Enterprise Softproducts - Your trusted cybersecurity partner
//WHOAMI

My name is Mark Steenberg.

I decided to create my own cybersecurity company because I was tired of ever-increasing pressure to deliver, shorter deadlines, and a blind focus on earning more and more while watching the quality of the work I was delivering drop.

To address this, I have set the following requirements for this endeavor:

  • Deliver quality, on time, every time
  • Always improve, and have a focus on receiving constant feedback
  • Be proud of the work sent to customers
  • Strive for happy customers

All in an effort to deliver work I'm proud of, while not burning out every 5-6 months. And overall, just trying to do a good job in a slop economy where more and more companies are cutting corners and sending AI slop out masquerading as professional reports. Please see below for my professional accreditations.

[CERTIFICATIONS]

Throughout my career, I have attained the following certifications, showcasing and demonstrating my expertise across cybersecurity domains. These certifications range from offensive and red teaming certifications like the eCPTXv2, where the goal was to compromise a simulated enterprise infrastructure. To defensive certifications such as eWDP and eNDP, where, respectively, the goals were to compromise a web page and a network and then subsequently harden the application and infrastructure.

[Hover for more details on each]

OFFENSIVE SECURITY

  • HTB Pro Labs:Various simulated enterprise environments with focus on initial access and post exploitation in multi-domain environments, containing defensive measures like network segmentation, AV, PowerShell Just Enough Administration (JEA), etc.
    • APTLabs
    • Cybernetics
    • RastaLabs
    • Offshore
    • Dante
    • Zephyr
  • eLearnSecurity Certified Penetration Tester eXtreme (eCPTXv2)Exploitation of multi-domain AD forest including ACL abuse, cross-domain lateral movement, MSSQL abuse, relay attacks, etc.
  • eLearnSecurity Certified eXploit Developer (eCXD)Exploitation of buffer overflows via traditional buffer overflows, ROP and SROP chains, on both Linux and Windows.
  • eLearnSecurity Certified Professional Penetration Tester (eCPPTv2)Intermediate pentest certification focusing on exploitation of vulnerabilities and cross-network lateral movement.
  • eLearnSecurity Mobile Application Penetration Tester (eMAPT)Cert focusing on the assessment and exploitation of Android applications.
  • eLearnSecurity Web Application Penetration Tester eXtreme (eWPTXv2)Advanced web app pentest cert. focusing on advanced techniques and exploitation.
  • eLearnSecurity Web Application Penetration Tester (eWPT)Web app pentest cert. focusing on OWASP top 10
  • eLearnSecurity Junior Penetration Tester (eJPT)Entry level offensive security certification
  • Certified Red Team Professional (CRTP)AD exploitaiton and lateral movement
  • Certified Azure Red Team Professional (CARTP) Exploitation of Azure cloud environment and lateral movement between cloud and on-prem.

DFIR

  • GIAC Certified Forensic Analyst (GCFA)Perform incident response investigations and analysis on a compromised network.
  • eLearnSecurity Certified Threat Hunting Professional (eCTHPv2)Conduct threat hunting activities, including SOC analysis, network investigations, and in-memory forensics, also use tools to create IOCs and detection rules for the identified IOCs.
  • eLearnSecurity Certified Incident Responder (eCIR)Certification showing capabilities for analyzing network and host-based incidents using Splunk and network traffic (.pcap).
  • eLearnSecurity Certified Digital Forensics Professional (eCDFP)Perform digital forensics on windows laptop.

DEFENSIVE SECURITY AND INFRA.

  • eLearnSecurity Certified Reverse Engineer (eCRE)Reverse engineer compiled binaries (unmanaged) and analyze ASM using Immunity Debugger.
  • eLearnSecurity Certified Malware Analysis Professional (eCMAPv1)Use IDA and other modern reverse engineering tools to analyze and understand complex malware.
  • eLearnSecurity Web Defence Professional (eWDP)Perform a penetration test of an PHP app, then harden the applicaiton using a custom MOD firewall to deny previous attacks, and then remediate all vulnerabilities in the code itself such as implementing RBAC and input/output sanitization.
  • eLearnSecurity Network Defense Professional (eNDP)Harden a modern network and servers, including configuration and setup of site-to-site VPN, creation and provisioning of GPOs, and AD hardening.
  • Azure Fundamentals (AZ-900)General introduction to the azure ecosystem.
[SECURITY RESEARCH]
  • CVE-2021-44151 - Session hijacking via brute forcing (Reprise RLM 14.2)
  • CVE-2021-44152 - Arbitrary unauthenticated password change (Reprise RLM 14.2)
  • CVE-2021-44153 - Authenticated RCE (Reprise RLM 14.2)
  • CVE-2021-44154 - Buffer Overflow (Reprise RLM 14.2)
  • CVE-2021-44155 - User enumeration (Reprise RLM 14.2)
[SECURITY RESEARCH]
[PRESENTATIONS]