Skip to content
cyberknight / 91
Available for new engagements

Mario Martín.

Cybersecurity consultant specialised in offensive simulation and detection engineering — the purple side of the room.

Defence is only real once a real attack validates it.

5+
years in security
15
public repos
14
certifications
CyberKnight
cyberknight91 ~ profile
mario@cyberknight $ whoami
mario.martin.feliz · cyberknight91
mario@cyberknight $ ./profile.sh --summary
# loading profile…
─────────────────────────────────────
profile · cybersecurity consultant
focus · purple-team · detection eng
base · león, spain · remote-friendly
stack · sigma · yara · wazuh · att&ck
─────────────────────────────────────
mario@cyberknight $ echo $STATUS
[OK] available for new engagements
mario@cyberknight $
v0.1.0 · deployed on cloudflare online
Featured work · 04 / 7

Where offence meets detection.

Each lab ships both the attack and the detection that catches it. No isolated demos — the full chain, end-to-end.

Philosophy

Detection without simulation is theatre.

Simulation without detection is posing. Every offensive test in my labs ships with its blue counterpart: the Sigma rule, the hunting query, the runbook. Or it does not ship.

That overlap — the purple side of the room — is where the best work happens. Where the attack teaches you to defend, and the defence forces you to attack better.

detection-engineering ~ T1003.001.yml
# sigma rule · adversary playbook
defender@soc $ cat ./detection/T1003.001.yml
title: OS Credential Dumping (LSASS)
id: 5ad88c0e-72b1-4d12-9e3d-purple
status: production
level: high
logsource:
category: process_access
product: windows
detection:
selection:
TargetImage|endswith: \lsass.exe
GrantedAccess: 0x1010
condition: selection
defender@soc $ ./validate.sh
[OK] mapped to MITRE ATT&CK
[OK] tested on baseline (72h, 0 fp)
[OK] published to detection-engineering
defender@soc $
Stack · 6 areas

Tools I work with every day.

No decorative badges: only what I actually use in production and the lab.

CyberKnight
YouTube channel @cyberknight91

CyberKnight.

AI · Cybersecurity · Hacking

My digital alter ego. Videos on AI, cybersecurity and hacking — the purple side of the room, after hours.

Watch on YouTube
$ contact

Got an infrastructure that needs defending or attacking with care?

Audits, adversary simulation, detection engineering, and NIS2 / ENS consulting for companies that take security seriously.