Skip to Main Content

Zach Bevilacqua

Security Consultant

EXPERIENCE
Zach Bevilacqua found his calling in Information Security after building a career in various PC repair positions before moving to System Administration and Engineering. Zach served as a subject matter expert for a Security Operations Center and fulfilled roles as a detection engineer and security controls tester, which allowed him to cover many aspects of Information Security.

EDUCATION & CERTIFICATIONS

  • Offensive Security Certified Professional (OSCP)

INDUSTRY CONTRIBUTIONS
Zach has spoken at several conferences on topics ranging from threat hunting to building a detection and response program in the enterprise.

PASSION FOR SECURITY
Early in his career, Zach was interested in the offensive side of security. While working toward that goal, he learned about the world of Information Security and his place within it. Zach is driven by learning how things are broken and fixed and enjoys sharing his knowledge with others.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog January 25 2024

From Zero to Purple

Learn how to create and deploy Internet Shortcut files for adversary emulation and detection engineering using Python, SMB, and WebDAV servers, a useful tool…

Read about this article
Blog January 18 2024

Engagement Guide: How to Prepare for Your Purple Team

TrustedSec's Purple Team engagements prepare clients for security assessments by identifying gaps in security coverage, logging, and tooling, with offerings…

Read about this article
Blog July 13 2023

Modeling Malicious Code: Hacking in 3D

This blog post reveals how attackers can exploit the.3mf file format to smuggle malicious code into an environment, bypassing off-the-shelf detection…

Read about this article
Blog April 16 2026

Dungeons and Daemons

Play Roll for Initiative. Hack the Planet.Dungeons & Daemons is a cybersecurity RPG that drops you into the boots of a Red Team operator on a live…

Read about this article
Webinars April 15 2026

You Had Us at the First Alert: A Guide to Finding Frequently Missed Detections

Join us for this webinar to get a clearer picture of where your detection coverage has blind spots and a practical roadmap for closing them before a real…

Read about this article
Blog April 14 2026

Benchmarking Self-Hosted LLMs for Offensive Security

We put LLMs to the test—let's find out how good AI is at hacking! We walk through six simple challenges with intentionally naïve setups to test how capable…

Read about this article
Events April 09 2026

TrustedSec Livestream - AMA: Detection Engineering in 2026 and Beyond with John Dwyer

Come prepared with your questions and walk away with actionable knowledge to sharpen your detection capabilities.

Read about this article
Blog April 09 2026

IAM the Captain Now – Hijacking Azure Identity Access

I decided to spend some research time diving in depth into Identity and Access Management (IAM) within Microsoft Azure. I am going to show you within this blog…

Read about this article
Blog April 07 2026

Building a Detection Foundation: Part 5 - Correlation in Practice

From Data Sources to DetectionWe've covered a lot of ground in this series: Windows Security events for logon tracking and process execution; PowerShell…

Read about this article
Podcasts April 06 2026

Security Noise - A Goblin, a Ghost, and a Ninja Walk into the Azure Bar

On this episode, Geoff and Skyler are joined by NyxGeek to discuss his suite of Azure bypass techniques. Since these techniques leave no trace, what does it…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.