The Pentrox team

The ethical hackers who perform every Pentrox assessment

Five ethical hackers, each specialised in a different attack surface, so the person testing your systems has spent years on exactly that kind of target. Every finding is reviewed by a second hacker before publication.

Five hackers, five specialities

The team works under codenames here; clients know the names behind them.

Galahad

Senior Ethical Hacker, Attack Chaining and Domain Compromise

Read profileClose profile

He has spent more than ten years in offensive security, testing web applications, APIs, mobile apps, cloud environments and internal networks, with and without source code. His speciality is chaining findings that look minor on their own into full compromise of the application and the domain behind it. In one assessment he found a blind SQL injection hidden in a cookie header, unauthenticated and rate limited, and turned it into a complete customer database extracted over DNS. His fastest route to Domain Admin took one minute from the start of an internal test. He writes his own exploit code and tooling in Python, PHP and JavaScript, and audits source code in those languages and in Java. He has led penetration testing teams and built their vulnerability database and reporting method from scratch. He has delivered assessments for organisations in banking, e-commerce, the public sector and retail.

Certifications: OSCP

Merlin

Senior Ethical Hacker/Vulnerability Researcher

Read profileClose profile

He has spent more than ten years in offensive security and is the team's exploit developer: when a vulnerability has no public exploit, he writes one. He has discovered and weaponised vulnerabilities in web applications, infrastructure and embedded systems, including multiple publicly disclosed CVEs in widely deployed devices. His method follows the attacker's own: reverse engineering firmware, analysing patches and building reliable exploits from what he finds. During assessments he specialises in bypassing defensive controls and chaining vulnerabilities, and when standard approaches fall short he writes his own tooling. He is equally at home in wireless and physical scenarios, from WiFi intrusion and rogue access points to compromise of the device itself.

Certifications: OSCP, OSCE

Gawain

Senior Ethical Hacker, Web and Mobile

Read profileClose profile

He has been in offensive security since 2018 and is the team's mobile specialist, testing iOS and Android apps and the APIs behind them alongside web applications and external infrastructure. He works against the OWASP ASVS and MASVS standards and walks stakeholders through the exploitation path and the fix himself. He has found and responsibly reported previously unknown vulnerabilities in commercial products his clients relied on, and his research has been acknowledged by several of the world's largest technology companies. He spent years on an invite-only researcher network finding high and critical vulnerabilities in live environments, and has delivered assessments for organisations in finance, telecom, government and technology.

Certifications: OSCP, OSWE, eMAPT

Percival

Senior Ethical Hacker, Source Code Review and Web

Read profileClose profile

He has been in offensive security since 2019 and is the team's source code specialist. He reads PHP, Python and Java and audits applications from the inside out: the code shows him where the weak points are, and testing the running application proves which of them an attacker can reach. He tests web applications, APIs, mobile applications and networks, and spent several years doing so in-house at a financial services organisation and a telecom operator, where he also verified incoming bug bounty reports and worked with the blue team to sharpen its detection alerts. His reports are written so that developers can act on them without a second explanation.

Certifications: eWPTX

Lancelot

Ethical Hacker, Web Exploitation and Infrastructure

Read profileClose profile

He has been in offensive security since 2022 and is the team's web exploitation specialist, testing web applications, APIs and internal and external infrastructure. His focus is on finding critical vulnerabilities and reporting them for a technical audience, with the risk and impact worked out for the specific target rather than stated in general terms. In the past year alone he turned a server-side request forgery into command execution on the server, and a stored cross-site scripting flaw into a takeover of the admin account. On the infrastructure side he works from the attacker's perspective, uncovering weaknesses at network and server level and following them through privilege escalation and lateral movement. He scripts in Python and Bash and works with Burp Suite, Nmap, Metasploit and BloodHound.

Certifications: CPTS, BSCP, CWES

Different hackers, one standard

A penetration test is only as good as the person running it, and no two targets reward the same instincts. So Pentrox did not hire five versions of the same hacker. Each of us has gone deep in a different direction, source code review, web and API exploitation, mobile, research and exploit development, and the chaining of small findings into real business impact. Whatever a client brings us, someone here has spent years on exactly that surface, so no one is ever learning the domain on your systems. Every finding is then reviewed by a second hacker before it leaves, so a report carries more than one expert's judgement. The result is a test that reflects how a real attacker would work, and a clear view of where you actually stand.

Ready to Secure Your Environment?

Schedule a free intake call to scope your assessment. Pentrox identifies vulnerabilities in your applications, infrastructure, and cloud environments before attackers do.

Schedule an intake call