03 / PENTEST FREELANCER BERLIN

Offensive security for applications, APIs and source code.

I examine systems from an attacker’s perspective, confirm vulnerabilities manually and document the attack path, impact and remediation. Comprehensive pentest and EASM engagements are delivered through DSecured.

THE PROJECT QUESTION

„Will we receive a scanner report, or will we know which attack paths really work and what needs to be fixed first?“

MY ANSWER

You receive manually confirmed findings with reproducible evidence, realistic impact and priorities for developers and decision-makers. Critical results are reported during the test.

WHEN I SUPPORT YOUR TEAM

When you need to know what an attacker can really find before release.

Scope, depth and rules are agreed first. The assessment then focuses on realistic attack paths, confirms relevant findings manually and translates them into an order your team can act on.

01

An important release is approaching

A web application or API needs an independent, realistic assessment before launch.

02

Customers or auditors require evidence

The test needs a clear scope, robust methodology and professional report.

03

The real external attack surface is unclear

Historic subdomains, cloud services and forgotten systems need to become visible.

04

The team needs help with remediation

Findings must be reproducible and understandable to the people implementing the fixes.

PUBLIC EVIDENCESecurity research you can verify.
DSecured HackerOne Bugcrowd Intigriti GitHub projects

OFFENSIVE IT SECURITY / DSECURED

Offensive security engagements are delivered through DSecured.

This page explains why offensive security is part of my development work. Detailed information about penetration testing, EASM, specialist articles and security research is available at DSecured, together with a specialist team and the processes for larger security engagements.

ATTACK SURFACES / FOCUS

The attack surfaces
I assess.

The focus is the relevant attack surface of modern digital products. Testing is manual and supported by targeted automation.

01
</>

Web Application Penetration Testing

In modern web applications, decisive risks often lie in authentication, authorisation, data flows and business logic. That is where manual testing focuses.

  • Authentication, sessions and account recovery
  • Roles, tenant isolation and IDOR/BOLA
  • Business logic, race conditions and abuse cases
02
API

API Penetration Testing

APIs connect applications directly to valuable data and functions. Testing covers endpoints as well as object relationships, role changes, states and chains of functionality.

  • BOLA/IDOR and broken function-level authorisation
  • Tokens, OAuth, JWT and session flows
  • GraphQL, REST and WebSockets
03
MOB

Mobile Application Penetration Testing

The application, local data, transport and backend communication are examined as one connected attack surface.

  • Android and iOS applications
  • Local storage, logs and credentials
  • TLS, certificate pinning and deep links
04
NET

Network & Infrastructure Penetration Testing

Exposed services, forgotten systems and weak transitions between networks are identified and manually confirmed from an external or internal attacker’s perspective.

  • External perimeter and exposed services
  • Cloud systems and misconfiguration
  • Unknown IT systems and asset discovery
05
SRC

Security-focused Source Code Review

Source code analysis exposes trust boundaries, data flows and hidden attack paths. Automated analysis supports the work; understanding architecture and business logic remains decisive.

  • Authentication and authorisation logic
  • Input flows, taint tracking and injection
  • Cryptography, credentials and sensitive data
SCOPENDA & RULESMANUAL TESTIMMEDIATE NOTICEREPORT & RETEST

From a clear scope to a confirmed fix: reproducible evidence, understandable priorities and direct exchange with the development team.

Technical details, concrete packages and the full scope of services are available at DSecured.All DSecured services

SELECTED EVIDENCE / 2

Products and research
from real practice.

Selected systems and public tools show how development, automation and offensive practice work together.

EXTERNAL ATTACK SURFACE MANAGEMENT
PLATFORMArgos EASM
PROJECT VIEW
SCOPEexternal assets
OPERATIONcontinuous
PRIORITYrisk-based
VERIFIED STATUS
External asset discoveryACTIVE
Change monitoringVERIFIED
Modular security checksACTIVE
Prioritisation & reportsVERIFIED

SCREEN / 01Anonymised product view · sample data

External Attack Surface ManagementPUBLIC

Argos EASM

Continuously identify external attack surfaces before attackers exploit them.

DSecured Argos identifies public systems, monitors change and prioritises exposed services and potential vulnerabilities.

CHALLENGE
Forgotten subdomains, cloud systems and temporary infrastructure are often missing from internal inventories.
SOLUTION
Continuous discovery, modular checks, change monitoring and traceable prioritisation in one interface.
OUTCOME
Individual scans become an ongoing process for the real external attack surface.
  • External asset discovery
  • Change monitoring
  • Modular security checks
  • Prioritisation & reports
EASMReconLaravelDistributed scans
View Argos at DSecured
OPEN SOURCE & SECURITY RESEARCH
RESEARCHOpen Source Security Research Tools
PROJECT VIEW
PROJECTSpublic
FOCUSweb security
USEfield-tested
VERIFIED STATUS
extended-ssrf-searchACTIVE
extended-xss-searchVERIFIED
commonCrawlParserACTIVE
OOB ScannerVERIFIED

SCREEN / 02Public GitHub projects

Open source & security researchPUBLIC

Open Source Security Research Tools

Repeated research work becomes robust tooling.

