Enterprise networks. Embedded systems. Everything between.

Trevor KemsOffensive Security Engineer
& Security Researcher

I break systems to understand how they fail.

I specialize in penetration testing, vulnerability research, firmware and binary reverse engineering, Active Directory security, and embedded/IoT devices. My work spans enterprise environments, hardware, radio protocols, mobile applications, and custom embedded systems.

  • OSCP
  • 3 Published CVEs
  • Splunk .conf Speaker

Selected work

Featured research.

All research

From a camera's flash chip to the trust relationships in Active Directory. Detailed writeups, source code, and talks behind the work.

Attacks, detection & a vulnerable lab

Active Directory Certificate Services

Exploring ADCS attack methods and defenses through talks and Damn-Vulnerable-ADCS, a PowerShell lab setup for testing NTLM relay vulnerabilities. Used in Iowa State University's Cyber Defense Competition.

  • Active Directory
  • ADCS
  • PowerShell

Binary reverse engineering

LockBit 3.0 decryptor breakdown

Reverse engineering the recovery tool's decryption-ID checker with Ghidra: unpacking Nuitka output and tracing how SHA-256 hashes are compared against a lookup table.

  • Reverse Engineering
  • Ghidra
  • Python

Hardware & radio protocols

Garage door RF security

Investigating garage-door radio protocols with accessible hardware. Research notes, a Python implementation for decoding Security+ 2.0 transmissions, and a practical walkthrough presented at SecDSM.

  • RF
  • Hardware
  • Protocol Analysis

Areas of focus

Across layers of a system.

Enterprise offensive security

Internal and external penetration testing, web applications, Active Directory, ADCS, Kerberos, and social engineering.

Vulnerability research

Binary analysis, vulnerability discovery, proprietary protocols, cryptography implementation review, and coordinated disclosure.

Embedded & IoT security

Firmware extraction, SPI and serial interfaces, embedded Linux, ARM and MIPS reverse engineering, mobile applications, and RF.

Security tooling

Purpose-built utilities in Python, PowerShell, and C, with Ghidra, Burp Suite, Wireshark, and SDR tools for investigation.

Speaking & community

Making the technical
work understandable.

I share practical investigations into ADCS, IoT cameras, RF, RFID, and hardware reverse engineering.

Explore all talks

Splunk .conf / 2024

Protecting ADCS with Splunk

Detecting common attacks and enabling certificate authority logging.

Also presented at Secure Iowa, BSides Iowa, and Iowa State University.

Trevor Kems

Beyond the engagement

Curiosity, with a soldering iron.

I enjoy taking systems apart: in software, with a debugger, and sometimes literally with a soldering iron. Outside professional penetration testing, I investigate embedded devices, unusual hardware, and security problems that have received little attention.

I also restore vintage computers and build security projects for competitions and the security community.

More about me

Let's talk technical security.

For research conversations, speaking, and professional inquiries.

Connect