Julio Iglesias Pérez
Offensive Security Engineer and Red Team Operator ranked in the top 0.02% globally on Hack the Box (Top 25 worldwide). Over a decade of hands-on experience designing and executing full-spectrum adversary simulations — from initial access and OSINT-driven reconnaissance to domain takeover, cloud privilege escalation, and post-exploitation persistence.
Delivered 150+ penetration tests and red team engagements across banking, government, and enterprise environments, consistently achieving full attack path compromise. Deep expertise in Active Directory offensive tradecraft, C2 infrastructure design, detection evasion, custom weaponization development (Rust, Python, ASM), and MITRE ATT&CK-aligned threat emulation.
Technical Expertise
Adversary Simulation & Red Teaming
MITRE ATT&CK emulation, threat actor profiling, full kill chain operations, assumed breach scenarios
Active Directory & Identity Attacks
Kerberoasting, AS-REP Roasting, ACL abuse, DCSync, Pass-the-Hash/Ticket, delegation attacks, BloodHound, lateral movement, persistence
OSINT & Reconnaissance
Digital footprinting, HUMINT, credential exposure analysis, dark web monitoring, social engineering, phishing infrastructure, pretexting
Penetration Testing
Web apps (OWASP Top 10), APIs, mobile (Android/iOS), internal networks, Wi-Fi auditing (WPA2), MSSQL injection, LFI/RCE chains, privilege escalation
Evasion & Anti-Detection
EDR bypass, in-memory execution, sleep obfuscation, stack spoofing, ETW patching, AMSI bypass, custom shellcode loaders, process injection
C2 Operations & Infrastructure
Custom C2 design (Rust), Cobalt Strike, Sliver, stealth beaconing, OPSEC-hardened redirectors, encrypted comms, long-haul persistence
Custom Tooling Development
Rust (primary), Python, Bash, ASM — payloads, BOF/COFF loaders, CLR hosting, SyscallDispatcher (Hell's/Halo's/Tartarus' Gate), obfuscation frameworks
Cloud Security
AWS IAM abuse, Azure privilege escalation, GCP misconfigurations, role chaining, service account takeover
LLM Red Team
LLM abuse, indirect prompt injection, tool abuse, multi-step attack chains, automated prompt fuzzing, OWASP TOP 10 LLM
Professional Experience
2013 – Present
VP of Offensive Security & Co-Founder
Ciberespacio – Bolivia
Full-service cybersecurity firm — Red Team, Penetration Testing, OSINT, LLM Red Team
- Architected and led 150+ offensive security engagements across financial, government, and critical infrastructure sectors — achieving full domain compromise in over 90% of red team operations.
- Executed end-to-end red team operations: OSINT-driven reconnaissance, phishing initial access, Active Directory attack chains, lateral movement, and long-term persistence via custom C2 implants with OPSEC-hardened beaconing.
- Built custom offensive tooling in Rust, Python, ASM, and Bash — including payload delivery frameworks, in-memory loaders, sleep obfuscation and privilege escalation automation.
- Conducted cloud red team engagements across AWS, Azure, and GCP — exploiting IAM misconfigurations, role chaining, and service account abuse.
- Designed adversarial interaction frameworks to evaluate LLM security posture, including indirect prompt injection and automated prompt fuzzing.
2019 – 2022
Enterprise Security Officer
Jalasoft – Bolivia
Nearshore software outsourcing firm — built offensive security and IR capability from ground zero.
- Established the Red Team program and Incident Response capability from scratch, defining methodology, tooling, and operational playbooks aligned to MITRE ATT&CK.
- Reduced critical and high application vulnerabilities by ~65% through continuous offensive testing cycles.
- Simulated targeted threat actor behavior — including phishing campaigns, credential harvesting, and lateral movement — to expose detection gaps and improve SOC response time.
- Designed secure architecture recommendations and hardening baselines adopted across the organization's production environment.
2015 – 2019
Senior Penetration Tester
Malware Intelligence – Argentina
Threat intelligence and offensive research firm — specialized in cybercrime infrastructure analysis.
- Conducted offensive operations against cybercrime infrastructure, malware ecosystems, and threat actor C2 networks — supporting law enforcement and intelligence clients.
- Developed automated threat intelligence collection pipelines integrating OSINT feeds, dark web monitoring, and malware sandbox analysis.
- Performed deep analysis of phishing campaigns, botnet C2 infrastructure, and crimeware toolkits.
- Reverse engineered malware samples and offensive tools to extract IoCs, identify attribution artifacts, and understand adversary TTPs.
Selected Red Team Operations
(Sanitized)
Full Active Directory Compromise
Multi-stage chained attack: Kerberoasting → delegation abuse → ACL-based privilege escalation → Domain Admin in <48 hours against a hardened financial sector target.
EDR Bypass & Long-term Persistence
Bypassed next-gen EDR (CrowdStrike / SentinelOne class) using in-memory payload execution, sleep obfuscation (stack spoofing + XOR encryption), and ETW patching — maintained undetected persistence for 30+ days.
Cloud Privilege Escalation (AWS)
Exploited misconfigured IAM role chaining to achieve full account takeover from an initial low-privilege developer credential.
Network Segmentation Bypass
Pivoted across five segmented network zones in an enterprise environment using dual-homed host lateral movement and tunneling through internal proxies, reaching OT-adjacent systems.
Web Application Red Team
Chained LFI to RCE, escalated to SYSTEM via SeImpersonatePrivilege abuse — full server compromise in a Windows/IIS environment with no alert triggered.
Certifications
Offensive Security Web Expert
OffSecOffensive Security Certified Professional
OffSecCertified Red Team Professional
Altered SecurityCertified Red Team Analyst
CyberWarFare LabsMulti-Cloud Red Team Analyst
CyberWarFare LabsAPI Security Exam Passed
APISec UniversityOperationalizing MITRE ATT&CK
AttackIQFoundations of Purple Teaming
AttackIQMicrosoft Most Valuable Professional
MicrosoftRecognition & Community
Hack The Box — Top 25 Globally
Ranked Top 0.02% globally — consistent high-performance across Pro Labs, Active Machines, and seasonal events.
View ProfileMicrosoft MVP Alumni
Recognized for technical community contributions in security.
Red Team Trainer & Mentor
Trainer and mentor for cybersecurity professionals, military teams, and law enforcement agencies across Latin America.
LATAM Security Community
Organizer of offensive security initiatives and technical knowledge-sharing events across the LATAM security community.
Educational Content
Creator of Red Team and offensive security educational content in Spanish.
YouTube ChannelOpen Source Contributions
Solana vulnerability PoCs, blockchain security research, and offensive tooling.
GitHub