Benjamin Iheukumere · Senior Cybersecurity Consultant

I combine offensive expertise with effective defense.

As an independent consultant, I help CISOs, IT leaders and technical teams understand complex cyber risks, prioritize them correctly and reduce them sustainably – from penetration testing and Microsoft security to networks, firewalls and critical infrastructure.

View Project Experience
  • Offensive and defensive security, seamlessly combined
  • Direct collaboration without layers of consulting
  • Analysis, prioritization and implementation through to validation
Benjamin Iheukumere, senior cybersecurity consultant
17+ Years of business and project responsibility
150+ Firewall and network migrations
OSCP+ Hands-on proof of offensive security expertise
Blue Team 01 Locked Shields 2026

Services

Deep technical expertise, pragmatic delivery.

I step in where risks need to be understood and resolved, not merely described. Depending on the project, I take responsibility for analysis, technical leadership, prioritization or implementation – working directly with stakeholders and without unnecessary handovers.

Penetration Testing & Attack Path Analysis

I assess internal networks, Active Directory and selected applications from an attacker's perspective. The result is a set of traceable attack paths, solid evidence and priorities that teams can act on.

Penetration TestingAttack PathsEvidence

Microsoft & Identity Security

I help secure Microsoft-centric environments – from Tier 0, privileged access and AD CS to domain controllers, Windows baselines and legacy authentication.

Active DirectoryTier 0Windows

Network & Perimeter Security

I analyze firewall and NGFW rule sets, VPN access, segmentation and logging. Legacy exceptions are assessed transparently and paired with safe remediation steps.

NGFWVPNSegmentationNetworks

Finding Remediation & Hardening

I turn findings from penetration tests, audits and internal reviews into concrete work packages, complete with owners, rollout path, rollback option, validation and defensible evidence.

HardeningRetestingImplementation

Security Advisory & CISO Sparring

I provide technical context for critical findings and architecture decisions, expose dependencies and help decision-makers weigh risk, effort and priorities with confidence.

CISO SupportArchitecturePriorities

Technical Project Support

I strengthen security projects as an experienced independent consultant – primarily remote, across the DACH region and on-site when needed. I work directly with CISOs, IT security, infrastructure and operations.

IndependentDACH-wideRemote & On-site

Working Together

Three practical ways to get started.

Depending on your situation, I begin with a focused assessment, structured remediation or support for an ongoing security project.

Focused Security Assessment

Trigger: When a penetration test, audit or internal suspicion points to a relevant risk – or when a solid baseline is missing.

Output: Technical assessment, traceable evidence, clear priorities and a realistic action plan for management and the delivery team.

Penetration TestingActive DirectoryMicrosoftNetworks

Structured Finding Remediation

Trigger: When open findings need to be prioritized, remediated technically and documented transparently for retesting.

Output: Ownership, remediation path, rollout plan, rollback option, validation method and a complete evidence package.

Pentest FindingsAuditsHardeningRetesting

Ongoing Project Support

Trigger: When a security project lacks experienced technical leadership, additional implementation capacity or independent sparring.

Output: Direct senior-level support for analysis, decisions and implementation – aligned with the team, schedule and operational constraints.

CISO SparringProject LeadershipImplementationDACH-wide

How I Work

Direct collaboration without detours.

At SafeLink IT, you work directly with me as the consultant accountable for the result – not with a sales layer or a rotating project team. I combine a management perspective, offensive analysis and operational implementation, and I stay with an issue until the decision, ownership and next step are clear.

  • One dedicated contact from the initial analysis to a defensible result
  • Technical depth and clear communication for management and operations
  • Project-based, DACH-wide and primarily remote – on-site when it benefits the project

Applied Defense Under Pressure

Locked Shields 2026: Defense when every minute counts.

At Locked Shields 2026, I was part of Blue Team 01 and responsible for securing and defending a Windows- and AD-adjacent domain in a critical-infrastructure scenario. Under continuous attack, my responsibilities included monitoring, analysis, containment, hardening and recovery – in close international collaboration and under intense time pressure.

