ETHICAL HACKING | PENETRATION TESTING | CYBER DEFENSE
$ whoami
chris.nellinger // Ethical Hacker // Security Researcher
$ cat mission.txt
Breaking into systems so the bad guys can't.
$ ./engage --mode=protect
[READY] Awaiting your command...
SCROLL TO EXPLORE
Founder & Lead Security Consultant
I'm Chris Nellinger, the mind behind BlackCat InfoSec. I specialize in ethical hacking and offensive security — legally and methodically breaking into systems to expose vulnerabilities before malicious actors do.
In an age where cyber threats evolve by the hour, organizations need more than firewalls. They need someone who thinks like an attacker but works on their side. That's where I come in. Every engagement I take on is governed by strict rules of engagement, full legal authorization, and a commitment to making your infrastructure bulletproof.
Whether it's a Fortune 500 company or a growing startup, I bring the same intensity: find every crack, document every weakness, and fortify every defense.
Offensive security services designed to expose your weaknesses before the enemy does.
Full-scope ethical hacking engagements that simulate real-world attacks against your networks, applications, and infrastructure. I don't just scan — I exploit, pivot, and demonstrate real impact.
Advanced adversary simulation that tests your people, processes, and technology. I operate like a real threat actor — covert, persistent, and creative — to evaluate your entire security posture.
Systematic identification and prioritization of security vulnerabilities across your digital assets. Comprehensive reporting with actionable remediation guidance ranked by real-world exploitability.
Deep-dive security testing of web applications targeting OWASP Top 10 and beyond. From SQL injection to business logic flaws, I find the bugs that automated scanners miss.
Targeted phishing campaigns, vishing, pretexting, and physical intrusion testing. Your people are your biggest attack surface — I help you find out exactly how vulnerable they are.
Strategic security advisory services including security architecture review, incident response planning, compliance guidance, and building a security-first culture from the inside out.
Every engagement follows a methodical, battle-tested approach.
Scoping, intel gathering, and attack surface mapping. Understanding your environment before the first packet is sent.
Crafting custom exploits, payloads, and attack strategies tailored specifically to your environment and threat model.
Executing controlled attacks to breach defenses. Every action is logged, documented, and performed within agreed-upon rules of engagement.
Pivoting, privilege escalation, and lateral movement to demonstrate the full impact of a breach on your organization.
Comprehensive deliverables with executive summaries, technical details, proof-of-concept evidence, and prioritized remediation roadmaps.
I don't just find the problems — I help you fix them. Re-testing included to verify vulnerabilities are properly patched.
Tools, frameworks, and skill sets in the BlackCat toolkit.
Documented exploits, CTF walkthroughs, and penetration testing reports from the field.
HackTheBox machine exploitation walkthrough covering enumeration, foothold, and privilege escalation.
Cold exploitation of a Windows target — from ColdFusion vulnerabilities to full system compromise.
Drupal-based attack chain demonstrating web app exploitation and Windows privilege escalation techniques.
Jenkins exploitation and post-exploitation techniques on a Windows environment with alternate data streams.
TryHackMe room targeting Jenkins misconfigurations for initial access and token impersonation for escalation.
API enumeration and command injection leading to Docker escape and root-level compromise.
Ready to test your defenses? Open a secure channel.