Think Like
an Adversary.
Defend with Precision.

Senior offensive security consultant specializing in Active Directory exploitation, red team operations, cloud identity, and adversary simulation.

Get in Touch → View Services
7+
Years in offensive security
11+
Certifications
AD/Cloud
Deep specialization
75+Pentests Delivered
7+Years In Offensive Security
11+Certifications
95%Domain Compromise Rate

Offensive Security
Built Around Your Threat.

Every engagement is scoped to your environment, your adversary, and your risk tolerance. No off-the-shelf reports. No checkbox pentests.

01
Network

Internal Network Pentest

Simulate a threat actor with internal access. Identify lateral movement paths, privilege escalation opportunities, and critical asset exposure before a real attacker does.

KerberoastingACL AbuseBloodHoundPass-the-Hash
Scope an engagement
02
Perimeter

External Penetration Testing

Simulate internet-facing adversaries targeting your exposed infrastructure, web apps, VPN gateways, and cloud perimeter from the outside in.

OWASP Top 10VPN / Remote AccessCloud Exposure
Scope an engagement
03
Social Engineering

Phishing & Vishing

Targeted phishing campaigns and pretexting exercises that test your human layer. Credential harvesting, payload delivery, and awareness gap analysis.

GoPhishPretextingCredential Harvest
Scope an engagement
04
Active Directory

AD Security Assessment

Deep identity-focused analysis. Privilege escalation paths, delegation misconfigs, GPO weaknesses, and ACL abuse chains mapped with BloodHound.

BloodHoundDelegationACL AbuseKerberos
Scope an engagement
05
PKI / ADCS

ADCS / PKI Security Audit

Certificate Services attack surface review covering ESC1–ESC16 misconfigurations, enrollment agent abuse, and NTLM relay vectors using Certipy.

ESC1–ESC16CertipyPKI HierarchyNTLM Relay
Scope an engagement
06
Red Team

Full-Scope Red Team

Multi-phase adversary emulation across physical, digital, and human attack surfaces. C2 infrastructure, evasion, persistence, and lateral movement to crown jewels.

Cobalt StrikeC2 InfraEvasionPersistence
Scope an engagement
01
Detection

Purple Team Exercises

Structured attack simulations with real-time detection validation. Measure your SOC's MTTD, tune SIEM rules, and close gaps before attackers find them.

Detection Eng.SIEM ValidationMTTD
Scope an engagement
02
Reporting

SIGMA Rule Development

Custom detection rules built from attacker behavior observed during engagements. Delivered in SIGMA format compatible with Splunk, Elastic, and Sentinel.

SIGMASplunkElasticSentinel
Scope an engagement
03
Training

Tabletop Exercises

Scenario-based exercises for security teams, leadership, and incident responders. Walk through real attack chains and test your response playbooks.

IR PlaybooksLeadershipScenarios
Scope an engagement
04
SIEM

SIEM Health Check

Validate your logging coverage, data quality, and detection logic. Identify gaps in visibility before they become blind spots during an active incident.

Log CoverageWazuhSplunkElastic
Scope an engagement
01
Azure / Entra

Azure / Entra Security Review

Cloud identity attack paths including service principal abuse, Conditional Access gaps, Azure RBAC misconfigurations, and hybrid identity escalation.

Entra IDService PrincipalsToken AbuseRBAC
Scope an engagement
02
Identity

Hybrid Identity Attack Assessment

Evaluate attack paths that span on-prem AD and Entra ID. Lateral movement from domain to cloud and vice versa via ADFS, PTA, PHS misconfigurations.

ADFSPTA / PHSAADConnectEntra
Scope an engagement
03
Compliance

Cloud Security Posture Review

Assess your cloud configuration against CIS Benchmarks and compliance frameworks. Identify misconfigurations, over-permissive policies, and exposure risk.

CIS BenchmarksCSPMSOC 2CMMC
Scope an engagement
01
Static Site
Hardened Static Site
Custom static HTML on hardened nginx. Security headers, fail2ban, SSL, structured data, GA4, Google Business Profile. No WordPress attack surface. Loads in under 1 second.
HSTSCSPfail2banSEO
View services
02
WordPress
Hardened WordPress
WordPress when you need a CMS — locked down the way an offensive security professional would. xmlrpc blocked, wp-login rate-limited, Wordfence configured, DISALLOW_FILE_EDIT enforced.
Wordfencexmlrpc BlockedRate Limited
View services
03
Review Engine
Automated Google Reviews
3-message automated sequence that converts past customers into Google reviews. Reactivation campaign against your existing list. Most clients see 20–40 new reviews in 30 days.
3-Message SequenceClick TrackingMonthly Report
View services
04
SEO / GEO / AEO
AI & Search Visibility
Traditional SEO gets you found on Google. GEO gets you cited by ChatGPT and Perplexity. AEO structures your content for AI answer engines. Structured data, Core Web Vitals, monthly reporting.
LocalBusiness SchemaGEOCore Web Vitals
View services
05
Managed Hosting
Fully Managed VPS Hosting
Dedicated VPS on hardened nginx. Monthly security audits, SSL auto-renewal, daily backups, uptime monitoring, fail2ban log review, 2hr/month content updates included.
99.9% UptimeDaily BackupsSecurity Audit
View services
06
Web Security
Web Security Audit
We audit your existing site the way an attacker would. Headers, exposed paths, PHP misconfigs, open redirects, outdated plugins, info disclosure — then we fix everything we find.
Header AnalysisPHP AuditFixes Included
View services
// attack surface coverage

Every Attack Path.
Mapped & Tested.

