Drew AllemanOffensive Security

Independent Offensive Security

Freelance Pentesting Services

I'm Drew Alleman - an independent penetration tester. My primary work is web application penetration testing: during pre-engagement, I plan the exact test surface with you before I break into apps and APIs by hand. I use the OWASP Web Security Testing Guide (WSTG) as my web-app testing methodology, then hand you a report your engineers can actually act on.

OSCP+ PenTest+ Security+

Why Manual Matters

A scanner finds the noise. I find the way in.

Automated tools are a starting point, not a test. The vulnerabilities that actually get companies breached - chained logic flaws, broken access control, the API endpoint nobody looked twice at - take a human who reads traffic and thinks like an attacker.

  • Hands on keyboard, every finding. Tools inform the work; they don't do the work.
  • Proof, not guesses. Every critical and high finding ships with a video demo of the proof - not just a text PoC - so your team can see exactly how it works.
  • Published research and writeups. My research blog is 25+ deep technical writeups. You can read exactly how I work before you ever hire me.

Latest from the blog

Recent research and walkthroughs

Deep technical writeups from engagements, labs, and research - so you can see how I work before we talk.

Latest

TryHackMe Management Wants a Word Walkthrough

2026-09-28 | writeups

A walkthrough of TryHackMe's hard forensics challenge Management wants a Word, covering KAPE triage, DPAPI, Chrome, and VeraCrypt.

Read post ->

Ready When You Are

Let's find your gaps first.

Tell me what you're running and what you're worried about. I'll come back with a scope and a straight answer on effort and cost - usually within two business days.

Request a Test