Network & Infrastructure PT
Internal and external testing of servers, network devices and perimeter defences — mapping the real path an attacker would take through your environment.
InfrastructurePenetration Testing / IT Security
Freelance Offensive Security Consultant — Italy
For over 15 years, I've made a career of breaking into networks, applications, and wireless infrastructure so the bad guys don't get the chance. My penetration testing work spans a broad mix of industries, from banking, telecom, and energy to automotive, logistics, and more.
Scope of services
Internal and external testing of servers, network devices and perimeter defences — mapping the real path an attacker would take through your environment.
InfrastructureManual, OWASP-driven testing of web applications: authentication, business logic, injection, and session handling — not just an automated scan.
WebSecurity review of Android applications — local storage, inter-process communication, and traffic between the app and its backend.
Android802.11 network testing — rogue access points, encryption weaknesses and authentication bypass across corporate wireless deployments.
Wi-FiManual review of application source code to catch the vulnerability classes that black-box testing alone tends to miss.
CodePost-incident investigation and evidence handling for Windows and GNU/Linux environments following a suspected compromise.
Incident responseApproach
From the first scoping call to a retest that confirms the fixes actually hold.
We agree targets, testing windows, and boundaries in writing before any traffic touches your systems.
Enumeration of the attack surface — hosts, endpoints, services and roles — to build an accurate picture of what's exposed.
Manual testing against the agreed scope, chaining findings the way a real attacker would rather than reporting isolated issues.
A report with reproduction steps, evidence, and severity ratings — written for both engineers and decision-makers.
Follow-up review to confirm fixes hold, and direct support for your team while they remediate.
Credentials
Background, certification and public disclosure history.
Get in touch
Tell me the systems in scope and the timeline you're working to, and I'll come back with a proposal and estimate. NDAs welcome — yours or mine, whichever you prefer.