>> _

BLACKCAT INFOSEC

ETHICAL HACKING | PENETRATION TESTING | CYBER DEFENSE

blackcat@infosec:~$

$ whoami

chris.nellinger // Ethical Hacker // Security Researcher

$ cat mission.txt

Breaking into systems so the bad guys can't.

$ ./engage --mode=protect

SCROLL TO EXPLORE

THE OPERATIVE

Chris Nellinger BlackCat Mascot
STATUS ACTIVE
CLEARANCE LEVEL 5
THREAT LVL MAXIMUM

CHRIS NELLINGER

Founder & Lead Security Consultant

I'm Chris Nellinger, the mind behind BlackCat InfoSec. I specialize in ethical hacking and offensive security — legally and methodically breaking into systems to expose vulnerabilities before malicious actors do.

In an age where cyber threats evolve by the hour, organizations need more than firewalls. They need someone who thinks like an attacker but works on their side. That's where I come in. Every engagement I take on is governed by strict rules of engagement, full legal authorization, and a commitment to making your infrastructure bulletproof.

Whether it's a Fortune 500 company or a growing startup, I bring the same intensity: find every crack, document every weakness, and fortify every defense.

OSCP+ (In Progress) PNPT PenTest+ GPEN eWPT
</about>

ATTACK VECTORS

Offensive security services designed to expose your weaknesses before the enemy does.

Penetration Testing

Full-scope ethical hacking engagements that simulate real-world attacks against your networks, applications, and infrastructure. I don't just scan — I exploit, pivot, and demonstrate real impact.

NetworkWeb AppAPICloud
🔒

Red Team Operations

Advanced adversary simulation that tests your people, processes, and technology. I operate like a real threat actor — covert, persistent, and creative — to evaluate your entire security posture.

Social Eng.PhishingPhysicalEvasion
🛡

Vulnerability Assessment

Systematic identification and prioritization of security vulnerabilities across your digital assets. Comprehensive reporting with actionable remediation guidance ranked by real-world exploitability.

ScanningAnalysisReportingCVSS
💻

Web App Security

Deep-dive security testing of web applications targeting OWASP Top 10 and beyond. From SQL injection to business logic flaws, I find the bugs that automated scanners miss.

OWASPXSSSQLiAuth Bypass

Social Engineering

Targeted phishing campaigns, vishing, pretexting, and physical intrusion testing. Your people are your biggest attack surface — I help you find out exactly how vulnerable they are.

PhishingVishingPretextingOSINT
🔐

Security Consulting

Strategic security advisory services including security architecture review, incident response planning, compliance guidance, and building a security-first culture from the inside out.

StrategyComplianceIR PlanTraining
</services>

KILL CHAIN

Every engagement follows a methodical, battle-tested approach.

01

RECONNAISSANCE

Scoping, intel gathering, and attack surface mapping. Understanding your environment before the first packet is sent.

02

WEAPONIZATION

Crafting custom exploits, payloads, and attack strategies tailored specifically to your environment and threat model.

03

EXPLOITATION

Executing controlled attacks to breach defenses. Every action is logged, documented, and performed within agreed-upon rules of engagement.

04

POST-EXPLOITATION

Pivoting, privilege escalation, and lateral movement to demonstrate the full impact of a breach on your organization.

05

REPORTING

Comprehensive deliverables with executive summaries, technical details, proof-of-concept evidence, and prioritized remediation roadmaps.

06

REMEDIATION SUPPORT

I don't just find the problems — I help you fix them. Re-testing included to verify vulnerabilities are properly patched.

</process>

THE ARSENAL

Tools, frameworks, and skill sets in the BlackCat toolkit.

Offensive Tools

Burp Suite Pro
Metasploit
Impacket Suite
Nmap / Masscan
Bloodhound

💻 Languages & Scripting

Python
Bash / Shell
PowerShell
Ruby
SQL

🔒 Platforms & Infra

Kali Linux
Active Directory
AWS / Azure / GCP
Docker / K8s
Wireshark
</arsenal>

PEN WRITEUPS

Documented exploits, CTF walkthroughs, and penetration testing reports from the field.

HTB

Access

HackTheBox machine exploitation walkthrough covering enumeration, foothold, and privilege escalation.

HackTheBox
HTB

Arctic

Cold exploitation of a Windows target — from ColdFusion vulnerabilities to full system compromise.

HackTheBox
HTB

Bastard

Drupal-based attack chain demonstrating web app exploitation and Windows privilege escalation techniques.

HackTheBox
HTB

Jeeves

Jenkins exploitation and post-exploitation techniques on a Windows environment with alternate data streams.

HackTheBox
THM

Alfred

TryHackMe room targeting Jenkins misconfigurations for initial access and token impersonation for escalation.

TryHackMe
THM

UltraTech

API enumeration and command injection leading to Docker escape and root-level compromise.

TryHackMe
VIEW ALL WRITEUPS
</writeups>

ESTABLISH LINK

Ready to test your defenses? Open a secure channel.

ENCRYPTED COMMS [email protected]
DIRECT LINE (555) 123-4567
COORDINATES Location TBD
🔗
SECURE NET www.blackcatinfosec.com
</contact>