OffensiveGuardian

Founder-led adversary validation

Unlock the truth inside your defenses.

We recreate the attack paths that matter and show you, control by control, what holds, what fails, and what to fix next.

Build my Evidence Gap Map

Direct senior review. No sales handoff.

What we measure, end to end

Attack pathControl responseTelemetryDetectionDecisionEvidence
Offensive Guardian mark

The guardian threshold unlocks and the Offensive Guardian mark is revealed.

Led by Jean-François Maes
  • Lead author, SANS SEC565
  • Co-author, SANS SEC699
  • SANS Certified Instructor
  • Former Cobalt Strike researcher at Fortra
Verify:SANSGitHub

The evidence standard

A pentest finds weaknesses.We prove how the defensive system behaves while the attack is moving.

Knowing a vulnerability exists is the easy part. What decides an incident is what your defense does while someone is using it: whether a control slows them down, whether the activity even reaches your telemetry, whether anyone notices and acts in time. That is what we put under test.

01

Controls

Did the expected preventive or limiting control change the path?

02

Telemetry

Was the activity visible with enough context?

03

Detection

Did logic and triage work when it mattered?

04

Decision

Was the right action taken in time?

Engagements

Start with what you need to prove.

Each engagement is built around one material attack path, the defensive outcome it tests, and the evidence you need to act. No generic menu. You leave with a decision, not a backlog.

01

Entry sprint

Detection Validation Sprint

Built forSOC and detection engineering leaders

We run the behaviors your detections are supposed to catch and follow each one from raw telemetry to the analyst who should act on it.

Outcome: A straight answer on which detections hold up, and a ranked list of the ones that don't.

2–4 weeks · Evidence matrix · Reproducible test cases · Focused retest

02

Collaborative

Threat-Informed Purple Team

Built forPurple-team, SOC, and CTI leaders

We take a threat that actually matters to your business, emulate it with your team in the room, and replay it until the detections work.

Outcome: Your threat intel becomes detections you have watched fire, not a claim on a slide.

4–8 weeks · Scenario pack · Execution record · Replay package

03

Objective-led

Full-Scope Red Team

Built forCISOs and cyber-defense leadership

An unannounced, objective-led operation against the whole organization, people and process included, under rules we agree up front.

Outcome: A defensible, evidence-backed picture of how you really perform when nobody is tipped off.

6–12 weeks · Executive narrative · Evidence timeline · Remediation/replay plan

Continuous Offensive Validation

A test is only true on the day you run it. Then you ship code, tune detections, and the answer quietly goes stale. We re-run the paths that matter on a set schedule, confirm last cycle's fixes actually held, and keep your evidence current instead of expiring with the report.

Build a program

New attack surface

Your AI agents have real access. Prove what they can be made to do.

Agents and copilots are getting wired into production with credentials, tools, and data. Most were never tested the way an attacker would use them. We probe the privilege boundaries, the injection-to-action paths, and the detection story for AI-driven behavior, then hand you the evidence and the fix plan.

2–4 weeks

Grounded in current research: our founder has published on autonomous pentest agent risk and AI-driven command and control.

Illustrative evidence object

What the work should leave behind.

One object, shown in isolation. The full version, in context and across a whole engagement, is the sample report.

Hypothesis

Credential access activity should produce correlated endpoint and identity evidence before privilege expansion.

Observed break

Endpoint evidence present · identity correlation absent · analyst context incomplete

Defensive consequence

The path remains visible locally but not actionable as a coordinated incident.

Owner / retest

Detection engineering · correlation change · focused replay in 30 days

Methodology

Pressure with a purpose. Evidence with an owner.

  1. 01

    Model

    Define the decision, threat relevance, critical path, safe operating constraints, and falsifiable hypothesis.

  2. 02

    Pressure

    Execute realistic behavior under controlled rules, from atomic tests to chained objectives.

  3. 03

    Observe

    Capture the full defensive chain: control effect, telemetry, analytic behavior, analyst decision, and response.

  4. 04

    Improve

    Classify the break, assign ownership, preserve repeatable test cases, and prove the change through retesting.

Jean-François Maes presenting on stage
Jean-François MaesFounder · lead practitioner

Who does the work

The person you meet is the person who runs the engagement.

Offensive Guardian is led by Jean-François Maes. He is the lead author of SANS SEC565: Red Team Operations and Adversary Emulation, co-author of SEC699: Advanced Purple Teaming, and a SANS Certified Instructor. He has worked for reputable security firms including NVISO, TrustedSec, and Fortra, where he was a Cobalt Strike researcher, with over a decade of hands-on offensive operations behind him. His open-source tooling, including LazySign, SharpZipRunner, and TrustJack, is used by red teams worldwide.

Most testing ends with a list. The useful work starts one step later: proving how the defense behaved while it mattered, and making the fix stick. That is the only work I do.

Five-minute diagnostic

Not ready to talk? Find your biggest evidence gap first.

Answer 12 non-sensitive questions across control assurance, telemetry quality, detection validation, and response cadence. See a useful four-dimension profile before we ask for email.

  • Immediate profile, no email required to start
  • Highest probable evidence gap called out first
  • Recommended first validation path
  • Optional full PDF + senior review after email
Start the Evidence Gap Map
Control assurance42
Telemetry quality58
Detection validation31
Response cadence47

Sample profile · Directional, not a certification

Questions worth answering

The things a serious buyer asks first.

Will senior people actually do the work?
Yes. Engagements are led and delivered by the founder. If a future engagement needs more hands, you meet them and know exactly who does what. No junior handoff.
What do we get beyond a findings list?
An evidence matrix that ties every result to its control, telemetry, detection outcome, owner, and retest, plus a leadership summary you can act on and an engineering backlog your team can execute.
Is this safe to run against a live environment?
Every engagement runs under agreed rules of engagement with deconfliction and safe constraints defined up front. Mature operations keep running. Nothing goes off-script.
Is it relevant to our specific threats?
We start from your critical paths and the threats that matter to your business, not a generic technique catalog. If we cannot find a material validation hypothesis, we tell you.
We are shipping AI agents. Can you test those?
Yes. AI Attack-Surface Validation tests what your agents and copilots can be made to do by an adversary, and whether you would detect it.
What happens after the test?
Each break has an owner and a preserved test. We retest the fixes so you can prove the change, not just log it.
How do you handle our data?
We work under a mutual NDA as standard. Data handling and retention are agreed per engagement before any access.

Bring the attack path, the coverage claim, or the decision you cannot yet defend.

In a short call we work out whether there is a real question worth testing, then point you to the smallest engagement that answers it. If there is not a good fit, we will tell you that too, and you still leave with a written next step.

Build my Evidence Gap Map