ZephrFish - Overview

Intro:

Andy has been consulting in offensive security for over a decade, focusing on red teaming and simulated attacks with a side of threat intelligence and purple teaming. Leading engagements of varying sizes and lengths, helping grow teams and encouraging risk-driven understanding.

Creator of ZephrSec LMS and ZephrSec.

pacman contribution graph

Projects:

Pages

Blog:

I post most of my research and other interesting tutorials on my blog; I also have a photos blog where I share pics I take; ZephrSnaps

Course:

I have written a course aimed at professionals wanting to learn more about red teaming, it focuses on red teaming from the perspective of not depending upon C2 and traditional malware but also teaches the background to red teaming that a lot of courses miss. https://lms.zsec.red

CertificateLogo_new

Book:

For those that don't know Andy, he is a firm believer in passing knowledge on and supporting the infosec community he does this by providing tutorials on his blog running his local DEF CON Chapter & has also published two books Breaking into Information Security and LTR102. He also helps out at DEF CON as a SOC Goon (Red Shirt) too each year (since DC24), assisting the SOC with operations and people flow.

Talks:

2026

  • TBC. -
  • TBC. -
  • TBC. -

2025

  • Securi-Tay 2025. - Think Like An Adversary - Recording
  • Steelcon 2025. - Drinking from the Same Firehose - How Red Teams Outrun Threat Actors - Recording
  • Hack Glasgow. - From Framing Risks to Framing Scenes - Transferable Skills Between Security and Hobbies- Was not recorded sadly!
  • FalCon Europe 2025. DORA and Friends - Navigating Regulatory Red Teaming - Was not recorded sadly!

2024

2023

2022

2021

2020

2019

2018

Bug Bounty:

Badges

Andy has been in the IT security industry for just over 15 years, a decade of which has been dedicated to security and offensive operations. Currently holds CREST's Certified Red Team Specialist (CCRTS) and he has previously held CREST’s CCT Infrastructure certification, which is highly sought-after, and CHECK Team Leader status. In addition to his years in the industry, he holds several other certifications and accolades, including CCRTS, CRTO, OSCP, and OSWP.