MLAOUDIS(1) User Commands MLAOUDIS(1)

mlaoudis@arizona:~$ man mlaoudis

Michael Laoudis

penetration tester · bug bounty hunter · web security researcher

mlaoudis --pentest --bugbounty --websec
    --location=Peoria,AZ --contact=michaellaoudis@gmail.com

Results-driven cybersecurity professional specializing in vulnerability assessments, penetration testing, and enterprise IT infrastructure security. Experienced in assessing web applications, APIs, databases, and Windows/Linux environments, with prior SOC experience triaging and remediating incidents in a 24/7 operations environment.

Delivers penetration testing and risk assessments primarily for government-sector clients as a government contractor holding a Public Trust position, with a focus on web application security testing and remediation.

TOOLS
--burp-suite-pro --plextrac --kali-linux --nmap --metasploit --bloodhound --wireshark --owasp-amass --docker --trivy --tenable-nessus --appdetective --readyapi --splunk-es --crowdstrike-falcon --vectra
SCRIPTING
--pythonAutomation, tooling, and OSINT scripts
--powershellWindows environment automation and reporting
--bashLinux shell scripting and automation
--javaGeneral-purpose application development
STANDARDS
--owasp-top-10Web application risk classification framework
--nist-800-53Federal security and privacy controls catalog
--cis-benchmarksVendor-agnostic hardening configuration standards
LANGUAGES
--englishFluent
--greekBasic proficiency
v4 Penetration Tester — Gunnison Consulting Group Mar 2025 – Present
  • Delivered client-facing engagements, including kick-off presentations to define testing scope and post-engagement debriefs to clearly communicate findings, risk impact, and remediation recommendations
  • Utilized Python and PowerShell scripting to automate workflows, including transforming raw JSON output from Trivy vulnerability scans into structured Excel reports for improved analysis
  • Conducted engagements for government-sector clients, assessing web applications, internal network environments, databases, and APIs, applying frameworks such as OWASP Top 10, NIST SP 800-53, and CIS Benchmarks
  • Regularly perform manual source code reviews across engagements, identifying vulnerabilities missed by automated scanning (e.g. blind SQL injection in unsanitized query parameters) and delivering client-facing writeups with proof-of-concept evidence and remediation guidance
  • Mentored and onboarded junior penetration testers by providing guidance on internal tooling, testing methodologies, and stakeholder communication to support effective delivery
v3 Cybersecurity Analyst — TBConsulting Feb 2024 – Dec 2024
  • Led mentorship and training of IT Operations staff in security detection, investigation, and escalation processes
  • Investigated over 40 user-reported phishing emails by identifying malicious indicators such as spoofed headers, relayed IP addresses, and social engineering techniques
  • Reduced alert fatigue by identifying and communicating hundreds of false-positive detections to clients for tuning, ensuring only genuine suspicious activity triggered investigation in a 24x7 SOC environment
  • Presented weekly security metrics to client stakeholders, including detection volume across Splunk, CrowdStrike, and Vectra, true/false positive rates, and status of open escalations, translating technical findings into actionable insights for non-technical audiences
v2 Help Desk Representative — FCG, Inc. May 2023 – Jan 2024
  • Provided Tier 1 and 2 IT support to clients over phone and email by remotely troubleshooting issues related to computer/printer hardware and software, Windows administration, TCP/IP networking, and Active Directory
v1 Bug Bounty Hunter (Freelance) — HackerOne Sep 2022 – Jan 2023
  • Identified and reported 3 high-impact and 2 medium-impact vulnerabilities in live websites, including a stored cross-site scripting vulnerability leveraged for full account takeover on a production web application
  • Performed offensive security testing of web applications for vulnerabilities on the OWASP Top 10 by utilizing tools such as Kali Linux, Burp Suite Pro, OWASP Amass, Nmap, Metasploit Framework, and Python/Bash scripting
GitHub Repository Web Scraper
$python3 github_repo_scraper.py --org <target>
Enumerates public repositories for exposed credentials.
Trivy Report Generator
$python3 trivy_report_generator.py scan.json
Parses Trivy Docker vulnerability scans into a formatted, severity-sorted Excel report.
Screenshot Taker
$python3 screenshot_taker.py --urls targets.txt
Automates web app screenshotting and file extraction across large sets of target URLs.
ΜΙΧΑΛΗΣ  ΛΑΟΥΔΗΣ
Michael Laoudis