About
Blake Grosskopf
Offensive Security Researcher.
I'm an aspiring red teamer working cloud and enterprise attack paths. The throughline in everything I do is that I don't just point tools at someone else's target. I build the environment myself, break in from the outside, then write the defense that would have stopped me.
That comes from a software-engineering background, so the instinct underneath all of it is building. I like taking something apart to see how it works, then turning what I learn into something usable: a script, a small tool, a primitive, in Python or whatever fits.
On the cloud side I chain real Azure attack paths from public exposure to subscription-level control, standing the range up in Terraform and working around the constraints of a locked-down subscription. Right now my focus is cloud and AI security, and pen testing.
Everything here is self-directed research on infrastructure I own or am cleared to test, and it stays dual-use: methodology, ATT&CK mapping, and hardening. The runnable tooling stays private. What I publish is the understanding and the defenses.
01Skills, and the evidence
| Capability | What it covers | Evidenced by |
|---|---|---|
| Azure attack paths | Public exposure → IMDS / managed-identity abuse → storage, secrets, and subscription-level control | Vermillion Drift → |
| Cloud range building (Terraform) | Standing up real, misconfigured cloud environments as IaC, then troubleshooting live deployments | Vermillion Drift → |
| Active Directory enumeration & priv-esc | Mapping privilege-escalation paths across a Windows domain with PowerShell, Windows RSAT, and the Active Directory module | Resume → |
| Threat-based risk assessment | MITRE ATT&CK / NIST-aligned methodology; phishing triage at enterprise scale | Resume → |
| ATT&CK mapping & detection | Every finding mapped to a technique and paired with the control or detection that breaks it | Vermillion Drift → |
| Offensive tooling (Python) | stdlib-first: captured traffic in, working primitive out | Vermillion Drift → |
02Cert spine
- SC-900 Security, Compliance & Identity Fundamentals Completed
- CARTP Cloud Attack & Red Team Professional Active
- SC-500 Cloud & AI Security Engineer Target
- PNPT Practical Network Penetration Tester Target