JOSEF BASNER
Penetration Tester · Security ResearcherPenetration Tester · Security Researcher
ProfilProfile
josef@sec:~$ cat profile.txt
Offensive-Security-Spezialist mit 5+ Jahren Praxis in Bug Bounty, Web-/API-Pentesting und Active-Directory-Angriffen. Seit 2020 in privaten / invite-only Programmen auf HackerOne und Bugcrowd — 20+ verifizierte Schwachstellen (RCE, SQLi, XSS, IDOR, Auth-Bypass), Schwerpunkt Business-Logic und Exploit-Chains. CompTIA Security+ (SY0-701) zertifiziert. Eigenes Security-Lab, dokumentierte Methodik, laufender Zertifizierungspfad (PenTest+, CEH v13, OSCP für Q4 2026). Zusätzlich ausgebildeter Mechatroniker (Siemens S7, SCADA) — direkter Zugang zu OT/ICS-Security.
Offensive-security specialist with 5+ years of hands-on experience in bug bounty, web/API penetration testing and Active Directory attacks. Active since 2020 in private / invite-only programs on HackerOne and Bugcrowd — 20+ verified vulnerabilities (RCE, SQLi, XSS, IDOR, auth bypass), focused on business-logic flaws and exploit chains. CompTIA Security+ (SY0-701) certified. Own security lab, documented methodology, certification path in progress (PenTest+, CEH v13, OSCP planned Q4 2026). Also a trained mechatronics engineer (Siemens S7, SCADA) — a direct route into OT/ICS security.
josef@sec:~$ _
HighlightsHighlights
Technische SchwerpunkteTechnical Skills
Offensive SecurityOffensive Security
Tools
Scripting
OT / ICS
NetzwerkeNetworking
SystemeSystems
Security-ErfahrungSecurity Experience
Bug Bounty ResearcherBug Bounty Researcher
- 20+ bestätigte Schwachstellen: RCE, SQL-Injection, Stored/Reflected XSS, IDOR, Auth-Bypass, Business-Logic-Flaws
- 20+ verified vulnerabilities: RCE, SQL injection, stored/reflected XSS, IDOR, auth bypass, business-logic flaws
- Schwerpunkt Web- & API-Schwachstellen, Recon-Automatisierung, Token-Analyse, Exploit-Chains
- Focus on web & API vulnerabilities, recon automation, token analysis, exploit chains
- Ziele: ████████ CLASSIFIED ████ — vollständige NDA- & Responsible-Disclosure-Einhaltung, reproduzierbare PoC-Reports
- Targets: ████████ CLASSIFIED ████ — full NDA & responsible-disclosure compliance, reproducible PoC reports
HackTheBox · Eigenes Security-LabOwn Security Lab
- Öffentliche deutschsprachige Writeups für retired Machines · github.com/JBMTP07/HTB-Writeups
- Public write-ups of full attack chains for retired machines · github.com/JBMTP07/HTB-Writeups
- Isoliertes Testlabor: Raspberry Pi, Metasploitable, Vulnerable VMs, eigene AD-Domäne
- Isolated test lab: Raspberry Pi, Metasploitable, vulnerable VMs, own AD domain
- Veröffentlichte Methodik-Sammlung (Linux PrivEsc, AD-Angriffe, Burp-Workflow) · github.com/JBMTP07/Study-Notes
- Published methodology notes (Linux PrivEsc, AD attacks, Burp workflow) · github.com/JBMTP07/Study-Notes
Gastredner — KI & CybersecurityGuest Speaker — AI & Cybersecurity
- Vorträge zu LLMs, KI-Sicherheitsrisiken, Phishing und Cybersecurity-Grundlagen für Schüler:innen & Lehrkräfte
- Talks on LLMs, AI security risks, phishing and cybersecurity fundamentals for students & teachers
ZertifizierungenCertifications
Kurse abgeschlossen über New Horizons (zertifizierter Bildungsträger). Security+ bestanden — weitere Prüfungen folgen 2026.Courses completed via New Horizons (accredited training provider). Security+ passed — further exams follow in 2026.
- BESTANDENPASSED
CompTIA Security+ SY0-701
05/2026 - IN PRÜFUNGIN PROGRESS
CompTIA PenTest+
2026 - IN PRÜFUNGIN PROGRESS
EC-Council CEH v13
2026 - IN PRÜFUNGIN PROGRESS
CompTIA Network+ / Linux+
2026 - GEPLANTPLANNED
OffSec OSCP
Q4 2026
WerdegangWork Experience
SelbstständigSelf-employed
MechatronikerMechatronics Engineer
- Wartung, Instandhaltung & Fehlerdiagnose industrieller Anlagen — praktische OT-Berührungspunkte
- Maintenance, servicing & fault diagnosis of industrial plants — hands-on OT exposure
Stellv. TeamleiterDeputy Team Lead
- Operative Führung, Teamkoordination, Qualitätssicherung, Eskalationsmanagement
- Operational leadership, team coordination, QA, escalation management
Ausbildung MechatronikerApprenticeship — Mechatronics
- SPS-Programmierung (Siemens S7), SCADA-Systeme, Industrieautomation, Messtechnik — direkter Bezug zu OT/ICS-Security
- PLC programming (Siemens S7), SCADA systems, industrial automation, instrumentation — direct link to OT/ICS security