Offensive Security Consultant · Red Team Operator
Nathan B. Herron
I run red team operations and penetration tests that emulate real-world threat actors, then turn the results into remediation guidance leadership can act on.
- RTAC
- NSA Red Team Operator
- GIAC GPEN
01 / About
Background
Cybersecurity consultant with six years of professional experience conducting red team operations that emulate real-world threat actors. I lead internal, external, and web application penetration tests, build the infrastructure and tooling that supports them, and translate the results into remediation guidance for audiences ranging from technical staff to executive leadership.
Summerville, South Carolina
02 / Resume
Experience & credentials
Roles, education, certifications, and published research.
Experience
Senior Consultant · Palo Alto Networks Unit 42
November 2024 – Present
- Served as Case Lead on client engagements, directing the activities of consultants and supporting staff to ensure assessment objectives were met within defined scope, rules of engagement, and delivery timelines.
- Delivered internal, external, and web application penetration tests tailored to each organization's unique threat landscape and risk tolerance.
- Presented tactics, techniques, and procedures (TTPs) to offensive security practitioners at a recurring weekly internal forum, fostering knowledge sharing and continuous capability development across the consulting team.
- Developed custom scripts, tools, and automations in Python, Bash, and Go to streamline internal engagement processes and enhance offensive capability.
- Authored assessment reports detailing testing methodologies, findings, and prioritized remediation recommendations for audiences ranging from technical staff to C-suite leadership.
Red Team Operator · NAVWAR Red Team
June 2020 – November 2024
- Led red team operations emulating adversary tradecraft against mission-critical DoD and DHA networks, conducting both external and internal access operations.
- Built and maintained red team infrastructure, including phishing domain acquisition, redirector deployment, and standing up and sustaining attack platforms.
- Conducted both onsite and remote adversarial operations to evaluate the security posture of client networks and test detection capabilities of affiliated Cyber Security Service Providers (CSSPs).
- Maintained long-term persistence on target networks, exercising defender response and driving measurable improvement in system security posture.
- Authored operation orders, rules of engagement, assessment reports, and technical briefings; presented findings and remediation guidance to system stakeholders.
Red Team Intern · NAVWAR Red Team
June 2018 – June 2020
- Executed red team operations and delivered technical briefings.
- Developed a small-scale virtual cyber range for the testing of adversarial TTPs.
Education
Master of Science in Computer and Information Sciences
May 2020
University of South Alabama
National Center of Academic Excellence in Information Assurance/Cyber Defense
Bachelor of Science in Computer Science
May 2018
University of South Alabama
Mathematics minor
Skills
- Conduct penetration testing across Windows, Linux, and Active Directory environments using open-source, commercial, and custom tooling.
- Operate industry-standard C2 frameworks including Cobalt Strike and Sliver.
- Build and maintain red team infrastructure, including redirector deployment and attack platform development.
- Craft and modify custom exploits and payloads independent of consumer frameworks.
- Evade blue team signatures and Indicators of Compromise (IOCs) through advanced adversarial tradecraft.
- Lead phishing campaigns from payload development to distribution.
- Develop offensive tooling and automation in Python, Bash, and Go.
- Apply CVSS, MITRE ATT&CK, and NIST standards to reporting, disclosure, and risk assessment.
- Communicate technical findings and risks to audiences ranging from technical staff to executive leadership, both written and verbal.
Professional Development
Certifications, Training, & Presentations
Summer 2020 – Present
- K>FiveFour, Red Team Apprentice Certified (RTAC) (2021).
- NSA Certified Red Team Operator (2020 – Present).
- SANS Institute, GIAC Penetration Tester (GPEN) (2020).
- Presented TTPs to the NAVWAR Penetration Testing Community of Interest (2020 – 2024).
Research Groups & Continuing Education, University of South Alabama
Fall 2014 – 2020
- Weekly DayZero meetings to study ethical hacking skills and techniques.
- Weekly Software Protection and Exploitation Research Group (SPERG) meetings.
- Weekly Digital Forensics research meetings covering forensic methodology.
- Monthly lectures for Centers of Forensics, Information Technology & Security (CFITS).
- Participated in Capture the Flag events including HackTheBox, VulnHub, CSAW, Cyberlympics, and Panoply.
DayZero Organization, University of South Alabama — Treasurer
Spring 2016 – 2020
- Conducted weekly presentations on information security concepts and penetration testing tools to students and faculty.
- Managed organization funds and secured SGA appropriations.
Publications
McDonald, J., Herron, N., Glisson, W., & Benton, R. (2021). Machine Learning-Based Android Malware Detection Using Manifest Permissions. Hawaii International Conference on System Sciences (HICSS-54)
Awards & Honors
- NIWC LANT 5.9 Competency On The Spot! Award (2020, 2021, 2022, 2023, 2024).
- CyberCorps: Scholarship for Service (SFS) (August 2017 – May 2020).
- Commendation by the Governor of Alabama (December 2017).
- Fifth place in the National Cyber Defense Competition (April 2017).
- Winner of the Southeastern Conference Cyber Defense Competition (March 2017).
- Dean's List (Fall 2012 – Spring 2016).
- Bay Area Freshman Scholarship (August 2011 – August 2013).
03 / Portfolio
Selected work
Case studies in progress
Selected engagements, tooling, and research will be published here.