Skip to content

Available for engagements - Brașov, Romania

Petre Radu
Cătălin

Penetration Tester @ NTT DATA

Offensive Security · Red Team · Cloud & AI Security

I'm Petre Radu Cătălin, a Penetration Tester at NTT DATA. I identify critical vulnerabilities in Active Directory, cloud environments, and complex web applications - then deliver remediation guidance that security teams can act on immediately.

  • TryHackMe PT1 Certified
  • HackTheBox Holo Tier
  • OpenAI Cyber Practitioner
Petre Radu Cătălin - Penetration Tester based in Brașov, Romania
● ONLINEsituated: BRASOV, RO

// whoami

About Petre Radu Cătălin

Offensive security professional · Penetration Tester at NTT DATA · Based in Brașov, Romania. Known as Petre Radu to clients, peers, and the security community.

Petre Radu Cătălin - About, penetration tester in Brașov, Romania

Who I am

I'm Petre Radu Cătălin - often simply known as Petre Radu - an offensive security professional and Penetration Tester at NTT DATA, based in Brașov, Romania. Every day I probe enterprise networks, web applications, and cloud infrastructure for the flaws that attackers are paid to find, and I translate them into risk owners can understand and engineers can fix.

My philosophy

My approach to security is simple: real risk over noise. Anyone can produce a spreadsheet of low-severity findings. My work focuses on what actually matters - the vulnerabilities that persist, the paths that lead to domain compromise, and the remediation guidance that a security team can act on the same day. Every report I ship includes a clear, prioritized, and technically accurate plan to get from 'vulnerable' to 'defended'.

The journey

My path runs through the Master's programme in Cyber Security at Universitatea Transilvania din Brașov (2024-2026), where I studied advanced cyber defense, red and blue team operations, and security auditing - and where I complemented the curriculum with Google.org Cybersecurity Seminars in 2025. That foundation carried me into enterprise penetration testing at NTT DATA, where I lead assessments against production systems at scale.

Beyond the enterprise

Between full-time engagements, I work as a Bug Bounty Hunter on Intigriti and as a Vulnerability Researcher on HackerOne, hunting for flaws in production systems through responsible disclosure. This freelance work keeps me sharp: real bug bounty programs are a constant grind of edge cases, business logic abuse, and access control failures that no lab environment can reproduce.

Beyond testing

My scope extends past traditional pentesting into AI security evaluations - testing LLM applications for prompt injection, data exfiltration, and excessive agency - and into the regulatory world through GDPR assessments and NIS2 implementation support. Security is a moving target, so I treat continuous learning as part of the job: new platforms, new tools, new attack classes, every single week.

100+
Certifications
98+
Skills
2+
Years Experience
1000+
LinkedIn Followers

// capabilities

Expertise

Four interlocking disciplines. My offensive work is grounded in an understanding of defense - every assessment I run, from web penetration testing to cloud security review, is built to produce actionable defense.

Offensive Security

Hands-on exploitation across the full attack surface - from web apps to the domain.

  • Web & API penetration testing (OWASP Top 10)
  • Active Directory exploitation & privilege escalation
  • Network security audits
  • Red Team emulation aligned to MITRE ATT&CK
  • Automated recon & exploit development (Python, Bash)

Cloud & AI Security

Breaking and hardening modern, ephemeral attack surfaces before attackers do.

  • Multi-cloud assessments (AWS, Azure, GCP)
  • IAM & identity misconfiguration exploitation
  • AI/ML security evaluations
  • Cloud incident response

Compliance & Governance

Turning regulatory requirements into measurable, defensible security posture.

  • GDPR assessments & data protection reviews
  • NIS2 implementation support
  • Security policy review
  • Technical risk assessment

Defensive Foundation

Knowing the defender's playbook sharpens every offensive engagement.

  • SIEM / SOAR engineering (Splunk)
  • Threat hunting & detection engineering
  • Secure code review
  • Purple-team collaboration

// history

Experience

Enterprise penetration testing, bug bounty hunting, and a Master's in Cyber Security - a career built on finding real vulnerabilities and fixing them for good.

  1. ND

    NTT DATA, Inc.

