior roles / experience approved for public display
  • Substantiated accomplishments
  • Technical areas to highlight
  • Certifications approved for display
  • Education / training approved for display

Contact

Let's talk security

Best reached by email for consulting, teaming, and assessment conversations.