Blake Grosskopf · Offensive Security Researcher
I build cloud and enterprise labs, then break them, and write the defense that stops me.
I'm an aspiring red teamer, currently shadowing a red team while I build and break my own labs. I stand up cloud and enterprise environments from scratch, get in from the outside, and push through to full control, then write the defense that would have stopped me.
- 01 Public blob recon T1526
- 02 App source disclosure T1530
- 03 Hardcoded secrets T1552.001
- 04 Forged admin JWT HS256
- 05 SSRF → file:// T1190
- 06 Storage key + SSH keys T1552.004
- 07 VM managed identity T1078.004
- 08 RG Contributor Impact
Approach
How I work
- Build
I stand up the range myself in Terraform, on real cloud with real constraints, so the attack path is genuine rather than a screenshot.
- Break
External-attacker lens, end to end: public exposure → tokens → secrets → subscription-level control. Evidence, not adjectives.
- Document
Every finding maps to MITRE ATT&CK and ships with its defense: the control, the detection, and the one change that breaks the chain.
02Latest writing
All writing03Cert spine
- SC-900 Security, Compliance & Identity Fundamentals Completed
- CARTP Cloud Attack & Red Team Professional Active
- SC-500 Cloud & AI Security Engineer Target
- PNPT Practical Network Penetration Tester Target
Looking for an offensive, cloud, or web-app security researcher?
I'm open to roles and collaboration. The fastest way to gauge fit is to read a case study, then say hello.