
Geschlossen
Veröffentlicht
We are seeking an experienced and highly technical freelancer to conduct an advanced Red Teaming and Penetration Testing engagement. This project is for someone deeply skilled in offensive operations, with a strong focus on realistic, low-level attack techniques that mimic real-world adversaries. What We're Looking For: Red Teaming Expertise: Proven ability to execute realistic attack simulations, including persistence, stealth, and evasion. You must be capable of gaining and maintaining undetected access in a manner similar to well-resourced threat actors. Your role will involve using techniques that go beyond typical vulnerability scanning, with a focus on exploiting deep, systemic weaknesses. In-Depth Technical Knowledge: Mastery of network protocols, Active Directory exploitation, privilege escalation, lateral movement, and Command & Control (C2). Strong experience in exploiting vulnerabilities in Windows, Linux, cloud systems, and other complex environments. Ability to exploit and chain vulnerabilities to achieve meaningful attack objectives. Tools and Techniques: Expert-level use of tools like Cobalt Strike, Metasploit, Mimikatz, Responder, BloodHound, Empire, and others. You must also be comfortable using Living off the Land techniques (LOLBins) and custom scripts to exploit misconfigurations or weaknesses. Experience with bypassing modern security measures, such as EDR evasion, is critical. Advanced Attack Skills: Hands-on experience with protocol exploitation, packet crafting, reverse engineering, and custom payload development. You should be comfortable developing your own exploits, adapting public techniques to fit specific scenarios, and evading advanced detection mechanisms. Familiarity with kernel-level exploits and deep system manipulation is a plus. Realistic Threat Actor Simulation: Proficiency in executing multi-stage, highly targeted attacks (e.g., phishing, lateral movement, persistence). Familiarity with MITRE ATT&CK Framework and a deep understanding of how sophisticated threat actors operate, including their tactics, techniques, and procedures (TTPs). Project Overview: Objective: To identify and exploit real vulnerabilities within our security environment, and provide actionable insights for remediation. The goal is not only to uncover weaknesses but to simulate a real-world adversary, showing how an attacker would move laterally, establish persistence, and exfiltrate data. Scope: Conduct both internal and external penetration tests, including black-box and white-box scenarios, with emphasis on sophisticated attack chains that involve multiple vectors. Expect to use every technique available—from phishing and social engineering to advanced evasion tactics, Active Directory attacks, and persistence mechanisms. Live Assessment: Applicants will be provided with an isolated, hardened test environment and must successfully breach it as part of the selection process. The assessment will include initial compromise (e.g., phishing or exploitation), lateral movement, and demonstrating persistence techniques that mirror the actions of sophisticated adversaries. Timeline: Estimated at 4-6 weeks, depending on the complexity of findings and the depth of analysis required. Deliverables: A highly technical report detailing findings, including all attack paths, persistence mechanisms, remediation recommendations, and strategic improvements for enhancing security posture. The report must include both technical depth and executive-level summaries for non-technical stakeholders. Desired Qualifications: Strong Offensive Security Background: Demonstrated success in conducting Red Team operations and penetration tests with a focus on high-value targets or critical infrastructure. The candidate should have experience with engagements that mimic nation-state or advanced criminal actor methodologies. Low-Level, Deep Technical Understanding: Comfort working at the packet and process level, creating custom exploits, modifying malware, analyzing protocol behavior, and executing living-off-the-land strategies. You must be able to identify and exploit opportunities that traditional security testing would miss. Practical Engagement Experience: Must have extensive experience in real-world engagements where gaining and maintaining unauthorized access was critical. This includes familiarity with post-exploitation activities and long-term stealth tactics. Clear Reporting Skills: Ability to document and communicate findings clearly and accurately, making complex technical issues understandable for both technical and non-technical audiences, including C-level executives. Professionalism and Integrity: Absolute adherence to ethical hacking principles, security best practices, and maintaining client confidentiality at all times. Experience handling sensitive information and working under strict NDAs is essential. How to Apply: If you are interested, please provide a summary of your experience, links to relevant case studies or previous engagements, and your rate. Please note that only applicants who successfully complete the live assessment will be considered for the role.
Projekt-ID: 38678436
10 Vorschläge
Remote Projekt
Aktiv vor 1 Jahr
Legen Sie Ihr Budget und Ihren Zeitrahmen fest
Für Ihre Arbeit bezahlt werden
Skizzieren Sie Ihren Vorschlag
Sie können sich kostenlos anmelden und auf Aufträge bieten
10 Freelancer bieten im Durchschnitt €168 EUR/Stunde für diesen Auftrag

