A breach costs more than a pentest.

I find the vulnerabilities in your systems before someone exploits them. Structured methodology, written deliverables, and a report your team can act on.

Daniel Ordonez Arango — Penetration Tester
  • 12 HTB paths completed
  • 720 HTB machines pwned
  • Top 1% HTB ranking

What I do

Web Application Pentest Find exploitable vulnerabilities in your app before a breach does. OWASP-aligned manual testing with a written report your team can act on immediately.
  • OWASP Top 10 manual testing
  • Severity-ranked PDF report
  • Business impact per finding
  • Remediation guidance included
Active Directory Pentest Find identity and privilege gaps in your Active Directory before lateral movement becomes a domain compromise. Identity-focused manual testing with a severity-ranked report your IT team can act on immediately.
  • Kerberos, ACL & delegation testing
  • Severity-ranked PDF report
  • Domain compromise path analysis
  • Remediation guidance included

All services include a free re-test after fixes are applied.

Real engagements, real findings

Automotive Industry · Colombia · 2026

5 Critical 3 High

Active SEO Spam Injection & Full Remediation

Hidden gambling SEO spam and exposed backups on WordPress — full cleanup verified in one session.

Background

I started as a full-stack developer. That background changes how I test — I know how applications are built, which means I know exactly where developers leave gaps.

My training covers the full offensive attack surface: web exploitation, Active Directory attacks, network pivoting, privilege escalation and post-exploitation techniques. I don't just find vulnerabilities — I explain why they exist, what a real attacker would do with them, and how to fix them correctly.

I work remotely with startups and SMBs across Latin America, the US and Europe. Fixed-price engagements, bilingual delivery, and a free re-test to confirm your fixes actually hold.

Training & Experience

Completed paths

Web Penetration Tester
CWES
Penetration Tester
CPTS
SOC Analyst
CDSA
Junior Cybersecurity Analyst
CJCA

In progress

Senior Web Penetration Tester
CWEE
Active Directory Pentesting Expert
CAPE
Offensive AI Expert
COAE
Wi-Fi Pentesting Expert
CWPE

Background

Full-Stack Developer

Structured engagement process

  1. Scoping & proposal

    Free scoping call to define your environment, targets and rules of engagement. You receive a written proposal with scope, methodology, fixed price and NDA — before any work begins.

  2. Assessment & testing

    Manual offensive testing with progress updates throughout. Critical and high findings are reported immediately — not held for the final report.

  3. Reporting & verification

    Severity-ranked PDF report with evidence and remediation steps. Free re-test included to verify your fixes hold.

Get an instant estimate

01

Choose your service

02

Environment parameters

Scope

Complexity

03

Testing type

Black-box No prior knowledge of the target. Simulates a real external attacker. Ideal to test your defences from an adversarial perspective. ✓ Most common
Grey-box Partial credentials or context provided. Simulates a compromised account or insider threat. Best coverage-to-cost ratio. ✓ Recommended
White-box Full access + source code provided. Maximum depth and coverage. Best for thorough audits or when regulations require it. ✓ Most thorough

Selected service

Web App Pentest

Estimated range

$2,000 $5,000 USD
Scope Small · 1–5 targets
Complexity Standard
Testing Black-box
Duration 1–2 weeks
Book a free scoping call

Automated estimate only — not a binding quote.
A signed authorization agreement is required before any engagement begins.

Common questions

Web app from $2,000 · Active Directory from $3,000. Use the pricing calculator above for an instant estimate, or book a free scoping call.

Cost, focus, and direct access. As a LATAM-based independent tester, my rates are significantly lower than US/EU firms without sacrificing methodology or quality. You work directly with the person doing the testing — from scoping to final report.

I report it immediately — you don’t wait for the final report. Critical and high findings are communicated as soon as confirmed so your team can begin remediation while the engagement is still active.

Direct message