Skip to Main Content

James Williams

Senior Security Consultant

EXPERIENCE
James started his career as a software developer and worked across a range of different industry sectors before moving into an information security role. He has spent the last 8 years in offensive security, with the latter half of that time spent delivering Red Team engagements.

EDUCATION & CERTIFICATIONS

  • Masters of Science: Computer Systems (Bangor University)
  • Offensive Security Certified Professional (OSCP)
  • Certified Red Team Operator (CRTO)

INDUSTRY CONTRIBUTIONS
James has presented at conferences in the United Kingdom (BSides Manchester and Steelcon) and often publishes research on employer blogs and personal blogs.  

PASSION FOR SECURITY
James has been fascinated by computers since he first broke the family PC and had to learn how to fix it in a hurry. Now, he enjoys finding new and unusual ways to make computers do things that they weren’t meant to do.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog June 12 2025

Hunting Deserialization Vulnerabilities With Claude

In this post, we are going to look at how we can find zero-days in .NET assemblies using Model Context Protocol (MCP).SetupBefore we can start vibe hacking, we…

Read about this article
Blog June 03 2025

Teaching a New Dog Old Tricks - Phishing With MCP

As AI evolves with MCP, can a new “dog” learn old tricks? In this blog, we test Claude AI’s ability to craft phishing pretexts—and just how much effort it…

Read about this article
Blog October 17 2024

Spec-tac-ula Deserialization: Deploying Specula with .NET

This post explains how.NET deserialization can be used to backdoor a workstation with Specula, making it a valuable resource for Red Team operations.

Read about this article
Blog December 03 2024

Discovering a Deserialization Vulnerability in LINQPad

Discovering a Deserialization Vulnerability in LINQPad, written by James Williams, reveals a novel deserialization vulnerability in a.NET application with over…

Read about this article
Blog April 16 2026

Dungeons and Daemons

Play Roll for Initiative. Hack the Planet.Dungeons & Daemons is a cybersecurity RPG that drops you into the boots of a Red Team operator on a live…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Blog April 14 2026

Benchmarking Self-Hosted LLMs for Offensive Security

We put LLMs to the test—let's find out how good AI is at hacking! We walk through six simple challenges with intentionally naïve setups to test how capable…

Read about this article
Events April 09 2026

TrustedSec Livestream - AMA: Detection Engineering in 2026 and Beyond with John Dwyer

Come prepared with your questions and walk away with actionable knowledge to sharpen your detection capabilities.

Read about this article
Blog April 09 2026

IAM the Captain Now – Hijacking Azure Identity Access

I decided to spend some research time diving in depth into Identity and Access Management (IAM) within Microsoft Azure. I am going to show you within this blog…

Read about this article
Blog April 07 2026

Building a Detection Foundation: Part 5 - Correlation in Practice

From Data Sources to DetectionWe've covered a lot of ground in this series: Windows Security events for logon tracking and process execution; PowerShell…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.