Available for remote and Pacific Northwest engagements
Garrett Allen
Offensive Security Engineer
Red Team Operator · Penetration Tester
Senior U.S. Army cyber warrant officer with 14 years in Offensive Cyberspace Operations, now building detection-aware security tooling and testing systems for commercial and nonprofit clients.
- Experience
- 14 years
- Certifications
- 10 (2 hands-on)
- Based
- Greater Seattle Area
whoami
army cyber warrant officer · red teamer · tool builder
cat focus.txt
- red — full-scope engagements, TTP development
- blue — detection engineering, threat hunting
- purple — measuring what defenders actually see
Credentials
Certifications
10 active credentials earned since 2014, including2 hands-on practical examinations. Grouped by issuing body.
Offensive Security
OSEP
hands-onOffensive Security Experienced Penetration Tester
Advanced evasion and lateral movement against hardened, monitored environments.
2025
OSCP
hands-onOffensive Security Certified Professional
The baseline hands-on penetration testing credential — 24-hour practical exam.
2019
GIAC
GPEN
GIAC Penetration Tester
Methodology and process for scoped, reportable penetration tests.
2019
GCIH
GIAC Certified Incident Handler
Incident detection, containment, and response from the defender's seat.
2020
GCFE
GIAC Certified Forensic Examiner
Host forensics and artifact analysis — what an operation leaves behind.
2014
Advisory Board
GIAC Advisory Board
Invited membership, extended to candidates scoring in the top tier of a GIAC exam.
2019, 2020
EC-Council
CEH
Certified Ethical Hacker
Broad offensive tooling and technique coverage.
2020
ECSA
EC-Council Certified Security Analyst
Analysis and reporting layered on top of the CEH technique set.
2020
CHFI
Computer Hacking Forensic Investigator
Digital forensics, evidence handling, and investigative process.
2020
CompTIA
Security+
CompTIA Security+
DoD 8570 baseline across the general security body of knowledge.
2019
Selected work
Projects & home lab
Published tooling, infrastructure built and secured end to end, and client engagements. Every figure below comes from the repository it describes.
- Infrastructure
Segmented Home Lab & Observability Stack
Seven VLANs, default-deny between every one of them.
A production-shaped lab built as code: Proxmox virtualization behind a pfSense firewall, seven isolated VLANs with default-deny between every segment, and a full Prometheus/Loki/Grafana observability stack. Built to test detections against real telemetry rather than assumptions.
- isolated VLANs
- 7
- inter-VLAN rules total
- 2
- alert rules
- 40
- dashboard panels
- 79
- Proxmox VE
- pfSense
- Docker
- Prometheus
- Grafana
- Loki
Read the write-up for Segmented Home Lab & Observability Stack
- Purple
opseclint
What would a defender see?
A detection-coverage analyzer, published to crates.io. Give it a command, script, or playbook and it resolves the techniques involved, the host telemetry they generate, and the detections that would actually fire — scored 0–100 for detectability across Linux, Windows, and macOS.
- detectability score
- 0–100
- telemetry platforms
- 3
- published
- crates.io
- code-scanning output
- SARIF
- Rust
- MITRE ATT&CK
- Sigma
- SARIF
- GitHub Actions
- Offensiveclient work
Web Security Audit & Remediation
Nonprofit early-childhood center — audit, fix, verify.
A full security and content audit of a nonprofit's public website, followed by remediation. Found and fixed a stored cross-site scripting path in the site's theme, verified plugin exposure against a live supply-chain incident, and delivered a content audit conducted under a strict no-PII rule.
- plugins audited
- 16
- stored XSS found & fixed
- 1
- vulnerability databases cross-checked
- 5
- upstream files modified
- 0
- WordPress
- PHP
- OWASP
- WPScan
- Patchstack
- Defensive
dotgibson
One authored-once core, eight operating systems, two role layers.
A layered dotfiles ecosystem across 13 repositories: a single authored-once core vendored into per-OS repos for macOS, Windows, and six Linux distributions, with red and blue operator role layers on top — including a Dockerized hunt lab and an ATT&CK-tagged red-versus-blue methodology corpus.
- repositories
- 13
- operating systems
- 8
- Python & Bash scripts
- ~370
- paired detection entries
- 20+
- Zsh
- Neovim
- tmux
- Python
- Bash
- Docker
Engineering & tooling
Roughly 370 Python and Bash scripts across the public repositories — operational tooling, detection validation fixtures, and the automation that keeps eight machines identical.