    Enterprise

    Penetration Tester

    Nov 2025 - PresentRomania · Remote

    • Lead enterprise penetration tests, identifying RCE, SQL injection and broken access control issues across production applications.
    • Deliver full-chain Active Directory attack simulations from unauthenticated foothold to domain compromise.
    • Build custom automation scripts that cut assessment turnaround by 30%.
  2. I

    Intigriti

    Freelance

    Bug Bounty Hunter

    May 2026 - PresentRemote

    • Freelance vulnerability discovery on production systems through coordinated programs.
    • Reported and triaged security flaws with clear, actionable remediation guidance.
    • Focused on business-logic abuse and access-control flaws in SaaS platforms.
  3. H

    HackerOne

    Freelance

    Vulnerability Researcher

    May 2025 - Sep 2025Remote

    • Discovered and responsibly disclosed XSS, IDOR, CSRF and access control vulnerabilities.
    • Prioritized impact and exploitability over severity-score theater.
    • Partnered with vendors to validate and remediate findings end-to-end.
  4. Universitatea Transilvania din Brașov

    Master's, Cyber Security

    2024 - 2026

    • Advanced cyber defense, red/blue team operations, and security auditing curriculum.
    • CTF participation and applied security research projects.
    • Google.org Cybersecurity Seminars (Mar 2025 - Jul 2025).

// featured_work

Projects

Selected projects from research, development, and real engagements - static malware analysis, forensic tooling, and the automation that powers my assessments.

MalwarePeek - PE File Analyzer for Static Malware Analysis project by Petre Radu Cătălin

MalwarePeek

PE File Analyzer for Static Malware Analysis

MalwarePeek is a Python-based portable executable analyzer built for malware analysts and reverse engineers. It parses PE headers, fingerprints packers, and scans samples against YARA rules - then generates clean HTML reports for triage.

Python
Malware Analysis
Reverse Engineering
Signature Stealer - Educational PoC - Authenticode Signature Extraction project by Petre Radu Cătălin

Signature Stealer

Educational PoC - Authenticode Signature Extraction

A focused educational proof-of-concept that inspects authenticated code-signing metadata inside signed PE files. It demonstrates how signature blocks remain queryable and how tooling can surface embedded certificate chains for forensic review.

Python
Digital Forensics
Reverse Engineering
Custom Pentest Automation Toolkit - Recon & Vulnerability-Scanning Automation project by Petre Radu CătălinPrivate

Custom Pentest Automation Toolkit

Recon & Vulnerability-Scanning Automation

An internal toolkit of Python and Bash scripts that automate reconnaissance, endpoint enumeration and vulnerability scanning. Used to deliver faster, repeatable assessments and cut end-to-end testing time by roughly 30% at NTT DATA.

Python
Bash
Automation
Offensive Security
Private repoCase study

// credentials

Certifications & Achievements

100+ certifications earned across security, cloud, and AI disciplines - plus CTF results that put the theory to work.

100+ Certifications Earned

Curated highlights below - full list available on request.

TryHackMe Junior Penetration Tester (PT1)

TryHackMe

OpenAI Cyber Practitioner

OpenAI · PartnerU

Microsoft AI Skills Fest 2026

Microsoft

AZ-700: Azure Networking Solutions

Microsoft Certified

Teaching the AI Fluency Framework

Anthropic

Puppet Environment Lab

Skillsoft

Google.org Cybersecurity Seminars

Google.org

CTF Achievements

Offensive security is a competitive sport. These results are how I train between engagements.

  • HackTheBox Season 9

    Holo Tier

  • TryHackMe Industrial Intrusion CTF

    Team Rank 6 / 20,220

  • TryHackMe Honeynet Collapse CTF

    Solo Rank 66 / 960

// arsenal

Tools Arsenal

The tools I reach for daily - offensive platforms, cloud CLIs, and the defensive stack I know well enough to test around.

tools.sh

Cobalt Strike

Sliver

Nighthawk

BloodHound CE

SharpHound

Rubeus

KrbRelayUp

NetExec

Impacket

Responder

Evil-WinRM

Ligolo-ng

Burp Suite Pro

Nuclei

ffuf

Pacu

AzureHound

GCPwn

Prowler

Garak

$ echo "recon --enumerate --exploit --report" | sudo tee /dev/arsenal

// write_ups

Insights from Petre Radu Cătălin

Technical write-ups on offensive security, cloud threats, and AI security - the lessons from real engagements, published to help the community.

9 min read

From Web App to Domain Admin: A Red Team Playbook

A practical, phase-by-phase breakdown of how a single web application flaw can be chained into full Active Directory compromise - and the detection gaps that let it happen.

Penetration Testing
Red Team
Active Directory
Read More

// connect

Work with Petre Radu Cătălin

Available for remote and on-site engagements. Based in Brașov, Romania.

Requests open the email client - no data is stored on this site.