Skip to Main Content
All Trimarc services are now delivered through TrustedSec! Learn more

Hans Lakhan

Principal Security Consultant

EXPERIENCE
With over a decade of industry experience, Hans Lakhan has worked in both offensive and defensive roles. Before switching to red teaming, he spent 5 years working as a technical Security Analyst for a Fortune 500 telecommunications company, specializing in networking, firewalls, vulnerability management, and VPNs.

EDUCATION & CERTIFICATIONS

  • B.S. Bio-Medical Information Systems, University of Minnesota
  • Offensive Security Certified Professional (OSCP)

PROFESSIONAL AFFILIATIONS
Hans occasionally presents at various conferences (Blackhat, DerbyCon) and contributes to several open source projects.

PASSION FOR SECURITY
While Hans enjoys tackling complex security challenges, his true passion stems from tearing apart systems (physical, digital, process flows, and more), in which the goal is to identify weaknesses and present remediation solutions.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog February 02 2021

Injecting Rogue DNS Records Using DHCP

Understanding DHCP to Inject Rogue DNS Records via Spoofed MAC Addresses.

Read about this article
Blog September 23 2020

Azure Account Hijacking using mimikatz’s lsadump::setntlm

Senior security researcher Carlos Perez reveals a hybrid Office 365 attack method using Mimikatz to gain domain admin access and hijack user accounts,…

Read about this article
Webinars June 17 2020

Password Recovery 101: Cracking More of Your List

Join VP of Consulting Services Martin Bos, Paul Burkeland, and Hans Lakhan for a webinar on password recovery tools and techniques, and gain an analytical…

Read about this article
Webinars February 11 2026

Perspectives on AI in the Cybersecurity Industry in 2026

Join us for this exclusive webinar where our experts will decode the complex relationship between artificial intelligence and cybersecurity in 2026. What will…

Read about this article
News January 22 2026

News 5 Cleveland - Social Security numbers may have been exposed in data breach connected to local car dealership

A Massillon car dealership reports that an unauthorized actor accessed its network, potentially exposing customer names and Social Security numbers. Advisory…

Read about this article
Blog January 22 2026

Adventures in Primary Group Behavior, Reporting, and Exploitation

If you’ve administered Active Directory (AD) for any significant time, chances are you’ve come across the primaryGroupID attribute. Originally developed as a…

Read about this article
Blog January 20 2026

Colonel Clustered: Finding Outliers in Burp Intruder

TL;DR, gimme the goods: https://github.com/hoodoer/ColonelClusteredExtension has been submitted to the Bapp store, awaiting approval.This is a Burp Suite…

Read about this article
Events January 15 2026

Discord Livestream - Crash Course: Building an Analysis Strategy

In this livestream, we will cover the components of an incident response attack plan from a high level —including scoping, building an analysis strategy,…

Read about this article
Blog January 15 2026

CMMC Scope – Understanding the Sprawl

The CMMC program contains complex, and potentially confusing, scope requirements. Contractors that are preparing for a CMMC assessment will need to pay close…

Read about this article
News January 15 2026

WWL First News with Tommy Tucker - What to know about the big Verizon outage on Wednesday

A widespread Verizon outage left many without service, sparking conversation about digital dependence. Advisory Solutions Director Alex Hamerstone joins WWL…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.