I find what others miss.
I’m Brandon Bennett — a penetration tester and cybersecurity analyst who uncovers real-world vulnerabilities across web apps, APIs, and cloud. I also administer and harden Microsoft 365 environments end to end — identity, endpoints, and compliance — and put prompt engineering to work speeding up security analysis, tooling, and development. That work extends into OSINT, cybercrime investigations, and financial-crime analysis (AML/CFT), where I map ownership and trace the connections others miss. From offensive testing to systems administration to AI-driven investigations, I turn findings into action.
Five practices, one goal:
reduce real risk.
Offensive Security
Penetration testing across REST and GraphQL using Burp Suite, Nmap, and Metasploit — mapped to the OWASP Top 10, reported with clear, prioritized remediation.
See the work →Cloud & Microsoft 365
Hardening Entra ID, Intune, Exchange, Defender, and Purview, plus a Sentinel SOC lab — aligned to NIST, CIS, ISO 27001, SOC 2, and PCI-DSS.
Explore →GRC & Automation
Control design and audit readiness, automated with Python, PowerShell, and Golang — and AI-driven workflows that speed up analysis.
Read more →Prompt Engineering
Applying prompt engineering across LLMs to accelerate security analysis, triage, and tooling — building AI-driven workflows and evaluating models for development and vulnerability management.
Read more →OSINT & Investigations
Open-source intelligence, cybercrime investigations, and AML/CFT analysis — mapping corporate ownership, tracing beneficial owners, and screening entities against sanctions and regulatory red flags.
Explore →Following the paper trail.
Beyond offensive and cloud security, I work in open-source intelligence (OSINT), cybercrime investigations, and financial-crime analysis — combating money laundering and the financing of terrorism (AML/CFT). I map corporate ownership, trace beneficial owners and officer networks, and screen entities against sanctions lists and regulatory red flags.
Paper Trail
An open-source OSINT tool that maps corporate ownership and officer relationships from public filings — SEC EDGAR, IRS Form 990, UK Companies House (persons with significant control), charity registers, and OFAC/BIS sanctions screening — into a relationship graph for due diligence and financial-crime investigations.
View on GitHub →Where to next.
Background
Experience, education, and the full skill stack.
→ 02 / ProjectsProjects
SOC lab, CTF machines, bug-bounty research, and open-source tools.
→ 03 / BlogBlog
Tutorials and write-ups on offensive and cloud security.
→ 04 / ContactContact
Open to roles and collaborations — let’s talk.
→ 05 / CodeGitHub
Open-source tools: Paper Trail, Acronomicon, creedGEN, cyberPUNKED.
→