Exercise and operational details are intentionally kept general for security reasons.

  • Active defense against ongoing red-team attacks on a Windows- and AD-adjacent domain
  • Hardening and recovery of security-critical services under time pressure
  • Coordination within an international, interdisciplinary blue team

Project experience

Accountability in real-world security projects.

Critical infrastructure / energy

Long-term advisory work covering continuous penetration testing, identity risk reduction, improvements to firewalls, proxies and IPS, as well as vulnerability management and audit preparation.

Logistics / incident recovery

Led the technical and organizational recovery after a security incident – including incident response, forensics, insurance, executive management and the rebuild of hybrid infrastructure.

Retail / penetration testing

Led internal penetration tests and Active Directory security assessments, including internal web applications, reporting and ongoing remediation support.

Research / VPN & ZTNA

Prepared a preliminary study and comparison matrix for VPN and ZTNA solutions, including a management decision paper and recommendations for the future network design.

Public Work Samples

A look at my technical work.

My public tools show how I approach security problems: transparently, repeatably and built for practical use.

SMB / credential exposure

secrets_find0r

A parallelized SMB share crawler that searches for exposed credentials, tokens and secrets during authorized assessments.

SMBSecretsAD Exposure
Active Directory / Kerberos

april26_ad_check0r

Read-only PowerShell checks for the Kerberos RC4/AES transition, exposing SPN accounts, KDC events and potential breakpoints before a change.

KerberosRC4AD Hardening
Firewall / NGFW

Sophos-XGS-Live-Log-Viewer

A Windows application providing near-real-time visibility into Sophos XGS logs over SSH, with filter presets, incident capture and a demo mode.

SophosNGFWLogs

Work Sample: AD Hardening Assessment

What an actionable security report looks like.

The sample report turns individual technical findings into a shared risk picture for management and the delivery team.

A report is useful only when technical teams and decision-makers understand the same priorities. This fictional sample shows the structure and depth of my AD hardening assessment – including an executive summary, prioritized findings, Tier 0 exposure, AD CS risks and a realistic 90-day plan.

Fictional sample – no real client data

Download the Sample Report
Fictional sample – no real client data

Turn findings into a realistic 90-day plan.

Effective hardening starts with the paths that actually control identities and systems. Changes are prioritized, introduced safely and then technically validated.

  • Executive summary
  • Prioritized finding register
  • Tier 0 exposure overview
  • AD CS risk notes
  • 30/60/90-day action plan

From the Field

Typical risks, placed in context.

These anonymized examples show how I connect technical findings with risk, evidence and a clear remediation path. No client data is used.

Domain Admin logon to a member server

Risk
A compromised member server can become a stepping stone to complete domain takeover.
Evidence
Privileged logons, local administrators, server role and EDR telemetry.

AD CS template without clear ownership

Risk
Overly broad enrollment rights or unsuitable intended purposes can enable the compromise of privileged identities.
Evidence
Template configuration, enrollment rights, EKUs, ownership and change logs.

Firewall rule without expiry

Risk
An exception intended to be temporary can develop into a permanent attack path.
Evidence
Owner, purpose, hit counts, logging, expiry date and change reference.

Pentest finding without technical validation

Risk
A closed ticket can become a finding again during retesting if the remediation was not validated reliably.
Evidence
Validation method, test scope, owner, rollout status and documented exceptions.

Certifications

Practice-oriented qualifications.

My certifications demonstrate technical focus in offensive security, Active Directory, penetration testing and red teaming. What matters is turning that knowledge into effective improvements for real-world environments.

