Skip to Main Content

Lou Scicchitano

Senior Security Consultant

EXPERIENCE
Lou has obtained several years of experience in information security roles by doing a variety of different tasks on both offense and defense including detection and monitoring, vulnerability management, and internal network and web application penetration testing. He initially spent three and a half years as a software developer before transitioning into an information security role.

EDUCATION & CERTIFICATIONS

  • Bachelor of Science: Computer Science, The University of Akron
  • GIAC Security Essentials (GSEC)
  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Wireless Professional (OSWP)
  • Offensive Security Certified Expert (OSCE)
  • eLearnSecurity Web Application Penetration Tester (eWPT)
  • GIAC Assessing and Auditing Wireless Networks (GAWN)
  • Certified Red Team Operator (CRTO)

PASSION FOR SECURITY
For as long as Lou can remember, he has been fascinated with computers, and from a young age began tinkering with them and learning how to program. He has always had a drive to understand how things really work and what makes them tick. After learning that one can make a computer do things it wasn’t intended to do, he was hooked. This mindset, along with growing up watching movies like The Matrix and Hackers, fueled his interest in security and an endless pursuit of knowledge and continuous learning.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this consultant and their team.

Webinars February 14 2024

Ask Me Anything: Pen Testing from a Hacker's Perspective

Join seasoned experts Adam Compton, Lou Scicchitano, and Justin Elze for an interactive discussion on penetration testing, covering real-world insights, best…

Read about this article
Blog July 14 2026

Pandora’s Container Part 1: Unpacking Azure Container Security

Azure container services are everywhere. Their attack surface? Often overlooked. In Part 1 of this blog series, we walk through offensive techniques targeting…

Read about this article
Blog June 16 2026

JQ for Hackers

Grey-bearded hackers and sysadmins still reaching for cut and CSV files, this one's for you. In this blog, we break down jq and why it's time to embrace JSON.

Read about this article
Blog June 12 2026

JS-Tap v3: Endpoint Post-Exploitation With JavaScript Implants

JavaScript escaped the browser. JS-Tap v3 followed it. In this blog, we introduce three new beacons targeting the Electron apps, browser extensions, and Node…

Read about this article
Blog April 23 2026

Kerberos with Titanis

In this article, I’ll walk you through the basics of Kerberos, how to use Titanis for the different parts, and how to mitigate some problems.Titanis SetupI use…

Read about this article
Blog April 14 2026

Benchmarking Self-Hosted LLMs for Offensive Security

We put LLMs to the test—let's find out how good AI is at hacking! We walk through six simple challenges with intentionally naïve setups to test how capable…

Read about this article
Blog March 17 2026

Better Together: Combining Automation and Manual Testing

When I started working in mobile application security in 2018, most testing was still largely manual. Since then, the ecosystem has exploded with scanners,…

Read about this article
Blog February 03 2026

MCP in Burp Suite: From Enumeration to Targeted Exploitation

MCP servers rely on SSE and WebSockets, which makes manual testing tricky. In this blog, we introduce MCP-ASD, a new Burp Suite extension designed to help…

Read about this article
Blog December 09 2025

Holy Shuck! Weaponizing NTLM Hashes as a Wordlist

Password reuse is common in Active Directory (AD). From an attacker’s perspective, it is a reliable path to lateral movement or privilege escalation. Most IT…

Read about this article
Podcasts November 19 2025

Security Noise - C2 for Me + You

Attackers and threat actors use command and control techniques, also known as C2, to gain access to networks and communicate with compromised devices. Listen…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.