Penetration Tester & Security Researcher. Seit 2020 in Bug Bounty aktiv (HackerOne & Bugcrowd, 20+ verifizierte Findings in privaten / invite-only Programmen), regelmäßig auf HackTheBox, ehrenamtliche Vorträge an bisher 8 Schulen zu KI-Sicherheit und Cybersecurity. Background aus der industriellen Automatisierung (Siemens S7, SCADA) — direkter Zugang zur OT/ICS-Security.
🎯 Offen für Pentest-/Red-Team-Rollen — Remote weltweit oder Deutschland. 🛡️ Betreibe [JB] Security, eigene Freelance-Pentest-Praxis: jb-security.de
- Penetration Testing — Web, API, Netzwerk, Active Directory
- Bug Bounty — private & invite-only Programme (HackerOne, Bugcrowd), Schwerpunkt Business-Logic & Exploit-Chains
- Red Team — Homelab mit isoliertem AD, HTB, eigene dokumentierte Methodik
- OT/ICS Security — Siemens S7, SCADA, IT/OT-Schnittstellen
- Security Awareness — Vorträge an Schulen zu LLMs, KI-Risiken & Cybersecurity
Offensive: Burp Suite Pro · Metasploit · Nmap · ffuf · sqlmap · Hydra · Nessus · Wireshark
AD/RedTeam: BloodHound · Impacket · CrackMapExec · Kerberoasting · AS-REP Roasting · RBCD · ADCS
Scripting: Python · Bash · PowerShell · JavaScript
OT/ICS: Siemens S7 (SPS) · SCADA · Industriesteuerungen · Feldbusse
OS: Kali Linux · Parrot OS · Windows Server · Active Directory · Docker
| Repo | Inhalt |
|---|---|
| 🛡️ jb-security | [JB] Security — Freelance-Pentest-Site (Web, AD, OT/ICS · OWASP, PTES, NIST, MITRE) |
| 🔴 bug-bounty-reports | Sanitisierte Bug-Bounty-Reports — Chained RCE (CVSS 9.9), Command Injection (CVSS 9.8) |
| HTB-Writeups | Deutsche Writeups für retired HTB Machines — komplette Angriffsketten von Recon bis Root |
| Study-Notes | Methodik-Playbook: AD-Angriffe, Linux/Windows PrivEsc, Nmap, Burp, Reporting |
| JBMTP07.github.io | Portfolio & CV |
| Zertifizierung | Anbieter | Status |
|---|---|---|
| Security+ (SY0-701) | CompTIA | ✅ Bestanden 05/2026 |
| Network+ | CompTIA | 📅 Prüfung 06–07/2026 |
| Linux+ | CompTIA | 📅 Prüfung 06–07/2026 |
| PenTest+ | CompTIA | 📅 Prüfung 06–07/2026 |
| CEH v13 | EC-Council | 📅 Prüfung 06–07/2026 |
| OSCP | OffSec | 🎯 Geplant Q4 2026 |
Kurse abgeschlossen über New Horizons (zertifizierter Bildungsträger)
📧 josefbasner@proton.me 🌐 jbmtp07.github.io · jb-security.de 🌍 Deutschland · Remote weltweit möglich