We don't run scanners and call it a pentest. Every engagement maps the actual kill chain — from initial access through lateral movement to domain compromise. BloodHound, Certipy, Cobalt Strike, Impacket — real tools, real techniques, real findings.

ESC1ESC15
ADCS Coverage
6+
Active Certs
AD+AAD
Identity Coverage
100%
Custom Reports
Attack Chain
Phishing → DA ✓
ESC Finding
ADCS ESC1 Detected
Evasion
EDR Bypassed
ADATTACKS AZUREENTRA ADCSESC1-15 REDTEAM PURPLETEAM
operator@w-logic — engagement.log
$ kerbrute userenum --dc dc01 -d corp.local users.txt
[+] VALID svc_sql@corp.local ** AS-REP roastable **
$ certipy find -vulnerable
[!] ESC1 : template allows SAN + client-auth
$ bloodhound → shortest path to Domain Admins
[✓] DOMAIN COMPROMISE — 4 hops
Engagements
Multi-Domain AD+Azure

Built by a Practitioner.
Not a Vendor.

I'm Mark Wharton, founder of W-Logic LLC and creator of the Ethical Hacker's Workshop Series. With over 7 years in offensive security, I specialize in Active Directory exploitation, red team operations, and cloud identity attacks.

Every engagement is approached with an attacker's mindset and delivered with defender-focused outcomes. Available for remote and on-site engagements — nationwide.

OSCPCPTSCRTOCRTECARTECESP-ADCSOSWPPNPTCCNP Security
Specializations
Active Directory • Kerberos • ADCS / PKI
Azure / Entra ID • C2 Infrastructure
Red Team Operations • Purple Team Exercises
Tooling
Cobalt Strike • Havoc • Mythic • Sliver
BloodHound • Impacket • Certipy • Rubeus
Burp Suite Pro • Metasploit
Detection & Monitoring
Splunk • Elastic / ELK • Wazuh
Microsoft Sentinel • SIGMA Rules
Detection engineering & SIEM tuning
W-Logic LLC
Remote & On-Site Engagements — Nationwide
Columbia, MO • markw@w-logic.com
Research & Content

Ethical Hacker's
Workshop Series

Purple team education for practitioners, defenders, and security leaders. Each episode covers the attack, the detection, and the business impact.

Red TeamBlue TeamBusiness
EHWS E01: Kerberoasting — Enterprise Readiness Validation
Step-by-step domain compromise via Kerberoasting, paired with event-level detection engineering and an executive brief. Would your SIEM catch this?
Tools
Open Source Security Tools
Offensive security tooling, AD assessment scripts, and purple team resources on GitHub.
LinkedIn
Connect on LinkedIn
Security content, engagement updates, and industry insights. Follow for regular posts on AD security and red team operations.
// client feedback

Results That
Speak for Themselves.

Real engagements. Real findings. Measurable outcomes.

01 / 03
// secure digital operations

Your Web Presence,
Built to Withstand Attack.

Most agencies build pretty sites. We build sites the way an attacker would audit them — so yours holds up. Security-hardened architecture, SEO/GEO visibility, and automated review management.

https://yourclient.com A+ A+ Security 99/100 Speed
Deploy Status
✓ Live in 24 hours
Security-Hardened by Default
Every site ships with HSTS, CSP, X-Frame headers, fail2ban, rate limiting, and bad bot blocking. Not as an add-on — as the baseline.
Rank on Google AND AI Search
Structured data, GEO optimization, and AEO content structure so you get cited by ChatGPT, Perplexity, and Claude — not just Google.
Automated Review Management
3-message sequence that converts past customers into Google reviews automatically. Most clients see 20–40 new reviews in 30 days.
Fully Managed — Nothing to Learn
We handle SSL renewals, server updates, backups, uptime monitoring, and security audits. You focus on your business.
→ View Web Services // Start Your Project
Network operations
// start an engagement

Beat Attackers
At Their Own Game.

We think like adversaries because we are adversaries — certified, practiced, and battle-tested across real enterprise environments. Book a scoping call and let's find your gaps before someone else does.

→ Book a Scoping Call markw@w-logic.com
Email
markw@w-logic.com
Schedule
calendly.com/markw-w-logic
Phone
(816) 286-4584
Location
Columbia, MO · Nationwide