Penetration Testing
External and internal assessments that validate realistic compromise paths — not just isolated findings.
I identify and validate real-world attack paths across applications, infrastructure, identity and cloud environments — and translate them into decisions your business can act on.
Offensive security engineer working across European and US markets, from Kyiv, Ukraine.
I approach security assessments as more than a search for isolated vulnerabilities. My goal is to understand how weaknesses interact, how an attacker could move through an environment, and which technical issues create meaningful business risk.
My background spans penetration testing, network security, critical infrastructure, product security, cloud engineering and security automation — including highly regulated sectors such as finance, insurance, government, legal services and energy.
Alongside assessments, I build private platforms for phishing simulations, remote physical penetration testing, AI-assisted reconnaissance and security process automation.
Grouped by outcome — not an exhaustive tool list. Methodology aligned with OWASP, PTES and MITRE ATT&CK.
External and internal assessments that validate realistic compromise paths — not just isolated findings.
AD CS abuse, Kerberos attack paths, NTLM relay validation, hybrid AD / Entra ID environments.
Authentication, authorization, tenant isolation, business logic and API testing for multi-tenant apps.
GCP, Azure and M365 assessments, container hardening, network segmentation and Zero Trust initiatives.
Custom offensive tooling, reconnaissance automation and engagement-specific utilities that scale assessments.
Human-in-the-loop AI pipelines for recon enrichment, finding correlation and attack-path identification.
A representative multi-stage path — anonymized from a real internal assessment that ended in full domain compromise.
Internal network mapping, identity and privilege analysis across the environment.
Validating exposure: credential access, misconfigurations and exploitable services.
AD CS misconfiguration testing and certificate-based authentication abuse.
Kerberos attack-path validation and domain replication privilege analysis.
Post-compromise impact analysis, safe evidence collection, remediation guidance.
Sensitive exploitation always runs with human approval, evidence quality is preserved, and disruption is avoided — even in production-like environments.
Offensive security platforms kept private by design. Descriptions focus on purpose and capability, not implementation.
Controlled phishing assessment and security awareness platform — campaign lifecycle, analytics, behavioral metrics.
PrivateRemotely managed hardware for authorized on-site assessments — secure operator channel, engagement isolation.
PrivateRecon enrichment, finding correlation and attack-path identification with human-in-the-loop validation.
PrivateAutomation connecting pentest operations, evidence handling, reporting and internal security workflows.
PrivateReusable cloud environment — engagement isolation, standardized tooling, rapid provisioning.
Private$ some things stay private — confidentiality requirements & the sensitive nature of offensive tooling.
Across banking, insurance, government, legal services, energy and technology — in Ukraine, Germany, the EU and the US.
Penetration testing, adversary simulation, security research or tooling — if you need to know how attackers could actually reach your critical assets, talk to me.