󰀦 cat /etc/stances — offense & defense
󰣨 cat /etc/stances
attacker$ recon & exploit — find the holes before they do
defender$ monitor & respond — watch the wall 24/7
# Neither stance works alone. Hire both, or start with one.

Offensive Security

RED TEAM — OFFENSE

Recon & Penetration Testing

You can’t fix what you don’t know is broken — and neither can the people attacking you. The cheapest vulnerability you’ll ever patch is the one you find first. I’ll map your attack surface, knock on every open door, and actually prove what’s exploitable. No “high-risk theoretical” filler, no jargon walls.

What I deliver:

  • Full external recon — domains, subdomains, exposed services, leaked credentials, takeover candidates
  • Infrastructure & web application penetration testing, OWASP-aligned
  • Verified exploits — proof of impact, not just CVE numbers
  • Custom tooling wherever the off-the-shelf stuff falls short
  • A prioritized report in plain language, not a 200-page PDF

You get:

  • A complete map of everything you’re exposing to the internet
  • Reproducible evidence for every finding — fix it, then re-test it
  • A remediation roadmap your team can actually execute
  • Your skeletons found by us — instead of by someone with bad intentions

Defensive Security

BLUE TEAM — DEFENSE

Monitoring & SOC

Offense is an appointment. Defense is a lifestyle. Between pentests, someone has to watch the perimeter, correlate the logs, and catch the quiet stuff before it becomes a headline. That’s where I live.

What I deliver:

  • Fleet-wide metrics, logs & alerting — VictoriaMetrics, Grafana, centralized log aggregation
  • SOC-style threat detection with intrusion detection and honeypots
  • Incident response runbooks, so the panic is pre-planned
  • Alert hygiene — you get woken up when it matters, not when a disk crosses 80%
  • Tabletop wargames and post-incident reviews

You get:

  • Knowledge of what’s happening before your users do
  • A clear picture of who’s knocking on your door — and whether anyone got in
  • Historical telemetry for forensics, tuning, and capacity planning
  • Defenses that get stronger every week instead of slowly rotting
󰀦 Offensive — Red Team
󰓃 Defensive — Blue Team
󱂵 Zero-Trust Perimeter
󰣻 NixOS Hardened
󰔟 Ready to find out how hard you really are to break into?
Whether you want me to attack your stack like I mean it, or keep watch over it like I built it — drop me a line. I'll come back with an honest technical assessment and a proposed approach, no buzzword bingo.
[ GET IN TOUCH ] [ SEE ALL SERVICES ]
󰣨 ymrtech@ymrtech 󰖣 DARK | 󰌠 NixOS | 󰍢 UTF-8