AD Hardening Snapshot
Focused assessment for Microsoft-centric environments: Tier 0, privileged groups, AD CS, Domain Controllers, legacy authentication and a prioritized 30/60/90-day roadmap.
AD & Windows Security Hardening
I help CISOs, IT security leads and infrastructure teams turn messy AD, Windows and firewall findings into prioritized remediation work without breaking operations: Tier 0, privileged access, AD CS, Domain Controllers, NGFW rules and pentest findings that need to stay fixed.
Positioning
For organizations that do not need another abstract security conversation. They need to know which AD, Windows and firewall paths are actually risky, who owns them, and how to close them safely.
Focused assessment for Microsoft-centric environments: Tier 0, privileged groups, AD CS, Domain Controllers, legacy authentication and a prioritized 30/60/90-day roadmap.
Close findings so they stay closed in retest: owners, evidence, validation queries, rollout paths and technical implementation without guesswork.
Clean up rules, VPNs and segmentation: owner, reason, expiry, logging, risk and safe cleanup steps instead of inherited exceptions.
Practical hardening of Windows and Microsoft security controls: admin workstations, Credential Guard, Defender/EDR, NTLM reduction and baselines.
Technical assessment of critical findings, architecture decisions and roadmaps for leaders who need to know what should really be prioritized.
Remote-first freelance support for projects from roughly three months. Direct collaboration with CISO, IT security, infrastructure and operations.
Offers
Clear scope, clear evidence, clear next steps. No black-box consulting.
Trigger: When an audit, pentest or internal review has surfaced Active Directory risk.
Output: Executive summary, prioritized finding register, Tier-0 exposure, AD CS risks, quick wins and 30/60/90-day roadmap.
Trigger: When rules have grown over time, nobody knows the owner, or segmentation is no longer defensible.
Output: Risky rules, missing owners, logging gaps, remote-access paths and a safe cleanup backlog.
Trigger: When findings need to be closed and must not reopen during retest.
Output: Owner, fix path, validation query, rollout plan, rollback option and evidence pack for retest and management.
Engagement model
Engagements are usually project-based and start at roughly three months. Full-time, part-time or advisory retainer setups are possible. Remote first across DACH, with on-site onboarding when it benefits the project.
Locked Shields
Participation in Blue Team 01 at Locked Shields '26, the world's largest and most complex live-fire cyber defense exercise simulating an armed conflict. The NATO exercise involves roughly 42 nations, more than 4,000 participants and around 8,000 systems including special systems from critical infrastructure environments. I was responsible for a domain including a domain controller in a critical-infrastructure scenario, with particular focus on domain hardening and active defense against ongoing attacks under extreme time and decision pressure. The role covered monitoring, analysis of network- and host-based indicators, containment of malicious activity, system hardening, restoration of compromised services and continuity of critical infrastructure components.
Further details are intentionally kept general because exercise and operational information is sensitive.
Project experience
External IT security consultant for continuous penetration testing, AD risk reduction, firewall/proxy/IPS improvements, vulnerability management and audit preparation.
Security Incident Lead coordinating incident response, forensics, insurance, executive stakeholders and technical rebuild of hybrid infrastructure.
Lead pentester for Active Directory security assessments, internal penetration testing, internal web apps, reporting and ongoing remediation support.
Pre-study, comparison matrix and management decision paper for VPN/ZTNA solutions including network design recommendations.
GitHub / Proof of work
Three public repositories as technical work samples: built around the same AD, SMB and firewall problems that show up in real environments.
Multithreaded SMB share crawler for finding exposed credentials, tokens and secrets in authorized assessments.
Read-only PowerShell checks for the April 2026 Kerberos RC4/AES change: SPN accounts, KDC events and likely breakpoints before cutover.
Windows app for near-real-time Sophos XGS log visibility over SSH, including filter presets, incident capture and demo mode.
AD Hardening Snapshot
I help companies turn messy Active Directory risk into a clear, prioritized hardening roadmap - especially around Tier 0, privileged access, AD CS, and Domain Controller protection.
Most organizations do not need more fear. They need clarity. This fictional sample report shows the kind of output an AD Hardening Snapshot produces: executive summary, prioritized findings, Tier-0 exposure view, AD CS risk notes, and a practical 90-day roadmap.
Fictional sample - no real client data
Good AD hardening is not about changing every setting at once. It is about understanding what controls the domain, which paths matter most, and which remediation steps are safe for real IT teams.
Anonymized proof library
No client data. No drama. Just recurring findings that show how I turn risk into workable remediation.
Credentials
The certifications show a clear focus on hands-on offensive security, Active Directory, penetration testing and reliable security advisory.
OffSec Certified Professional+
OffSec · Active
Offensive Security Certified Professional
OffSec · Active
Practical Network Penetration Tester
TCM Security · Active
Certified Ethical Hacker Master
EC-Council · Active
Certified Ethical Hacker Practical
EC-Council · Active
Certified Ethical Hacker
EC-Council · Active
Jr Penetration Tester
TryHackMe · ActiveJunior Penetration Tester
INE Security · Active
Certified Red Team Professional
Altered Security · In progress
OffSec Experienced Penetration Tester
OffSec · In progressBackground
Diploma in business informatics at Rheinische FH Köln, focused on multimedia networks.
Managing partner of an MSP and managed cloud service provider.
IT freelancer under SafeLink IT focused on offensive and defensive cybersecurity.
Blog
Technical notes on Active Directory security, hardening, incident readiness and measurable risk reduction.
Security News
Concise but actionable advisories on relevant Microsoft, Windows and Active Directory topics: concrete impact, risks and next steps without alarmism.
Contact
For project requests, retainer advisory or a quick technical assessment: contact directly or choose a Microsoft Bookings slot.
YouTube
The four most viewed videos from the SafeLink IT YouTube channel: concise context on Active Directory security, lateral movement, password attacks and security fundamentals.
4.3K+ views
1.5K+ views
1.5K+ views
830+ views