OSCP+ Badge

OSCP+

OffSec Certified Professional+

OffSec · Active
OSCP Badge

OSCP

Offensive Security Certified Professional

OffSec · Active
PNPT Badge

PNPT

Practical Network Penetration Tester

TCM Security · Active
CEH Master Badge

CEH Master

Certified Ethical Hacker Master

EC-Council · Active
CEH Practical Badge

CEH Practical

Certified Ethical Hacker Practical

EC-Council · Active
CEH Badge

CEH

Certified Ethical Hacker

EC-Council · Active
THM PT1 Badge

THM PT1

Jr Penetration Tester

TryHackMe · Active
eJPT Badge

eJPT

Junior Penetration Tester

INE Security · Active
CRTP Badge

CRTP

Certified Red Team Professional

Altered Security · In progress
OSEP Badge

OSEP

OffSec Experienced Penetration Tester

OffSec · In progress

About Me

Entrepreneurial experience meets technical specialization.

  1. 2002-2005

    Studied business informatics at Rheinische University of Applied Sciences in Cologne, specializing in multimedia networks.

  2. 2006-2023

    Founded and led an IT systems house and managed cloud service provider as managing partner.

  3. Since 2023

    Independent cybersecurity consulting under SafeLink IT with both an offensive and defensive focus.

Security Blog

Insights from security practice.

Technical perspectives on Active Directory, Windows and Microsoft security, networks, vulnerabilities and effective hardening.

Block unapproved RMM tools: control remote administration

RMM tools are privileged admin paths. Sustainable control separates Tier 0, hardens approved services, and blocks shadow access through application and network controls.

Active DirectoryAD HardeningRMMApplication ControlPrivileged AccessIncident Response

Use password complexity correctly in AD: add length and banned password lists

AD's built-in complexity rule is only a baseline. Sufficient length, targeted fine-grained password policies and a controlled banned-password rollout create a stronger, measurable password standard.

Active DirectoryHardeningPassword PolicyFine-Grained Password PoliciesMicrosoft EntraIdentity Security

Disable reversible storage of AD passwords

A disabled policy value does not remove passwords that were already stored reversibly. Checking domain policy, fine-grained password policies and user options, followed by controlled password rotation, removes the exposure.

Active DirectoryHardeningPasswordsFine-Grained Password PoliciesService AccountsCredential Protection

Security Advisories

Current risks, placed in context.

Concise analysis of relevant vulnerabilities and changes: what is affected, how serious is the risk and what should responsible teams review now?

Teams support scam: attack path into Active Directory

Microsoft has observed a campaign using fake IT support contacts over Teams. Remote access, a silent MSI installation and WinRM lead toward domain controllers and certificate authorities.

MicrosoftMicrosoft TeamsActive DirectorySocial EngineeringWinRMIncident ResponseRemote Support

Windows IKE: CISA prioritizes CVE-2026-33824

CISA has added the critical Windows IKEv2 flaw CVE-2026-33824 to the KEV catalog. Update systems and restrict UDP 500/4500 to required peers.

MicrosoftWindowsCVE-2026-33824IKEv2IPsecRemote Code ExecutionPatch Management

Windows: CVE-2026-68820 actively exploited

Microsoft has fixed an actively exploited use-after-free flaw in the Windows Ancillary Function Driver for WinSock. Prioritize the August updates across clients and servers.

MicrosoftWindowsCVE-2026-68820WinSockPrivilege EscalationPatch Management

Contact

Let's discuss your security project.

Tell me briefly about your situation. I will respond personally – or you can choose a time directly through Microsoft Bookings.

Call directly Send an Email LinkedIn

Describe Your Project Briefly

Videos

Cybersecurity, explained clearly.

In my most-viewed videos, I explain Active Directory security, lateral movement, password attacks and essential protective measures using practical examples.

SO bewegen sich Hacker durch Dein Netzwerk - Lateral Movement mit Ligolo-NG

4.3K+ views

So cracken Hacker Deine Passwörter.

1.5K+ views

Angriff auf Active Directory in 2026 - Zum Domainadmin in 15 Minuten

1.5K+ views

Hacking 101: Einführung in Shells und Reverse Shells

830+ views