Reconnaissance
& security research

Think like a criminal, act like a professional.

Reconnaissance and security researcher, based in Groningen, focused on how digital and physical intrusions develop.

Contact me before it happens.

About

I operate where security problems begin to form, not where they are already reduced to technical findings. Long before tools, exploits or controls become relevant, realistic attack paths exist in behaviour, routine and environment.

Modern threats rarely present themselves as isolated technical issues. They develop gradually through exposure, habit, human behaviour and overlooked dependencies across digital, physical and organisational domains.

By observing and correlating small details across these domains, patterns emerge that reveal realistic exposure and risk. These patterns typically exist long before a vulnerability is scanned or an incident is detected.

Field reconnaissance setup
Field reconnaissance in uncontrolled environments. Observing signals, behaviour and context as they naturally occur.

I am engaged to provide early insight: mapping realistic attack paths, assessing situational risk and translating abstract threats into concrete context that supports informed security decisions.

Capabilities

Reconnaissance & exposure mapping

Establishing situational awareness through structured reconnaissance and analysis of observable signals, infrastructure and behaviour across digital and physical environments.

This capability focuses on identifying realistic exposure, dependencies and attack paths at an early stage, before interaction, testing or exploitation occurs. Emphasis is placed on passive observation, correlation and context rather than intrusion.

By correlating indicators across technical, environmental and human domains, emerging risk becomes visible in its natural state. The result is verified context that supports security decisions prior to control selection, technical assessment or intervention.

Signal analysis tooling
Signal observation and technical context during reconnaissance.

OSINT investigations

Conducting structured open-source intelligence investigations to understand how individuals, organisations and networks manifest themselves across publicly observable digital environments.

The focus is on correlation rather than collection: identifying relationships, recurring behaviour and structural inconsistencies by analysing open information in context and over time.

By evaluating data longitudinally instead of as isolated findings, underlying patterns and dependencies become visible. This supports attribution, exposure assessment and situational understanding without interaction, manipulation or escalation.

OSINT terminal output
Correlation and aggregation of publicly observable data.

Physical reconnaissance & human pathways

Conducting authorised physical security assessments that examine how environments, controls and human behaviour interact under real-world conditions.

The focus is on observation and verification: how access controls, procedures and routines perform in practice, and how legitimate movement and behaviour can create unintended pathways through physical defences.

Findings are evidence-based and repeatable, highlighting where controls fail due to design, implementation or human routine. The outcome supports proportionate remediation, improved awareness and realistic readiness for both security and safety incidents.

Physical access observation
Real-world access conditions observed during physical reconnaissance.

Technical exploitation

Applying offensive security techniques to validate assumptions and determine whether identified exposure and attack paths are practically exploitable under real-world conditions.

Technical testing is used deliberately and selectively in support of reconnaissance, OSINT and physical assessment outcomes. The emphasis is on verification rather than volume: confirming how systems, processes and people respond when pressure is applied in a controlled adversarial context.

Exploitation serves as a validation mechanism, not an end in itself. It confirms whether observed exposure, behavioural assumptions or physical access translate into meaningful compromise, ensuring findings are grounded in evidence and context rather than theoretical vulnerability alone.

Offensive security tooling
Technical testing used to validate exposure identified through reconnaissance and analysis.

Applied scenarios & decision context

Bringing reconnaissance, OSINT, physical and technical findings together into controlled scenarios that make complex exposure and risk understandable without simplification.

Scenarios are derived from real observations and validated attack paths, demonstrating how routine, assumptions and small indicators converge into meaningful risk. The emphasis is on showing how situations unfold, not on showcasing individual techniques or tools.

These sessions support awareness, judgement and decision-making under uncertainty. The objective is not technical proficiency, but shared understanding: enabling participants to recognise early signals, interpret context correctly and intervene at the appropriate moment.

Scenario-based security briefing
Scenario-based briefings grounded in real reconnaissance and validated attack paths.

Skills

  • Reconnaissance
  • Situational awareness
  • Threat modelling
  • Attack chains
  • Decision dominance
  • Operational discipline
  • Restraint
  • Risk assessment
  • Adaptive planning
  • OSINT
  • SIGINT
  • Passive collection
  • Correlation
  • Pattern analysis
  • Attribution
  • Context building
  • Verification
  • Attack surface mapping
  • Exposure analysis
  • Adversarial validation
  • Assumption testing
  • Controlled exploitation
  • Network reconnaissance
  • Infrastructure mapping
  • Protocol analysis
  • Service enumeration
  • Dependency analysis
  • RF reconnaissance
  • Spectrum analysis
  • Passive capture
  • SDR
  • Physical reconnaissance
  • Access pathways
  • Perimeter analysis
  • Environmental observation
  • Human routing
  • Behavioural analysis
  • Routine modelling
  • Trust exploitation
  • Social engineering
  • Linux
  • Debian
  • Kali
  • Live environments
  • Virtualisation
  • Nmap
  • Masscan
  • Metasploit
  • BeEF
  • Hydra
  • Gobuster
  • Feroxbuster
  • Burp
  • SQLmap
  • Hashcat
  • Aircrack-ng
  • hcxdumptool
  • Wireshark
  • tcpdump
  • Responder
  • Impacket
  • CrackMapExec
  • BloodHound
  • Evil-WinRM
  • Netcat
  • Socat
  • John
  • theHarvester
  • SpiderFoot
  • Recon-ng
  • Maltego
  • Shodan
  • Censys
  • Amass
  • Subfinder
  • dnstwist
  • ffuf
  • Wfuzz
  • Searchsploit
  • Empire
  • Sliver
  • Cobalt Strike
  • Powershell
  • Mimikatz
  • Koadic
  • LinPEAS
  • WinPEAS
  • Ghidra
  • Radare2
  • HackRF
  • RTL-SDR
  • GNU Radio
  • Python
  • Bash
  • Shell
  • CLI workflows
  • Active Directory
  • Azure AD
  • Cloud environments
  • Containers
  • Evidence handling
  • Chain reconstruction
  • Risk translation
  • Security reporting
  • Operational debriefing
  • Fieldcraft
  • Low-profile operations
  • Improvisation
  • Self-reliance

Contact

This site functions as a professional reference point for clients, verification and context.

Secure communication
Signal:

Signal contact QR for eol.rip

Scan with Signal.
Operational discussion only.

Reference
eol.rip