root@aluc:~/whoami
Crypto Mathematician — Hacker, Researcher, Organizer.
Red Teaming, Blue Teaming, critical infrastructure. Founder and organizer of BerlinSides — a conference by hackers for hackers.
I don't just do IT security. I live it. 20+ years in the field. For banks. For critical infrastructure operators. For government agencies. For organizations that understand security is not a product — it's a process.
Muay Thai. Firearms instructor. Daito-ryu Aikijujutsu – Mainline Shimbucho. Philosophical principle: "Never strike. But if you must: strike correctly."
speaker / talks
Speaker at international conferences — CCC, Confidence, Balccon, FSec among others. Topics: quantum cryptography, red teaming, physical security, OpSec and social engineering.
No bullshit keynotes. No vendor pitches. Only hard stuff from the front line.
services
Pentest
Web, mobile (iOS/Android), APIs, infrastructure, OT/IoT. Conducted per OSSTMM and PTES standards. Code reviews. Architecture reviews. No scanner dumps — real, manual deep-dive testing.
Red Team Assessment
Realistic, targeted attack simulations. Full-scope or focused. Social engineering, physical penetration, network infiltration, Active Directory takeover. I think like an adversary — because I am one.
Blue Team Strategy
Building and optimizing your defense. SIEM architecture (Wazuh/Splunk/ELK), detection engineering, IOC development, threat hunting. Strategy that holds — not just logs that burn.
Incident Response Plan
Emergency processes that work under fire. Playbooks, communication chains, forensics-ready infrastructure. Including tabletop exercises and live drills.
Forensic
Digital forensics by the book. Memory analysis, disk forensics, network forensics, mobile forensics. For incident response or evidence preservation.
Code Review
Manual code analysis for security vulnerabilities. No SAST tool results. Architecture reviews, threat modeling, source-level vulnerability assessment.
Data Security
Privacy impact assessments, encryption strategies, data loss prevention (DLP), data classification, GDPR-compliant data architecture. Protecting data at rest, in transit, and in use.
AI Security Services
Security auditing and hardening of AI/ML pipelines. Adversarial robustness, model hardening, prompt injection prevention. Security architecture for AI-driven systems — from data source to decision.
Business Impact Analysis
Impact analysis for KRITIS and financial sector. Criticality assessment, recovery objectives (RTO/RPO), dependency analysis. Foundation for BCM and emergency planning.
KRITIS / Critical Infrastructure Consulting
BSI baseline protection, KRITIS regulation (BSI-KritisV), ISO 27001 based on IT-Grundschutz. Business continuity management and emergency drills. Audits per §8a / §8b BSI-Act.
Security Awareness
Not boring Powerpoint. Real, hands-on awareness. Phishing simulations, live hacking demos, workshops that actually stick.
selected references (kritis & financial sector)
Over 20 years of work for the following organizations — from DAX-listed corporations to mid-sized critical infrastructure operators:
- Deutsche Bank
- Deutsche Bank Group Audit
- LEAG
- Vattenfall
- BEW
- KfW
- Dresdner Bank
- Deutsche Bahn
- WobCom
- Vossloh
- Thales
and more — references and project details available upon request.
contact
No contact-form bullshit. You reach me directly:
aluc @ aluc-security • de
XMPP: aluc @ aluc-security • de
PGP: upon request
No recruiters. No salespeople. No "innovative cyber-security solution" emails.
If you need a real hacker — write.