Public tools for SSRF, XSS, external callbacks and Common Crawl data were built directly from practical bug bounty work.

CHALLENGE
Manual repetition costs time and makes results difficult to compare.
SOLUTION
Small focused tools automate discovery and initial hypotheses. Security-relevant judgement remains manual.
OUTCOME
Public projects that other security researchers can use and extend.
  • extended-ssrf-search
  • extended-xss-search
  • commonCrawlParser
  • OOB Scanner
PythonXSSSSRFRecon
View open source projects on GitHub

LOCAL AI INFRASTRUCTURE

Local AI for confidential project
data.

Information about target systems, source code and vulnerabilities can be processed locally without sending it to an external provider for model inference.

Fotorealistische Darstellung einer lokalen AI-Workstation mit zwei Grafikkarten
01 / WORKSTATION256 GB RAM · 2 × RTX 4090
FOR FAST LOCAL INFERENCE

256 GB RAM and two RTX 4090 GPUs for fast local inference.

The workstation runs compact and medium-sized models such as Qwen3.6-27B and Gemma 4 31B locally at suitable quantisation levels. It supports code analysis, document processing, evaluations and parallel development tasks with confidential data.

  • 256 GB system memory
  • Two RTX 4090 GPUs
  • Local development and test environments
FOR LARGER LOCAL MODELS

Two DGX Spark systems extend local memory for larger models.

Each DGX Spark provides 128 GB of unified memory. Depending on the model, quantisation and workflow, this supports larger models, longer contexts and more demanding local agents.

  • Two DGX Spark systems
  • 128 GB unified memory each
  • Local inference without an external model API
Fotorealistische Darstellung von zwei kompakten lokalen AI-Systemen
02 / DGX SPARK2 × 128 GB UNIFIED MEMORY
Model choice follows the protection needs of your task.
Source code stays localPentest data stays localModels remain interchangeable

Frontier models provide speed for non-sensitive work. Local models keep confidential code, documents and security data inside a controlled environment. Both can be combined in a clearly separated workflow.

The images are photorealistic representations of the available system classes; they do not show the actual installation location.

AI-ASSISTED PENTESTING

Local models.
Controlled tools.

AI can accelerate repeatable analysis and prepare additional test hypotheses. It replaces neither a pentester’s experience nor manual assessment of a potential attack.

01MANUALLY LED

Experience remains decisive

AI agents generate hypotheses, use tightly restricted tools and collect evidence. An experienced pentester evaluates relevance, risk and possible attack chains.

  • No unchecked scanner output
  • Manual confirmation of relevant findings
  • Reproducible evidence rather than assumptions
02LOCAL OPTION

Sensitive data remains protected

Target system, source code and vulnerability data can be processed with local models. The architecture is not tied to one model provider.

  • Local or owned infrastructure
  • Provider-independent orchestration
  • Restricted and logged tool access

CLIENT FEEDBACK / OFFENSIVE IT SECURITY

What clients value
about the collaboration.

Damian found a large amount of malicious code that even the host had completely missed, removed it reliably, closed every gap and gave many useful security recommendations. I felt in excellent hands, at a fair price.

Felix Beilharzfelixbeilharz.de

After repeated manipulation attempts Damian addressed the issue immediately and secured the application. We have had no further problems and are very grateful.

Gregor NebelDeutsche Medienportale GmbH

FREQUENTLY ASKED QUESTIONS / PENTEST FREELANCER BERLIN

What team leads want to know before a project.

Clear answers about the start, collaboration, data protection and budget before you invest time in a long sales process.

View security services
Why are larger security engagements delivered through DSecured?+

DSecured is the specialist environment for scopes, contracts, assessment delivery, reporting and ongoing security services. This portfolio explains the connection to my development work and links to the detailed security offering.

What can be assessed?+

Typical scopes include web applications, APIs, mobile applications, external infrastructure, networks and selected source code. The exact depth depends on risks, access and the agreed rules of engagement.

Can sensitive pentest data remain local?+

Yes. Local inference infrastructure is available for work involving source code, vulnerability details and confidential system data. External models are not required for those workflows.

What information is needed for a quote?+

Useful information includes the target, technology, roles, interfaces, environment, desired depth and deadline. A short scoping call usually resolves remaining questions.

Is the assessment manual or automated?+

Automation supports discovery and repeatable checks. Relevant findings, business-logic issues and combined attack paths are assessed manually and backed by reproducible evidence.

How long does a penetration test take?+

Duration depends on scope, roles, interfaces and depth. A focused application can take days; complex platforms or several targets take longer. The schedule and reporting points are agreed before the test.

What does a penetration test cost?+

Cost follows scope and depth rather than a generic page count. After scoping, you receive a transparent proposal with targets, assumptions, deliverables and retest conditions.

Does AI replace a manual pentest?+

No. AI can accelerate repeatable analysis and prepare additional hypotheses. Authorisation logic, workflow abuse and realistic impact still require experienced manual assessment.

IT SECURITY / DSECURED

Want to know where
your system is vulnerable?

Pentests, continuous attack surface analysis and further security services are delivered through DSecured.