g3rt.com

Contact for availability.

Garrett Allen

Offensive Security Engineer

Red Team Operator · Penetration Tester

Senior U.S. Army Cyber Warrant Officer with 14 years in Offensive Cyberspace Operations, now building detection-aware security tooling and testing systems for commercial and nonprofit clients.

Experience
14 years
Certifications
10 (2 hands-on)
Based
Seattle, WA

Credentials

Certifications

10 credentials earned since 2014, including2 hands-on practical examinations. Grouped by issuing body.

Offensive Security

  • OSEP

    hands-on

    Offensive Security Experienced Penetration Tester

    Advanced evasion and lateral movement against hardened, monitored environments.

    2025 · no expiration

  • OSCP

    hands-on

    Offensive Security Certified Professional

    The baseline hands-on penetration testing credential.

    2019 · no expiration · verify

GIAC

  • GPEN

    GIAC Penetration Tester

    Methodology and process for scoped, reportable penetration tests.

    2019 · lapsed 2023 · verify

  • GCIH

    GIAC Certified Incident Handler

    Incident detection, containment, and response from the defender's seat.

    2020 · lapsed 2024 · verify

  • GCFE

    GIAC Certified Forensic Examiner

    Host forensics and artifact analysis.

    2014 · lapsed 2018 · verify

  • Advisory Board

    GIAC Advisory Board

    Invited membership, extended to candidates scoring in the top tier of a GIAC exam.

    2019, 2020 · lapsed 2024

EC-Council

  • CEH

    Certified Ethical Hacker

    Broad offensive tooling and technique coverage.

    2020

  • ECSA

    EC-Council Certified Security Analyst

    Analysis and reporting layered on top of the CEH technique set.

    2020

  • CHFI

    Computer Hacking Forensic Investigator

    Digital forensics, evidence handling, and investigative process.

    2020

CompTIA

  • Security+

    CompTIA Security+

    DoD 8570 baseline across the general security body of knowledge.

    2019 · lapsed 2022 · verify

Selected work

Projects & home lab

Published tooling, infrastructure built and secured end to end, and client engagements. Every figure below comes from the repository it describes.

Engineering & tooling

Roughly 370 Python and Bash scripts across the public repositories. Operational tooling, detection validation fixtures, and the automation that keeps eight machines identical.

  • Offensive tooling

    Enumeration, exploitation, and reporting automation in Python and Bash. Written to be read by whoever inherits the engagement.

  • Detection validation

    Fixture generators that synthesize DNS tunneling, DGA beaconing, ICMP tunneling, authentication coercion, and cryptomining traffic, plus Sigma rule evaluation against the output.

  • Infrastructure as code

    Docker Compose stacks, Prometheus and Loki configuration, CI that validates rules with promtool and amtool before anything ships.

  • Development environment

    A documented, reproducible terminal environment (zsh, Neovim, tmux) vendored across eight operating systems from one source of truth.

Background

14 years in Cybersecurity

I have spent 14 years in the Army conducting Offensive Cyberspace Operations. Mostly in planning and executing operations against national-priority targets, developing the tactics and procedures other operators use, and mentoring the people who run them.

Lately I have been pointing that experience elsewhere. Knowing exactly which artifacts an operation leaves behind is the same knowledge a defender needs to catch it, so most of what I build now is detection-aware: tooling that answers what a defender would actually see, and lab infrastructure built to prove the answer.

Before any of that I was a music education major in college. Weird, right? That didn't end up being the path I wanted to pursue. But I earned the degree and the teaching certificate that goes along with it. So, I joined the Army!That turns out to matter more than it sounds: a penetration test is only worth what its report communicates, and explaining a finding to a board that does not speak in CVEs is a teaching problem, not a technical one.

Experience

  1. Training with Industry Fellow

    current

    U.S. Army / Microsoft · 2025–Present

    • Internship with Microsoft Azure
  2. Weapons & Tactics Director

    U.S. Army · 2023–2025

    • Strategic level advisor, mentor, technical expert.
  3. Cyberspace Operator

    U.S. Army · 2020–2023

    • Senior-level certified, planner, coordinater, integrater.
  4. Liaison Officer

    U.S. Army · 2019–2020

    • Representative, collaborator, advisor.
  5. Cyberspace Operator

    U.S. Army · 2016–2019

    • Developer, documenter, maintainer.
  6. Cyberspace Operator

    U.S. Army · 2012–2016

    • Superviser, trainer, analyst, engineer.

Note:A full curriculum vitae is available to verified inquiries. Request it using the contact form below.

Education

Contact

Email Me

Let me know whether you would like to chat, or if I can be of any assistance. I will get back to you when I can.

What is this about? (required)

At least 20 characters. For sensitive scoping, request the PGP key first.

This form posts to an endpoint on this domain. No third-party service.