10+ Years in this field and I still feel like a NOOB. Oh well, this is me!
Been in-house for the last 4 years. I heart: Red teaming, Pentesting (2 polar opposites btw); Security Research in general...
I'm also a habitual hand raiser for the test nobody wants: Thick Clients & NetPen.
Independent Security Consultant. I genuinely like being in the field!
My lane: thick clients. Everyone's off fuzzing web forms while the desktop app sits there with local admin, a signing cert, an auto-updater, and the structural integrity of a screen door. I got tired of testing those slowly, so I built the tooling that doesn't. Then I wrote down how, which is the repo below.
Also fluent in
- Red team and adversary emulation. Physical/On-site, Social Engineering, Network, the whole walk from the parking lot to domain admin.
- Web3 and smart-contracts (Oohhh yeaa... $$$).
- Agentic AI, LLM, and agent security. = New toys, same old habit of trusting input they shouldn't. Just faster now.
Public work
- Exploit Nation: Book 01, ThickClientAllTheThings, the desktop-app methodology I wanted on day one and had to write myself. Source.
- More books, incoming.
Certs, for the box-checkers Zero Point Security CRTO 路 Certified Web3 Hacker 路 Blockchain Security Expert 路 CompTIA CySA+ 路 Cisco CyberOps Associate 路 INE Cloud Associate 路 AWS Cloud Foundations
Find me
- LinkedIn: https://linkedin.com/in/jerrod-baker
Assessment and validation is authorized work only. Everything here is for defensive and educational use.


