Personal details

Evan H. - Remote

Evan H.

Timezone: Eastern Time (US & Canada) (UTC-4)

Summary

Hey there!

My name is Evan. I currently work as a Penetration Tester for a top 4 firm in the US where I also create applications and scripts utilized for Red Team Engagements.

I have been programming for the better part of 6 years but only really prioritized it 4 years ago. I am proficient in more than 12 programming, scripting and declarative languages and pride myself on my ability to write efficient, practical and neat code. I have a deep understanding of programming with the stack and heap and enjoy getting into the technical weeds with my mentees to create a better understanding of the task being performed.

In my spare time I run a Cyber Security Tools Company, hang out with friends, play volleyball and enjoy being with my dogs

Work Experience

Senior PenTester
KPMG | Dec 2021 - Present
Linux
Bash
PostgreSQL
PowerShell
Active Directory
LDAP
Windows Server
Python 3
TCP/IP
Go (Golang)
• Actively performed internal penetration assessments utilizing scripting techniques and open-source tools • Monitored, analyzed and infiltrated client wireless assets using scripts, open-source tools and pineapples to capture handshakes, perform VLAN Hops and clone or create access points • Performed Web Application Assessments utilizing BurpSuite and NetSparker • Developed phishing campaigns building a Virtual Private Server and GoPhish, crafting emails with HTML and CSS and configuring DNS Records on hosting sites • Developed and maintained OSINT script for the enumeration of client employees, services, email address patterns, phone numbers and more • Crafted payloads to be utilized in phishing campaigns for information extraction • Built, hardened and maintained shared server in Microsoft Azure used for poising attacks from cloud environment • Constructed automated Faraday Reporting in python for the creation of production level reports for clients • Performed manual and automated SAST Investigations on client source code in a variety of languages • Architected, developed and maintained innovative Phishing Application built in Golang, hosting an API service with PostgreSQL capable of capturing clicks, opens and engagement details