Skip to Main Content

Paul Koblitz

EXPERIENCE

Paul Koblitz is a Principal Security Consultant for TrustedSec. Paul recently assumed the role of Director of Technical Services for TrustedSec. This job entails managing 40 other employees and all of the technical penetration testing teams. He has expertise in physical and social engineering security has been honed over the years by using every opportunity possible to further develop his craft. It is not uncommon for Paul to be shopping and ask to talk to a store manager about how their security could be better by different camera placements. Paul also has extensive networking experience having worked for several years as a desktop support technician, a NOC operator, a head-end engineer, and a network engineer in the US Navy and for a local cable company.

EDUCATION & CERTIFICATIONS

Associate of Science, Electronic Engineering Technology, The University of Akron

INDUSTRY CONTRIBUTIONS

Volunteered at numerous local and national security conferences to include:

  • Black Hat 2013, 2014 and 2015 - Intro to Pentesting
  • Black Hat 2016 - Red Team vs. Blue Team
  • Black Hat 2017 - Red vs. Blue Techniques with Huntteaming
  • Black Hat 2018 - Defense and Offense: Understanding Attackers Through Red Team Tactics
  • Black Hat 2019 - A Practical Approach to Defense and Offense: Understanding Attackers Through Red Team Tactics and Purple Teams
  • DerbyCon 4 and 5- Intro to Pentesting
  • DerbyCon 6 and 7, Red Team vs. Blue Team

PASSION FOR SECURITY

Paul has always had a passion for security, focusing on the physical side. While in the US Navy, Paul was a Duty Master-at-Arms and part of the shipboard security team. In Paul’s off time from the military, he held several security-related jobs to include: late night and emergency locksmith, security systems installation consultant, and vehicle/personal property repossession. While working for TrustedSec, Paul has utilized his physical and social engineering skills in several fields of business such as; financial institutions, retail clothing chains, grocery store chains, manufacturing, and education. Paul also was the Head of Physical Security for DerbyCon.

Featured Blogs And Resources

Discover the blogs, analysis, webinars, and podcasts by this team member.

Blog November 07 2023

The Triforce of Initial Access

LootWhile Red Teamers love to discuss and almost poetically describe their C2 feature sets, EDR evasion capabilities, and fast weaponizing of N-day exploits,…

Read about this article
Blog November 02 2023

JS-Tap: Weaponizing JavaScript for Red Teams

How do you use malicious JavaScript to attack an application you know nothing about?Application penetration testers often create custom weaponized JavaScript…

Read about this article
Blog October 17 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 3)

This blog series was co-authored by Security Consultant Megan Nilsen and TAC Practice Lead Andrew Schwartz.1    IntroductionIn this third and final…

Read about this article
Blog October 12 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 2)

This blog series was co-authored by Security Consultant Megan Nilsen and TAC Practice Lead Andrew Schwartz.1    IntroductionThis is a continuation of A…

Read about this article
Blog October 11 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 1B)

This blog series was co-authored by Security Consultant Megan Nilsen and TAC Practice Lead Andrew Schwartz.1    IntroductionIn this continuation to our first…

Read about this article
Blog October 10 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 1A)

This blog series was co-authored by Security Consultant Megan Nilsen and TAC Practice Lead Andrew Schwartz.1    IntroductionIf you were to collectively ask any…

Read about this article
Blog September 21 2023

Basic Authentication Versus CSRF

I was recently involved in an engagement where access was controlled by Basic Authentication. One (1) of the findings I discovered was a Cross-Site Request…

Read about this article
Blog September 18 2023

Okta for Red Teamers

For a long time, Red Teamers have been preaching the mantra “Don’t make Domain Admin the goal of the assessment” and it appears that customers are listening.…

Read about this article
Blog September 05 2023

Creative Process Enumeration

Very often in engagements, you'll want to list out processes running on a host. One thing that is beneficial is to know is if the processes is a 64-bit or…

Read about this article
Blog August 31 2023

Crafting Emails with HTML Injection

Have you ever wanted to send an email from a domain you don’t have SMTP credentials for? With some HTML injection, we may be able to do just that. From time to…

Read about this article

Empower your business through better security design.

Talk directly with our experienced advisory consultants to learn how we can help.