Contact for availability.
Garrett Allen
Offensive Security Engineer
Red Team Operator · Penetration Tester
Senior U.S. Army Cyber Warrant Officer with 14 years in Offensive Cyberspace Operations, now building detection-aware security tooling and testing systems for commercial and nonprofit clients.
- Experience
- 14 years
- Certifications
- 10 (2 hands-on)
- Based
- Seattle, WA
whoami
army cyber warrant officer · red teamer · tool builder · tinkerer
cat focus.txt
- red — full-scope engagements, tool development
- blue — detection engineering, threat hunting
- purple — measuring what defenders actually see
Credentials
Certifications
10 credentials earned since 2014, including2 hands-on practical examinations. Grouped by issuing body.
Offensive Security
OSEP
hands-onOffensive Security Experienced Penetration Tester
Advanced evasion and lateral movement against hardened, monitored environments.
2025 · no expiration

OSCP
hands-onOffensive Security Certified Professional
The baseline hands-on penetration testing credential.
2019 · no expiration · verify
GIAC

GPEN
GIAC Penetration Tester
Methodology and process for scoped, reportable penetration tests.
2019 · lapsed 2023 · verify

GCIH
GIAC Certified Incident Handler
Incident detection, containment, and response from the defender's seat.
2020 · lapsed 2024 · verify

GCFE
GIAC Certified Forensic Examiner
Host forensics and artifact analysis.
2014 · lapsed 2018 · verify
Advisory Board
GIAC Advisory Board
Invited membership, extended to candidates scoring in the top tier of a GIAC exam.
2019, 2020 · lapsed 2024
EC-Council
CEH
Certified Ethical Hacker
Broad offensive tooling and technique coverage.
2020
ECSA
EC-Council Certified Security Analyst
Analysis and reporting layered on top of the CEH technique set.
2020
CHFI
Computer Hacking Forensic Investigator
Digital forensics, evidence handling, and investigative process.
2020
CompTIA

