OFFENSIVE SECURITY

I find what
others miss.

Purplehat Cybersecurity finds the weaknesses in your systems before attackers do. Specialized in penetration testing, bug bounty programs and red team operations.

What I do

From targeted pentests to full red team simulations โ€” offensive security services that genuinely protect organizations.

Penetration Testing

In-depth manual testing of web applications, APIs, networks and mobile apps. I think like an attacker and report like a professional.

Web App API Network Mobile Cloud

Bug Bounty Programs

Setting up and managing responsible disclosure programs. I act as your triage specialist and security partner.

VDP Managed Program Triage Disclosure

Red Team Operations

Realistic simulation of advanced threats (APT). I test not just technology, but people and processes too.

APT Simulation Social Engineering Phishing Physical

Security Assessment

Code reviews, architecture assessments and threat modeling. I identify structural risks before they get exploited.

Code Review Architecture Threat Modeling SAST

Why Purplehat?

No templates, no automated scanners as the end product. Every engagement is manual, deliberate and fully tailored to your environment.

  • Fully manual testing โ€” no false-positive reports full of scanner output
  • Clear, actionable reporting for both engineers and management
  • Direct communication with the researcher, no middle layers
  • CVE experience and acknowledged findings across several major programs
  • NDA and full confidentiality as standard
Get in touch
purplehat@recon ~ engagement
โ–ธ ./recon.sh --target client.example.com
[*] Starting reconnaissance...
[+] Subdomain bruteforce complete โ€” 47 hosts
[+] Open ports mapped: 22, 80, 443, 8443
 
โ–ธ ./vuln_enum.sh --deep
[!] CVE-2023-44487 โ€” HTTP/2 Rapid Reset (CRITICAL)
[!] Exposed .git directory at /api/.git
[!] JWT secret hardcoded in source
 
โ–ธ ./report.py --generate --severity critical
[โœ“] pentest_report_2024.pdf generated
[~] 3 critical, 5 high, 9 medium findings

Cybersecurity Cowboy

I find the way in that no one left open.

I work where precision meets nerve. Systems that pass every scan, tick every box, sit behind every firewall โ€” those are the ones I take apart, quietly and completely. Not with noise, but with patience and a read on how things really break.

When I'm done you get one thing: the truth about your defenses, mapped out clean โ€” every door I walked through, and exactly how to close it. No inflated findings. No scanner output dressed up as insight. Just sharp, deliberate work from someone who's spent years on the wrong side of the lock.

That mindset has carried me through hardened mobile banking stacks โ€” defeating layered runtime protection (RASP), certificate pinning, and device-integrity checks through targeted smali patching, then reaching the pre-authentication GraphQL logic the defenses were built to hide.

And not everything I surface stays behind an NDA. Some of it reaches further โ€” feeding large-scale compromised-credential datasets, harvested from infostealer malware logs, to the Shadowserver Foundation for coordinated remediation through national CSIRTs. Millions of records across government, education, and critical-infrastructure sectors, routed to the people who can actually shut the door. A safer net is bigger than any single engagement.

The trade

Deep reconnaissance & stealth exploitation Business logic abuse & authorization flaws Mobile RASP / anti-tamper & pinning bypass API & web application security Data exposure & sensitive data leaks EDR / WAF bypass Python-driven pentest automation Advanced OSINT & threat intelligence Firmware & low-level โ€” ARM Trusted Firmware Mobile & Android reverse engineering SQL injection & database security Kali Linux & the full offensive toolchain Windows exploitation & hardening

"I break things to make them unbreakable."

Recent findings

ARM Trusted Firmware Firmware ยท CVD

Memory-safety and anti-rollback bypass vulnerabilities in the ARM secure boot chain (TF-M / TF-A), coordinated with upstream engineering and PSIRT. Multiple findings accepted and rewarded.

HIGH โ€” Accepted & rewarded
Discourse Bug Bounty ยท HackerOne

Information disclosure enabling enumeration of the existence of restricted private topics via a flag parameter. Acknowledged and paid via HackerOne.

MEDIUM โ€” Resolved
Enterprise recruitment platform Responsible Disclosure

Broken access control (missing authorization) exposing ~39,000 user records. Remediated by the vendor within 24 hours.

HIGH โ€” Remediated

Start a conversation

Ready to map out your attack surface? Send a message for a no-obligation introduction or a tailored quote.

info@purplehat.nl
  Response within 24 hours   NDA & full confidentiality