Skip to Main Content

Esteban Rodriguez

Senior Security Consultant

EXPERIENCE

  • 10+ years IT
  • 8+ years cybersecurity
  • 5+ years penetration testing/consulting

EDUCATION & CERTIFICATIONS

  • Associate in Science, Information Systems Technology, Community College of the Air Force
  • Bachelor of Science, Computer Networks & Security, University of Maryland University College
  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Wireless Professional (OSWP)
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Penetration Tester (GPEN)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • Certified Ethical Hacker (CEH)
  • CompTIA Network+
  • CompTIA Security+

INDUSTRY CONTRIBUTIONS

PASSION FOR SECURITY
I just love popping shells.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog December 05 2023

The SOCKS We Have at Home

Use OpenSSH to pivot through networks without complex tools, leveraging Windows 10 and Server 2019's default installation, and easily set up a bind shell for…

Read about this article
Blog September 15 2022

Practical Attacks against NTLMv1

Exploit NTLMv1 vulnerabilities to gain administrative access, leveraging authentication downgrade, LDAP relay, and Shadow Credentials attacks, with techniques…

Read about this article
Blog March 03 2022

Manipulating User Passwords Without Mimikatz

Manipulating User Passwords Without Mimikatz: Exploring Alternative Techniques for Lateral Movement and Privilege Escalation.

Read about this article
Blog April 16 2026

Dungeons and Daemons

Play Roll for Initiative. Hack the Planet.Dungeons & Daemons is a cybersecurity RPG that drops you into the boots of a Red Team operator on a live…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Blog April 14 2026

Benchmarking Self-Hosted LLMs for Offensive Security

We put LLMs to the test—let's find out how good AI is at hacking! We walk through six simple challenges with intentionally naïve setups to test how capable…

Read about this article
Events April 09 2026

TrustedSec Livestream - AMA: Detection Engineering in 2026 and Beyond with John Dwyer

Come prepared with your questions and walk away with actionable knowledge to sharpen your detection capabilities.

Read about this article
Blog April 09 2026

IAM the Captain Now – Hijacking Azure Identity Access

I decided to spend some research time diving in depth into Identity and Access Management (IAM) within Microsoft Azure. I am going to show you within this blog…

Read about this article
Blog April 07 2026

Building a Detection Foundation: Part 5 - Correlation in Practice

From Data Sources to DetectionWe've covered a lot of ground in this series: Windows Security events for logon tracking and process execution; PowerShell…

Read about this article
Podcasts April 06 2026

Security Noise - A Goblin, a Ghost, and a Ninja Walk into the Azure Bar

On this episode, Geoff and Skyler are joined by NyxGeek to discuss his suite of Azure bypass techniques. Since these techniques leave no trace, what does it…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.