MW
// founder & principal consultant

Mark Wharton

OSCP · CRTO · CRTE · CARTE · CESP-ADCS · CPTS

Offensive security consultant and founder of W-Logic LLC. I specialize in red team operations, Active Directory attack chains, ADCS certificate abuse (ESC1–ESC15), and Azure/Entra ID identity attacks. Based in Columbia, MO — available for engagements nationwide.

"Think Like an Adversary. Defend with Precision."
10+
Active Certifications
AD·Azure
Core Specialization
ESC1–15
ADCS Coverage
MO / US
Columbia, MO — Nationwide
// core expertise
Red Team Operations
Full-scope adversary simulation from initial access through domain dominance and post-exploitation persistence. Cobalt Strike C2, custom implants, and OPSEC-aware tradecraft.
Cobalt Strike C2 Infrastructure OPSEC Persistence
Active Directory Attack Chains
End-to-end AD exploitation: Kerberoasting, AS-REP roasting, ACL abuse, delegation attacks, cross-forest trust exploitation, and diamond ticket persistence. Full BloodHound CE attack path analysis.
Kerberos BloodHound ACL Abuse Cross-Forest
ADCS Certificate Abuse
Deep specialization in Active Directory Certificate Services exploitation — ESC1 through ESC15 abuse chains, misconfigured templates, CA ACL abuse, and NTLM relay to ADCS (PetitPotam/Coercer). CESP-ADCS certified.
ESC1–ESC15 certipy Certify PetitPotam
Azure / Entra ID Identity Attacks
Azure red team from initial Entra ID enumeration through token abuse, conditional access bypass, service principal escalation, AADConnect credential extraction, and cross-tenant pivoting.
ROADtools AADInternals GraphRunner AzureHound
Purple Team Exercises
Collaborative red/blue engagements that generate detection coverage — not just findings. Attack execution paired with real-time defender feedback, Wazuh/SIEM tuning, and detection rule development.
Detection Engineering MITRE ATT&CK Wazuh SIEM
Security Gap Analysis
Low-barrier entry assessment identifying the highest-risk exposures in your environment — AD configuration, cloud identity posture, certificate infrastructure — with a clear remediation roadmap.
PingCastle Maester ScubaGear Risk Scoring
// certifications & credentials
OSCP
Offensive Security
Active
CPTS
Hack The Box · #0CAD03D77E
May 2026
CRTO
Zero-Point Security
Active
CRTE
Altered Security
Recert Jun 2026
CARTE
Altered Security
Exp Mar 2028
CESP-ADCS
ADCS Specialist
Exp Nov 2027
PNPT
TCM Security
Jan 2024
CCNP Security
Cisco
Exp Jul 2027
OSWP
Offensive Security
Active
CompTIA Security+
CompTIA
Active
CRTP
Altered Security
Exp Mar 2025
CRTO II (CRTE retake)
Zero-Point Security · In Progress
Week 6/12
// approach & philosophy

W-Logic engagements are built on a simple premise: your adversary doesn't read your security policy. They read your AD ACLs, your certificate templates, and your conditional access exclusions. Every assessment I run is designed to find what a real attacker would find — before they do.

I operate with full attack chain documentation. Every technique is mapped to MITRE ATT&CK, every finding includes a remediation path with implementation priority, and every deliverable is written for two audiences: the technical team that has to fix it, and the executive that has to fund it.

Engagements are scoped conservatively and executed aggressively. Rules of engagement are defined in writing before a single packet is sent. No surprises — on either side.

// primary toolkit
Cobalt Strike
BloodHound CE
Impacket
NetExec
Rubeus
Mimikatz
certipy
AzureHound
ROADtools
AADInternals
GraphRunner
Maester
ScubaGear
PingCastle
Ligolo-ng
Evil-WinRM
TokenTacticsV2
Burp Suite Pro
// client reference
"Mark provided an exceptionally thorough assessment of our environment. His findings on our Active Directory configuration identified exposures our internal team had missed entirely. The remediation documentation was clear enough that we could act on it immediately without bringing in additional consultants."
— G.S., Director of IT · Energy Sector · Columbia, MO

Ready to test your defenses?

Engagements start with a no-obligation 30-minute scoping call. W-Logic works directly — no account managers, no junior staff running your assessment. You get the certified consultant on every call, every deliverable.