About
Founder, Unknown². Principal consultant in adversary simulation and incident response. Came up on the defensive side — SOC teams, threat intelligence, detection engineering — then switched to offense.
Background
Most red teamers come up through CTF competitions and academic exploitation research. My path was different. I spent years on the defensive side — building SOC teams, writing detection logic, running threat intelligence programs, and responding to real incidents under pressure.
That background shaped how I approach adversary simulation. When I'm operating against an environment, I know what the defenders are seeing — or not seeing. I know which log sources are typically gaps. I know what alert fatigue looks like at 2am, and I know which detections security teams trust versus which ones they've tuned to silence. That operational context makes the simulation more realistic and the findings more actionable.
I've been in the room for ransomware negotiations — with legal counsel, crisis communications teams, and decision-makers under breach disclosure pressure. I've briefed boards in the hours after an incident was confirmed. And I've built the detection engineering programs that the adversaries I now simulate are designed to evade.
Unknown² was founded on the premise that most organizations don't need more vulnerability findings. They need to know whether their security investment would actually stop a motivated adversary. That's the question we answer.
Areas of Expertise
Full-scope red team operations replicating named threat actor behavior. MITRE ATT&CK-mapped technique execution with structured detection gap analysis.
Post-initial-access operations testing lateral movement detection, privilege escalation controls, and incident response time from an established foothold.
Emergency response and retainer-based IR support. Forensic investigation, containment strategy, and recovery planning under active incident conditions.
Negotiation alongside technical remediation. Offensive ransomware TTP knowledge applied directly to defensive response and recovery sequencing.
SIEM content development, log source architecture, and detection validation. Purple team engagements that produce detection logic, not just findings.
Board-level security briefings, fractional CISO support, and threat-to-business-risk translation for executives navigating high-stakes security decisions.
Speaking
To discuss a speaking engagement, reach out directly at hello@unknown2.com.
How to build and operate an adversary emulation program — from threat profiling and TTP selection through execution and detection gap closure. Practical methodology for organizations moving beyond generic penetration testing.
A frank account of the detection gaps and architectural assumptions that red teams reliably exploit — drawn from years of operating against defended environments. What security programs consistently fail to cover and why.
The operational reality of ransomware incidents — negotiation dynamics, technical investigation under breach pressure, recovery sequencing, and the decisions that determine outcome. For incident responders and security leaders.
How to communicate threat actor capability and organizational risk to executive audiences without losing precision. For CISOs and security leaders navigating board-level conversations about cybersecurity investment.
Get In Touch
Whether you're evaluating a red team engagement, managing an active incident, looking for a speaker, or need fractional CISO support — the best first step is a direct conversation.
Start a Conversation →