Penetration Testing / IT Security

Marco Frison

Freelance Offensive Security Consultant — Italy

For over 15 years, I've made a career of breaking into networks, applications, and wireless infrastructure so the bad guys don't get the chance. My penetration testing work spans a broad mix of industries, from banking, telecom, and energy to automotive, logistics, and more.

Based in
Italy
Practicing since
2010
Languages
Italian (native) · English (C1/C2)
Standards
OWASP · OSSTMM · CWE · CAPEC
VAT no.
IT 03965020401
CERTIFIED OSCP SINCE 2018
Years testing15+
Public disclosureCVE-2023-2359
VAT no.IT 03965020401

Scope of services

What I do

Network & Infrastructure PT

Internal and external testing of servers, network devices and perimeter defences — mapping the real path an attacker would take through your environment.

Infrastructure

Web Application PT

Manual, OWASP-driven testing of web applications: authentication, business logic, injection, and session handling — not just an automated scan.

Web

Mobile Assessment

Security review of Android applications — local storage, inter-process communication, and traffic between the app and its backend.

Android

Wireless Assessment

802.11 network testing — rogue access points, encryption weaknesses and authentication bypass across corporate wireless deployments.

Wi-Fi

Security Code Review

Manual review of application source code to catch the vulnerability classes that black-box testing alone tends to miss.

Code

Digital Forensics

Post-incident investigation and evidence handling for Windows and GNU/Linux environments following a suspected compromise.

Incident response

Approach

How an engagement runs

From the first scoping call to a retest that confirms the fixes actually hold.

01

Scoping & rules of engagement

We agree targets, testing windows, and boundaries in writing before any traffic touches your systems.

02

Reconnaissance & mapping

Enumeration of the attack surface — hosts, endpoints, services and roles — to build an accurate picture of what's exposed.

03

Testing & exploitation

Manual testing against the agreed scope, chaining findings the way a real attacker would rather than reporting isolated issues.

04

Reporting & risk rating

A report with reproduction steps, evidence, and severity ratings — written for both engineers and decision-makers.

05

Remediation support & retest

Follow-up review to confirm fixes hold, and direct support for your team while they remediate.

Credentials

Record

Background, certification and public disclosure history.

Certification
Offensive Security Certified ProfessionalOSCP · obtained 2018
Public disclosure
CVE-2023-2359Vulnerability disclosed 2023
Education
MSc Computer Science & EngineeringUniversity of Bologna · 110/110 cum laude
Research background
Swarm robotics & AIThesis work at IRIDIA, Université Libre de Bruxelles — 3 peer-reviewed publications

Get in touch

Start a scoping call

Tell me the systems in scope and the timeline you're working to, and I'll come back with a proposal and estimate. NDAs welcome — yours or mine, whichever you prefer.

Email enable JavaScript to view
Location Italy
Availability Remote & on-site, Worldwide
VAT no. IT 03965020401
Contact me