Offensive tooling
Enumeration, exploitation, and reporting automation in Python and Bash. Written to be read by whoever inherits the engagement.
Detection validation
Fixture generators that synthesize DNS tunneling, DGA beaconing, ICMP tunneling, authentication coercion, and cryptomining traffic, plus Sigma rule evaluation against the output.
Infrastructure as code
Docker Compose stacks, Prometheus and Loki configuration, CI that validates rules with promtool and amtool before anything ships.
Development environment
A documented, reproducible terminal environment — zsh, Neovim, tmux — vendored across eight operating systems from one source of truth.
Background
14 years in Offensive Cyberspace Operations
I have spent 14 years in the Army conducting Offensive Cyberspace Operations. That mostly include planning and executing operations against national-priority targets, developing the tactics and procedures other operators use, and mentoring the people who run them.
Lately I have been pointing that experience elsewhere. Knowing exactly which artifacts an operation leaves behind is the same knowledge a defender needs to catch it, so most of what I build now is detection-aware: tooling that answers what a defender would actually see, and lab infrastructure built to prove the answer.
Before any of that I was a music education major in college. Weird, right? That didn't end up being the path I wanted to pursue. But I earned the degree and the teaching certificate that goes along with it. So, I joined the Army!That turns out to matter more than it sounds: a penetration test is only worth what its report communicates, and explaining a finding to a board that does not speak in CVEs is a teaching problem, not a technical one.
Red Teaming
Full-scope engagements, tactics and procedures development, defense evasion, and post-exploitation tradecraft.
Penetration Testing
Network, Active Directory, and web application testing — scoped, reported, and remediated.
Tooling & Weaponization
Python and Bash enumeration and exploitation tooling, plus the reporting that makes it useful.
Detection Engineering
Turning offensive knowledge inward — building the detections that catch the techniques.
Experience
Weapons & Tactics Director
currentFederal cyber mission organization · 2023–Present
- Developed risk-mitigation strategies under delegated national authorities, enabling 15+ successful campaigns.
- Strategies were adopted more broadly across the force, improving operational readiness beyond the originating organization.
- Delegated responsibility and developed leadership within the team, optimizing workflows and reducing timelines by 20%.
- Mentored 90+ cyberspace operators and appointed subject-matter experts, raising operational output without direct intervention.
- Served as a strategic-level advisor across 10+ cyber teams, aligning technical execution with command objectives.
Cyberspace Operator
Joint service cyber component · 2020–2023
- Attained the senior-most operator certification level within the joint cyber enterprise.
- Planned, coordinated, and executed cyberspace operations supporting national objectives.
- Integrated component processes into the daily operational battle rhythm to keep the team ahead of mission requirements.
Liaison Officer
Interagency assignment · 2019–2020
- Led the transition of a premier capability between military cyber and interagency partners.
- Represented the organization as its technical specialist and authored 10+ standard operating procedures adopted by every subsequent person in the role.
- Mentored interagency personnel and advised 20+ staff on meeting technical and policy requirements.
- Built working relationships across government and industry that drove ongoing cybersecurity collaboration.
Cyberspace Operator
Army cyber organization · 2016–2019
- Executed cyberspace operations in support of national intelligence requirements.
- Developed, documented, and maintained 10+ tactics, techniques, and procedures closing enterprise capability gaps.
- Wrote and maintained operational tooling that measurably reduced operational risk.
- Contributed to a joint tactics manual — a shared repository of tool documentation used across the enterprise.
Cyberspace Operator
Army cyber organization · 2013–2016
- Conducted cyberspace operations fulfilling national collection requirements.
- Supervised and led 20+ training operations covering tooling and tradecraft for 25+ operator trainees.
- Performed malware analysis to determine the function and persistence of newly encountered tooling.
- Analyzed and debugged 5+ tools, reverse-engineering them to improve existing capability.
Note:A full curriculum vitae is available to verified inquiries. Request it using the contact form below.
Education
Bachelor of Music Education
University of Nebraska–Lincoln · 2012
Graduated 3.5 GPA. Nebraska teaching certification, 2012.
Contact
Start a conversation
Available for remote and Pacific Northwest engagements. Tell me what you are trying to find out and I will tell you whether I am the right person for it.