As an accomplished and certified Penetration Tester, I believe my skills and experience make me the perfect choice for your deep Technical Red Teaming and Penetration Testing project. I have a unique mix of offensive security knowledge combined with a deep technical understanding of operating systems, including Windows and Linux, as well as expert-level use of tools such as Cobalt Strike, Metasploit, Mimikatz and others mentioned in your project description. I also have a proven record of conducting highly realistic attack simulations that mimic real-world adversaries through persistence, stealth and evasion techniques. From your project's scope to its desired outcomes, it resonates with my core competency. For instance, my familiarity with MITRE ATT&CK Framework has given me a deep understanding on how sophisticated threat actors operate which enables me to devise progressive tactics to exploit deep systemic weaknesses. Lastly, I pride myself on delivering reports that are both technically detailed yet concise enough for non-technical stakeholders to understand--an important aspect given the desired deliverables. Even though most of my work is confidential due to its sensitive nature, I can share vulnerability assessment samples that exhibit my capability to identify known and unknown exploits which is equally critical for your project." With my broad range of skills and proven expertis.
€175 EUR in 40 Tagen
7,2
7,2

Hello, I am excited to apply for the Red Teaming and Penetration Testing project. With over 9 years of experience in offensive security, I specialize in executing highly sophisticated attack simulations that mirror real-world adversaries. My expertise spans advanced persistence, stealth, and lateral movement techniques using tools like Cobalt Strike, Metasploit, and custom-developed exploits. I have deep technical knowledge in network protocols, Active Directory exploitation, privilege escalation, and bypassing modern security measures like EDR. My hands-on experience in red teaming and conducting full-scope penetration tests ensures a realistic, thorough assessment of your security posture. I thrive in developing and adapting attack strategies to reveal critical vulnerabilities and provide actionable remediation. Thanks, Rajesh
€225 EUR in 40 Tagen
6,4
6,4

With over a decade of diverse and comprehensive IT experience, I can guarantee you the skills necessary to fulfill the trials and objectives of your project effectively. As a Data Center Expert, Network Administrator, and Security Solution extraordinaire, my proficiencies naturally align with the technical knowledge you seek. My proficiency in network protocols, exploitation of vulnerabilities in Windows, Linux, cloud systems, and more pair perfectly with your requirements. My mastery of common penetration testing tools such as Cobalt Strike, Metasploit, and others combined with my adaptive approach to finding solutions sets me apart from other competitors. I have not only honed traditional approaches but also obtained a legitimate understanding of how threat actors operate in depth - the prime skill you require in your red teaming specialist. Apart from having all the above qualities to undertake your project successfully for your coveted four to six weeks duration, an added bonus is my understanding of Microsoft Hyper-V deployments and management. This intertwines nicely with your environment's potential needs while conducting both internal and external penetration tests. I am driven by passion for security analysis; hence I assure you that the deliverables will include all facets YOU require: highly technical report, executive-level summaries and strategic improvements for a better security posture -
€200 EUR in 40 Tagen
5,6
5,6

As a talented tech enthusiast and security professional, I've consistently leveraged my skills in penetration testing, web security, and much more to secure data in a constantly evolving digital landscape. I understand the significance of the task at hand: identifying and exploiting real vulnerabilities while simulating a real-world adversary's actions. My expertise in conducting red team operations and penetration tests on high-value targets is both dynamic and exceptional. My strategies have mimicked those used by nation-state or advanced criminal actors, making me the right fit for your project. My strength lies in my comfort working at the packet and process level which has equipped me to create custom exploits to expose systemic weaknesses, similar to what you are seeking. I have expert-level proficiency with tools such as Cobalt Strike, Metasploit, Mimikatz, Responder, BloodHound, Empire among others needed for this project. Moreover, my knowledge of bypassing modern security systems ensures that I'm adept at using every technique available from social engineering to advanced evasion tactics.
€175 EUR in 40 Tagen
4,9
4,9

Hello, i think my bid is cheaper than others. I have experience handling Red Teaming and Pentesting specially for banking. Let's chat to discuss more
€100 EUR in 40 Tagen
3,5
3,5

Michendorf, Germany
Mitglied seit Okt. 13, 2024
₹750-1250 INR / Stunde
₹12500-37500 INR
$10-30 USD
$60 USD
$10-30 USD
₹600-1500 INR
₹600-1500 INR
₹600-1500 INR
$30-250 USD
£18-36 GBP / Stunde
$30-250 USD
$10-30 USD
₹12500-37500 INR
$30-250 USD
₹600-1500 INR
$10-30 USD
$1500-3000 USD
₹600-1500 INR
$30-250 USD
$250-750 USD