[...]
INIT: aluc-security v3.0 — secure boot sequence engaged
KERNEL: hardened, grsecurity-style mitigation layers active
AUDIT: continuous monitoring — zero trust by design
[...]

root@aluc:~/whoami

Crypto Mathematician — Hacker, Researcher, Organizer.

Red Teaming, Blue Teaming, critical infrastructure. Founder and organizer of BerlinSides — a conference by hackers for hackers.

I don't just do IT security. I live it. 20+ years in the field. For banks. For critical infrastructure operators. For government agencies. For organizations that understand security is not a product — it's a process.

Muay Thai. Firearms instructor. Daito-ryu Aikijujutsu – Mainline Shimbucho. Philosophical principle: "Never strike. But if you must: strike correctly."

speaker / talks

Speaker at international conferences — CCC, Confidence, Balccon, FSec among others. Topics: quantum cryptography, red teaming, physical security, OpSec and social engineering.

No bullshit keynotes. No vendor pitches. Only hard stuff from the front line.

services

Pentest

Web, mobile (iOS/Android), APIs, infrastructure, OT/IoT. Conducted per OSSTMM and PTES standards. Code reviews. Architecture reviews. No scanner dumps — real, manual deep-dive testing.

Red Team Assessment

Realistic, targeted attack simulations. Full-scope or focused. Social engineering, physical penetration, network infiltration, Active Directory takeover. I think like an adversary — because I am one.

Blue Team Strategy

Building and optimizing your defense. SIEM architecture (Wazuh/Splunk/ELK), detection engineering, IOC development, threat hunting. Strategy that holds — not just logs that burn.

Incident Response Plan

Emergency processes that work under fire. Playbooks, communication chains, forensics-ready infrastructure. Including tabletop exercises and live drills.

Forensic

Digital forensics by the book. Memory analysis, disk forensics, network forensics, mobile forensics. For incident response or evidence preservation.

Code Review

Manual code analysis for security vulnerabilities. No SAST tool results. Architecture reviews, threat modeling, source-level vulnerability assessment.

Data Security

Privacy impact assessments, encryption strategies, data loss prevention (DLP), data classification, GDPR-compliant data architecture. Protecting data at rest, in transit, and in use.

AI Security Services

Security auditing and hardening of AI/ML pipelines. Adversarial robustness, model hardening, prompt injection prevention. Security architecture for AI-driven systems — from data source to decision.

Business Impact Analysis

Impact analysis for KRITIS and financial sector. Criticality assessment, recovery objectives (RTO/RPO), dependency analysis. Foundation for BCM and emergency planning.

KRITIS / Critical Infrastructure Consulting

BSI baseline protection, KRITIS regulation (BSI-KritisV), ISO 27001 based on IT-Grundschutz. Business continuity management and emergency drills. Audits per §8a / §8b BSI-Act.

Security Awareness

Not boring Powerpoint. Real, hands-on awareness. Phishing simulations, live hacking demos, workshops that actually stick.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

selected references (kritis & financial sector)

Over 20 years of work for the following organizations — from DAX-listed corporations to mid-sized critical infrastructure operators:

and more — references and project details available upon request.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

contact

No contact-form bullshit. You reach me directly:

aluc @ aluc-security • de
XMPP: aluc @ aluc-security • de
PGP: upon request

No recruiters. No salespeople. No "innovative cyber-security solution" emails.

If you need a real hacker — write.