Available for Consulting

Securing Digital
Solutions Worldwide

Director of Technology Services with 12+ years protecting organisations across Africa, the Middle East, and beyond. Trusted by Fortune 500 companies and global institutions.

0
Years Experience
0
Hall of Fame Awards
0
Global Organisations
Photo Here

Recognised by the World's
Top Organisations

Featured in Security Hall of Fame pages across leading global companies.

View All 17+ Recognitions

Security Tools I've Built

Open-source tools published on GitHub for the cybersecurity community.

FortiGate Configuration Audit Tool (FCFAT)

Audits FortiGate firewall configurations for security, compliance, and best practices. Automated analysis of security policies.

Python FortiGate Audit
View on GitHub

Cisco Configuration Audit Tool (CCFAT)

Analyses and audits Cisco configurations for security, compliance, and best practices across network devices.

Python Cisco Networking
View on GitHub

Nix Auditor

Tool to perform baseline review against Unix operating systems as per CIS benchmark standards. Comprehensive compliance checking.

Unix CIS Benchmark Audit
View on GitHub

Password Complexity Check

Python script that audits cracked credentials, checking password length, complexity, reuse, and generating colorised reports. Exports to CSV.

Python Passwords Audit
View on GitHub

Latest Articles

Sharing knowledge on cybersecurity tools, techniques, and research.

October 2025

Password Complexity & Reuse Audit Tool

A deep dive into auditing cracked credentials for password strength, complexity patterns, and reuse detection across enterprise environments.

Read Article
March 2025

Automating Cisco Configuration Audits

Strengthen your Cisco network by automating configuration audits with ease. A practical guide to security compliance checking.

Read Article
March 2025

FortiGate Configuration Files Audit Tool (FCFAT)

Enhancing firewall security with automated analysis of FortiGate configuration files for misconfigurations and compliance gaps.

Read Article
November 2018

Oracle EBS Security Auditing

An in-depth approach to auditing Oracle E-Business Suite, covering default credentials, weak passwords, application-level tests and database security controls.

Read Article
January 2018

From Shodan to RCE #3: Hacking the Belkin N600DB Wireless Router

The third instalment of the Shodan to RCE series, discovering and exploiting vulnerabilities in Belkin routers found exposed on the internet.

Read Article
December 2017

Blackhat Europe 2017 โ€“ Conference Notes

Key takeaways from Blackhat Europe 2017 in London, with links to slide decks, videos, and tools from briefings and demonstrations.

Read Article
June 2017

From Shodan to Remote Code Execution #1 โ€“ Hacking Jenkins

Exploring how misconfigured Jenkins automation servers exposed on the internet can lead to full remote code execution.

Read Article
May 2017

SAMBAry Save Us!! (CVE-2017-7494)

Exploiting the Samba remote code execution vulnerability (CVE-2017-7494), where all versions from 3.5.0 onwards were vulnerable to a malicious shared library upload attack.

Read Article
May 2017

From Shodan to RCE #2 โ€“ Hacking OpenDreambox 2.0.0

The second part of the Shodan to RCE series, exploiting misconfigured Dreambox digital TV set-top boxes for remote code execution.

Read Article
May 2017

Exploiting Windows with Eternalblue & Doublepulsar with Metasploit

Hands-on walkthrough of the NSA's EternalBlue and DoublePulsar exploits using Metasploit, the tools behind the WannaCry outbreak.

Read Article
April 2017

Penetration Testing Sharepoint

Reconnaissance and security testing techniques for Microsoft Sharepoint, using Google dorks and OWASP Top 10 vulnerability checks.

Read Article
April 2017

Word Heist!

Leveraging MS Word documents for social engineering, capturing NTLM hashes without macros using a clever spear-phishing technique.

Read Article
March 2017

Do You Know What Your ERP Is Telling Us?

Auditing Oracle E-Business Suite from an insider threat and external attacker perspective, uncovering information disclosure in ERP systems.

Read Article
March 2017

Lateral Movement: Part II

Continuation of the lateral movement series, focusing on techniques for privilege escalation and moving through a Windows domain environment.

Read Article
March 2017

Should We Be Worried? Huawei Router: Part II

Digging into the Huawei HG8245H router configuration, analysing suspicious parameters like X_HW_MonitorCollector and external server URLs.

Read Article
March 2017

Auditing Linux/Unix OS in 120 Seconds Flat

A baseline security auditing script for Linux and Unix operating systems, modelled around CIS benchmark controls that runs in under 2 minutes.

Read Article
March 2017

Huawei HG8245H Router "Privilege Escalation": Part I

Exploring the Huawei HG8245H home router, from default credentials to privilege escalation and full configuration extraction.

Read Article
January 2017

Lateral Movement: Part I

How a normal domain user with no admin privileges can exploit Group Policy Preferences (GPP) passwords to become local administrator across the organisation.

Read Article

Let's Secure Your Organisation

Looking for an experienced cybersecurity consultant? With 12+ years in the field and recognition from the world's top companies, I'm ready to help.