I’m Trevor Kems. My professional background combines penetration testing with infrastructure and systems administration. I work across web applications, internal and external networks, Active Directory, and the software and hardware inside embedded devices.
I enjoy taking systems apart: sometimes in software, sometimes with a debugger, and sometimes literally with a soldering iron. My independent research follows that curiosity into IoT cameras, proprietary protocols, cryptography implementations, and unusual hardware.
Areas of expertise
- Enterprise offensive security: web application and network penetration testing, Active Directory, ADCS, Kerberos, and social engineering.
- Vulnerability research: firmware and binary reverse engineering, protocol analysis, cryptanalysis, and coordinated vulnerability disclosure.
- Embedded and hardware security: firmware acquisition, serial interfaces, embedded Linux, ARM/MIPS analysis, and radio protocols.
My Operation Big Brother research resulted in three published CVEs. I also share technical investigations at conferences and community events, including Splunk .conf and SecDSM.
Certification
Offensive Security Certified Professional (OSCP) — earned August 2, 2022. Verify credential.
Away from the day job
I restore vintage computers, investigate unusual devices, and build projects for security competitions and the community. I’m interested in physical security, locksport, RFID, and the places where hardware and software trust meet.
Contact
My professional interests include senior offensive security, product security, vulnerability research, and security research. Remote U.S. / Central Iowa.
Email Trevor · GitHub · LinkedIn
Please include the topic of your message in the subject line.
Opinions on this site are my own and do not represent current or former employers.