Home / About
About Halberd Security LabsWe think like attackers because some of us used to be paid to.
Halberd Security Labs operates under the h4ckers.pro banner. We are a deliberately small, senior team that turns down work we can't do with rigor. Founded in 2014 by three national-CERT responders, we've stayed independent and operator-led ever since.
Make the next breach happen on our terms.
Defenders have to be right every time; an attacker has to be right once. That asymmetry is unfair — so we put a professional, authorized adversary on your side of the table.
We don't sell fear, dashboards, or shelfware. We sell a clear answer to one question: if a capable attacker targeted you tomorrow, where would they get in, how far would they go, and what would it take to stop them? Then we hand you the map to close every door we opened.
Authorized always
Every action we take is contractually scoped and signed off. No surprises, no scope creep, no gray areas.
Defenders at heart
We attack so your team can defend. Knowledge transfer is a deliverable, not an afterthought.
Radically clear reporting
If your engineers can't act on a finding in an afternoon, we haven't finished writing it.
No theater
We won't inflate severity to justify a fee. The risk we report is the risk that exists.
Senior operators, on the record.
You'll meet your lead consultant during scoping — not a sales engineer who disappears after signing.
Dr. Lena Marchetti
Founder & Principal Operator
Former national-CERT incident lead. 18 years across red team and reverse engineering.
Theo Okafor
Head of Red Team
Built and ran adversary-emulation programs for two G-SIB banks.
Priya Raman
Cloud Security Lead
Ex-platform engineer turned breaker; specializes in multi-cloud identity attack paths.
Marcus Vogel
Application Security Lead
Maintainer of two open-source fuzzing tools; logic-flaw specialist.
A decade of disciplined offense.
- 2014Halberd Security Labs founded by three former CERT responders.
- 2017First financial-sector red-team program; CREST accreditation achieved.
- 2020Cloud security practice launched across AWS, Azure, and GCP.
- 2023SOC 2 Type II attested; 2,000th engagement delivered.
- 202631 industries served across four continents — still operator-led, never offshored.