About

A dozen years breaking into companies that paid me to, and exploits were rarely the point. The credentials were usually already there. The only question was how far they went.

The work now is adversarial engineering: still finding the paths, but sitting between the red team and the people designing the system, so a finding changes the design instead of the report. Most recently that was at Okta, threat modeling the identity products and production cloud from the inside and running purple team exercises with detection engineering so the detections were built against real attack paths, not the vendor’s list. Alongside that, assessing LLM systems holding PHI and regulated data. The systems I care about most are the ones that hand credentials to software: identity boundaries, tenant isolation, agents and the tools they call.

Co-founder at Adversis and Puck, which answers what an attacker can actually reach from here.

Lots of Go and Python, typed by hand, which is apparently a period detail now. tailsnitch, go-decrypt-jenkins, grpc-scan, and a Next.js server action analyzer are on GitHub, alongside merged contributions to Sliver, Metasploit, and Hashcat. A few CVEs, one in Acrobat Reader. The rest is on the tools page.

The Effective Red Team: Adversary Emulation Inside the Enterprise, written with Trevin Edgeworth and Jordan Potti, is out from No Starch Press in January 2027 and in early access now. Before Adversis: built and operated red teams at Capital One, Symantec, and Gen Digital, consulted at Bishop Fox, and did adversary engineering at Okta.

OSCE, OSCP, GXPN, and others.

Contact

Email noah at this domain. Haikus get read first.

GitHub as @thesubtlety and, more recently, @noahpotti. Same person. Also on LinkedIn.