Offensive Security · Cloud & M365 · AI · OSINT & Investigations

I find what others miss.

I’m Brandon Bennett — a penetration tester and cybersecurity analyst who uncovers real-world vulnerabilities across web apps, APIs, and cloud. I also administer and harden Microsoft 365 environments end to end — identity, endpoints, and compliance — and put prompt engineering to work speeding up security analysis, tooling, and development. That work extends into OSINT, cybercrime investigations, and financial-crime analysis (AML/CFT), where I map ownership and trace the connections others miss. From offensive testing to systems administration to AI-driven investigations, I turn findings into action.

Burp SuiteGraphQLOWASP Top 10 Microsoft 365Microsoft SentinelPython PowerShellPrompt EngineeringMaltego OSINTAML/CFT
Crimson Ghost crest
30+
Vulnerabilities found
18+
XSS in production
40+
Certifications
5+
Compliance frameworks
What I do

Five practices, one goal:
reduce real risk.

More about me →
01

Offensive Security

Penetration testing across REST and GraphQL using Burp Suite, Nmap, and Metasploit — mapped to the OWASP Top 10, reported with clear, prioritized remediation.

See the work →
02

Cloud & Microsoft 365

Hardening Entra ID, Intune, Exchange, Defender, and Purview, plus a Sentinel SOC lab — aligned to NIST, CIS, ISO 27001, SOC 2, and PCI-DSS.

Explore →
03

GRC & Automation

Control design and audit readiness, automated with Python, PowerShell, and Golang — and AI-driven workflows that speed up analysis.

Read more →
04

Prompt Engineering

Applying prompt engineering across LLMs to accelerate security analysis, triage, and tooling — building AI-driven workflows and evaluating models for development and vulnerability management.

Read more →
05

OSINT & Investigations

Open-source intelligence, cybercrime investigations, and AML/CFT analysis — mapping corporate ownership, tracing beneficial owners, and screening entities against sanctions and regulatory red flags.

Explore →
Investigations & OSINT

Following the paper trail.

Paper Trail on GitHub →

Beyond offensive and cloud security, I work in open-source intelligence (OSINT), cybercrime investigations, and financial-crime analysis — combating money laundering and the financing of terrorism (AML/CFT). I map corporate ownership, trace beneficial owners and officer networks, and screen entities against sanctions lists and regulatory red flags.

Maltego — Cybercrime Investigations Basel Institute — Combating Financial Terrorism Basel Institute — Open-Source Intelligence OpSec for Security Professionals
Featured project · GitHub

Paper Trail

An open-source OSINT tool that maps corporate ownership and officer relationships from public filings — SEC EDGAR, IRS Form 990, UK Companies House (persons with significant control), charity registers, and OFAC/BIS sanctions screening — into a relationship graph for due diligence and financial-crime investigations.

View on GitHub →

Need someone to find it first?

Start a conversation →