Security+
CompTIA Security+
DoD 8570 baseline across the general security body of knowledge.
2019 · lapsed 2022 · verify
Selected work
Projects & home lab
Published tooling, infrastructure built and secured end to end, and client engagements. Every figure below comes from the repository it describes.
- Infrastructure
Segmented Home Lab & Observability Stack
Seven VLANs, but don't break anything, or else...
A production-shaped lab built as code: Proxmox virtualization behind a pfSense firewall, seven isolated VLANs with default-deny between every segment, and a full Prometheus/Loki/Grafana observability stack. Built to test detections against real telemetry rather than assumptions.
- isolated VLANs
- 7
- inter-VLAN rules total
- 2
- alert rules
- 40
- dashboard panels
- 79
- Proxmox VE
- pfSense
- Docker
- Prometheus
- Grafana
- Loki
Read the write-up for Segmented Home Lab & Observability Stack
- Purple
opseclint
What would a defender see?
A detection-coverage analyzer, published to crates.io. Give it a command, script, or playbook and it resolves the techniques involved, the host telemetry they generate, and the detections that would actually fire. Results are scored 0–100 for detectability across Linux, Windows, and macOS.
- detectability score
- 0–100
- telemetry platforms
- 3
- published
- crates.io
- code-scanning output
- SARIF
- Rust
- MITRE ATT&CK
- Sigma
- SARIF
- GitHub Actions
- Offensiveclient work
Nonprofit Site: Audit, Remediation, Rebuild
Found the hole, fixed it, then made the site theirs to run.
A nonprofit's public site, taken from a security audit through remediation to a rebuilt front end their office staff can maintain without a developer. Found and fixed a stored cross-site scripting path, then delivered 27 releases of a child theme that left the upstream theme untouched and upgradeable.
- releases delivered
- 27
- page templates
- 19
- stored XSS found & fixed
- 1
- upstream files modified
- 0
- WordPress
- PHP
- OWASP
- WPScan
- Accessibility
Read the write-up for Nonprofit Site: Audit, Remediation, Rebuild
- Purple
dotgibson
One core, eight operating systems, two role layers.
A layered dotfiles ecosystem across 13 repositories: a single authored-once core vendored into per-OS repos for macOS, Windows, and six Linux distributions, with red and blue operator role layers on top. Also a Dockerized hunt lab and an ATT&CK-tagged red-versus-blue methodology corpus.
- repositories
- 13
- operating systems
- 8
- Python & Bash scripts
- ~370
- paired detection entries
- 20+
- Zsh
- Neovim
- tmux
- Python
- Bash
- Docker
- Secure Engineering
StonkSmith
I need financial security, not another app.
A CLI that consolidates personal brokerage accounts into SQLite and publishes them to a dashboard. The scraping is the ordinary part. What makes it worth writing up is the credential lifecycle, where the secret lives in the operating system keyring and the database holds only a pointer to it, and a login path that stops at the bot-detection boundary and hands control back to a human.
- secrets in the database
- 0
- credential store
- OS keyring
- test functions
- 918
- broker integrations
- 5
- Python 3.14
- SQLite
- Playwright
- OS keyring
- Google Sheets API
- pytest
Engineering & tooling
Roughly 370 Python and Bash scripts across the public repositories. Operational tooling, detection validation fixtures, and the automation that keeps eight machines identical.
Offensive tooling
Enumeration, exploitation, and reporting automation in Python and Bash. Written to be read by whoever inherits the engagement.
Detection validation
Fixture generators that synthesize DNS tunneling, DGA beaconing, ICMP tunneling, authentication coercion, and cryptomining traffic, plus Sigma rule evaluation against the output.
Infrastructure as code
Docker Compose stacks, Prometheus and Loki configuration, CI that validates rules with promtool and amtool before anything ships.
Development environment
A documented, reproducible terminal environment (zsh, Neovim, tmux) vendored across eight operating systems from one source of truth.
Background
14 years in Cybersecurity
I have spent 14 years in the Army conducting Offensive Cyberspace Operations. Mostly in planning and executing operations against national-priority targets, developing the tactics and procedures other operators use, and mentoring the people who run them.
Lately I have been pointing that experience elsewhere. Knowing exactly which artifacts an operation leaves behind is the same knowledge a defender needs to catch it, so most of what I build now is detection-aware: tooling that answers what a defender would actually see, and lab infrastructure built to prove the answer.
Before any of that I was a music education major in college. Weird, right? That didn't end up being the path I wanted to pursue. But I earned the degree and the teaching certificate that goes along with it. So, I joined the Army!That turns out to matter more than it sounds: a penetration test is only worth what its report communicates, and explaining a finding to a board that does not speak in CVEs is a teaching problem, not a technical one.
Red Teaming
Full-scope engagements, tactics and procedures development, defense evasion, and post-exploitation tradecraft.
Penetration Testing
Network, Active Directory, and web application testing — scoped, reported, and remediated.
Tooling & Weaponization
Python and Bash enumeration and exploitation tooling, plus the reporting that makes it useful.
Detection Engineering
Turning offensive knowledge inward — building the detections that catch the techniques.
Experience
Training with Industry Fellow
currentU.S. Army / Microsoft · 2025–Present
- Internship with Microsoft Azure
Weapons & Tactics Director
U.S. Army · 2023–2025
- Strategic level advisor, mentor, technical expert.
Cyberspace Operator
U.S. Army · 2020–2023
- Senior-level certified, planner, coordinater, integrater.
Liaison Officer
U.S. Army · 2019–2020
- Representative, collaborator, advisor.
Cyberspace Operator
U.S. Army · 2016–2019
- Developer, documenter, maintainer.
Cyberspace Operator
U.S. Army · 2012–2016
- Superviser, trainer, analyst, engineer.
Note:A full curriculum vitae is available to verified inquiries. Request it using the contact form below.
Education
Bachelor of Music Education
University of Nebraska–Lincoln · 2012
Graduated 3.5 GPA. Nebraska teaching certification, 2012.
Contact
Email Me
Let me know whether you would like to chat, or if I can be of any assistance. I will get back to you when I can.