Award-Winning Ethical Hacker

Sablewatch Red Team

Ethical Hacker & Penetration Tester based in USA

★★★★★

350+ Reviews (4.9 of 5)Reviews from Valued Clients

Portrait of Sablewatch, ethical hacker in a black hoodie

Ethical Hacker with Real-World Pentesting Tradecraft!

Pen Testing Network Web App Security Social Engineering Red Teaming
My Services

How I Turn Attacks into Defense

View All Services
External Network Testing Internal Network Testing Firewall Evasion Review Lateral Movement Paths

Adversary-style testing of your external and internal networks to expose open doors, weak segmentation, and paths an attacker would walk to reach crown jewels.

Explore this service →
API Security Testing OWASP Top 10 Coverage Auth & Session Testing Business Logic Abuse

Hands-on testing of web apps and APIs focused on real exploitability — authentication flaws, injection, broken access control, and logic bugs scanners miss.

Explore this service →
iOS & Android Review Runtime Manipulation Secure Storage Audit MASVS Coverage

Deep static and dynamic analysis of mobile apps and their backends — insecure storage, weak crypto, exposed endpoints, and tamper resistance.

Explore this service →
AWS & Azure Review IAM Privilege Paths Misconfiguration Hunts Container Escape Tests

Configuration and identity review of cloud estates plus live attack-path validation — showing exactly how a misconfigured role becomes full takeover.

Explore this service →
Phishing Simulations Physical Intrusion Tests Full-Scope Red Teams Blue Team Debriefs

Full-scope adversary simulation against people, process, and technology — measuring detection and response, not just prevention.

Explore this service →
Portrait of Sablewatch, ethical hacker in a black hoodie pointing
About Me

Who is behind Sablewatch?

Hey there — I'm Sablewatch, an ethical hacker obsessed with thinking like the adversary so you don't have to. Every engagement blends sharp tradecraft with reporting your engineers will actually enjoy reading.

250+ Successful Operations
25+ Industries Covered
150+ Happy Clients
16+ Years of Experience
My Toolkit

Exploring the Arsenal
Behind My Operations

98%

Kali Linux

92%

Burp Suite

90%

Metasploit

98%

Nmap

90%

Wireshark

95%

Cobalt Strike

My Portfolio

Let's Have a Look
at My Operations

View All Projects
Bank building exterior — external network assessment target
Network Testing Web App Recon

Meridian Bank — External Network Assessment

Full external assessment of a regional bank's perimeter — exposed services, phishing-resistant MFA gaps, and a path from one forgotten subdomain to domain admin.

Retail clothing store — e-commerce security program
Web App Cloud Social Engineering

Northwind Retail — E-Commerce Security Program

Season-long program for a national retailer: storefront and API testing, cloud misconfiguration hunts, and a phishing simulation that cut click rates by two thirds.

Training & Work

My Academic and Professional Journey

Education

Blackridge InstituteMaster in Cybersecurity
2012 - 2014
Lakeside CollegeBachelor in Computer Science
2008 - 2012
Cedar Falls HighHigh School Diploma
1996 - 2008

Work Experience

Independent PracticeEthical Hacker & Penetration Tester
2018 - 2026
Ironhold SecuritySecurity Consultant
2016 - 2018
IndependentPenetration Tester
2014 - 2016
Achievement Awards

My Award-Winning
Security Journey

Recognized for creative adversarial thinking, rigorous tradecraft, honest reporting, and defensive impact that lasts.

01.

Ethical Hacker Excellence Award

Recognized for outstanding adversarial operations, creativity, and client impact.

02.

Offensive Security Mastery Award

Awarded for creative thinking and exceptional adversary-simulation tradecraft.

03.

Creative Defense Impact Award

Honored for sharp, practical findings and measurably stronger client defenses.

My Work Process

The Way I Test
Defenses

01.

Recon & Enumeration

Mapping your attack surface the way a real adversary would — OSINT, asset discovery, and quiet enumeration before a single packet is sent.

02.

Exploitation & Access

Chaining vulnerabilities into real access paths, validating every finding hands-on so nothing in the report is theoretical.

03.

Persistence & Pivoting

Proving business impact by pivoting through the environment toward crown jewels — while testing your detection at every step.

04.

Reporting & Remediation

Clear, prioritized findings with reproduction steps, fix guidance, and a live debrief plus free retesting of criticals.

Pricing Table

My Pricing Model

Need a Custom Quote?

Get a tailored offensive-security quote scoped to your goals, timeline, and environment size.

HOURLY

$60 / Hour

  • Flexible hourly hiring
  • Fast testing turnaround
  • Pay as you go
  • Quick finding retests
  • Transparent hourly pricing
  • Perfect for short assessments
MONTHLY

$9600 / Month

  • Dedicated monthly testing
  • Priority testing support
  • Fast testing turnaround
  • Flexible monthly scope
  • Long-term program support
  • Built for security maturity
  • Smooth team collaboration
  • Consistent testing quality
Contact Me

Let's Talk for Your
Next Assessment

Address

4180 Harbor View Dr, Austin,
Texas 78746

Time

Monday - Friday  : 10:00 - 20:00
Saturday - Sunday : 11:00 - 18:00

Stay Connected

FAQs

Question? Look here.

You have different questions? Ask Away!

Your Questions, My Answers.
Quick Responses Guaranteed.

Contact Me

Finance, healthcare, retail, SaaS, energy, and government systems — 25+ industries so far. If it has an IP address, a login screen, or employees, we can test it.

Yes — we test external and internal networks, web and mobile applications, APIs, and AWS/Azure cloud estates, plus full-scope red team operations that combine them all.

Absolutely. From targeted spear-phishing and voice pretexting to on-site intrusion attempts, always with agreed rules of engagement and immediate staff-safety guardrails.

Both. Startups get focused, budget-friendly assessments; enterprises get program-level testing with quarterly operations, purple-team exercises, and board-ready reporting.

Focused tests run 1–2 weeks, standard assessments 3–4 weeks, and full red team operations 6–12 weeks. You'll get a firm timeline at scoping — and we hit it.

Recon, exploitation, pivoting, then reporting: a live kickoff, daily testing updates on longer ops, a prioritized report with reproduction steps, a debrief with your engineers, and free retesting of critical findings.