Skip to main content

About

I’m a penetration tester based in northeast Pennsylvania.

My work covers external and internal network testing, web applications, and social engineering, along with some onsite physical assessment work covering WiFi, Bluetooth, NFC, and rogue USB devices. I’ve also built a handful of internal tools that automate parts of the testing workflow and cut down the tedium in reporting.

I came into security sideways. I spent years in customer service and IT support before moving into cloud and security engineering, and then into pentesting. That path turned out to be more useful than expected, since a lot of this job is sitting with clients and explaining what happened without making anyone feel stupid about it.

Lately I’ve been spending more time on the adversary emulation side of things. A pentest tells you what can be broken. A red team engagement tells you whether anyone notices, how long it takes, and what they do about it. That second question is the one I find more interesting, and it’s the direction I’ve been building toward.

Certifications #

  • OffSec Experienced Penetration Tester (OSEP)
  • OffSec Certified Professional (OSCP)
  • Red Team Lead (CRTL)
  • Red Team Operator (CRTO)
  • eLearnSecurity Junior Penetration Tester (eJPT)

Community #

I help organize DEF CON 570, our local DEF CON group.

Elsewhere #

You can find me on LinkedIn and GitHub. I’m always happy to connect and talk shop.

Mark Hunsinger
Author
Mark Hunsinger
Notes on offensive security, Active Directory, and adversary emulation.