V

Vincent Y.

CEO

Hong Kong, Hong Kong, Hong Kong SAR11 yrs 4 mos experience
Most Likely To SwitchAI ML Practitioner

Key Highlights

  • Two decades of experience in offensive cybersecurity.
  • Expert in Red Team exercises and threat simulation.
  • Recognized leader in cybersecurity tool development.
Stackforce AI infers this person is a Cybersecurity Expert specializing in offensive security and Red Team operations.

Contact

Skills

Core Skills

CybersecurityTool Development

Other Skills

Automated Shellcode MutationBackdoor SeriesExploitationPayload GenerationCommand and Control TechniquesNetwork SecurityLinuxComputer SecurityHackingActive DirectoryWindows DomainCitrix XenDesktopWindowsPHPSQL

About

Helping customers protect their organisations from bad guys. Offensive Cybersecurity Leader / Ethical hacker with around two decades of experience in hacking operations. We serve clients using offensive security to scrutinise their posture and enhance their resiliency through unique insights backed with real data. If you need proper Red Team just contact me. We specialise in getting in, not marketing. Security Qualifications: * MITRE - MAD Cyber Threat Intel * MITRE - MAD Security Operations Center Assessment * MITRE - MAD Adversary Emulation Methodology * OSEP - Offensive Security * PA Certified Enterprise Security Specialist * Certified Red Team Expert * eLS Certified Penetration Tester eXtreme * CCT Infrastructure - CREST (ex-CHECK Team Leader) * OSCE - Offensive Security * CRT - CREST * CSTA - 7Safe * OSCP - Offensive Security * 2015 Finalist - Cyber Security Challenge General Qualifications * 4 Year MEng Computer Science - University of Warwick CVE: * CVE-2023-46314 * CVE-2023-46315

Experience

11 yrs 4 mos
Total Experience
2 yrs 5 mos
Average Tenure
2 yrs 7 mos
Current Experience

Hacking group

Co-Founder of HG852C

Jun 2025Present · 11 mos · Hong Kong, Hong Kong SAR · Hybrid

  • Co-founder along with Captain of HG852C - a local Hong Kong technical cyber community.

Syon security

2 roles

Managing Director

Promoted

Oct 2023Present · 2 yrs 7 mos

  • At SYON Security Ltd, we provide Advanced Cyber Security Services to our global client base. Our team consist of world-class experts that adopt the "adversarial" mindset and role to provide a necessary alternative analysis of your organisation's security.
  • Our team are battle-hardened and ready with real-world capabilities. We retain our clients through high value and cost effective Red Team exercises which out-class our competitors.

Interim Financial Controller

Sep 2023May 2024 · 8 mos

  • Temporarily stepping in as the FC
  • Payroll, HR, admin, tax, and more

Defcon adversary village

Defcon Adversary Village CFP Review Board

Apr 2021Present · 5 yrs 1 mo

  • https://adversaryvillage.org/cfp-review-board/
  • Vincent is on the Defcon 29, 30, 31, 32, 33 Adversary Village CFP Review Board and shares his expertise to ensure selection of the best papers and research to be showcased in the prestigious event.
  • Helping to filter out the noise.

Deloitte

Director | Cyber Risk

Sep 2019May 2021 · 1 yr 8 mos

  • The fourth industrial revolution is driving change at an exciting pace—creating an increasingly global, digital, and interconnected world. The resulting pervasiveness of cyber brings both new business opportunities, and new cyber threats. Deloitte has led the way through every era of cyber risk, from compliance, to resilience, to complexity. Our heritage, combined with deep tech expertise and broad industry experience, means we’re prepared for virtually every scenario.
  • Deloitte’s Cyber Risk services can help clients perform better, solving complex problems so organizations can build confident futures. Smarter, faster, more connected futures. Better futures never before thought possible—for business, for people, and for the planet. Using human insight, technological innovation, and comprehensive cyber solutions, we manage cyber everywhere, so society can go anywhere.
  • Deloitte provides industry-leading audit and assurance, tax and business advisory, consulting, financial advisory and risk advisory services to nearly 90 per cent of the Fortune Global 500 and thousands of private companies. Its professionals deliver measurable and lasting results that help reinforce public trust in capital markets, enable clients to transform and thrive, and lead the way toward a stronger economy, a more equitable society and a sustainable world. Building on its 175-plus year history, Deloitte spans more than 150 countries and territories. Learn how Deloitte’s more than 345,000 people worldwide make an impact that matters at www.deloitte.com .
  • Lead the Red Team, Penetration Test, and iCAST services for Hong Kong, Macau, and Greater China.
  • Hiring and recruitment
  • Sales
  • Delivery
  • Service Line development
  • Product development

Syon security

3 roles

Trainer

Dec 2018Dec 2018 · 0 mo

  • Trained senior level students with Red Team insights and provided a hands-on view of modern attack techniques.

Director

Promoted

Jun 2018Present · 7 yrs 11 mos

  • At SYON Security Ltd, we provide Advanced Cyber Security Services to our global client base. Our team consist of world-class experts that adopt the "adversarial" mindset and role to provide a necessary alternative analysis of your organisation's security.
  • Our team are battle-hardened and ready with real-world capabilities. We retain our clients through high value and cost effective Red Team exercises which out-class our competitors.

Researcher

May 2015May 2021 · 6 yrs

  • https://vincentyiu.com
  • Automated Shellcode Mutation - Backdoor Series
  • WePWNise - Tool to generate sophisticated Office Macro generation to bypass EMET
  • Domain Fronting using High Profile Domains - Using Government, Financial and other domains for Command and Control
  • Domain Fronting using Tor2Web Services and Hiding of Onion URL - Using TOR for C2 without installing TOR on target.
  • Exploiting CVE-2017-0199 HTA Handler Vulnerability - First publicly available Weaponisation PoC / Video Tutorial
  • RDPInception - Tool and PoC to automate worm / attack on TSCLIENT using RDP
  • CACTUSTORCH - Payload generation Tool and PoC of weaponising James Forshaw's DotNetToJScript research
  • LinkedInt - Tool to automate reconnaissance against an organisation and prediction of e-mail formats / report generation.
  • ANGRYPUPPY - Cobalt Strike Aggressor Script to automate execution of Domain Privilege Escalation
  • Exploiting CVE-2017-8759 WSDL SOAP Parser Code Injection Vulnerability - First working PoC in RTF autotrigger with no prompts + Weaponisation video
  • Cloudjacking - hijacking sub domains and domains to obtain trusted and categorised entries that can be used for command and control
  • MaiInt - Tool to automate reconnaissance against a target organisation and predict email addresses for employees and generate reports. Mainly applies to China based organisations.
  • morphHTA - A tool to take Cobalt Strike's PowerShell HTA format, completely obufscate and generate fake code paths, and change the COM spawning mechanism to Explorer or WMI.
  • genHTA - A tool to generate anti-sandbox HTA payloads through the use of a form
  • Weaponising CVE-2018-4878 - First to share weaponised PoC
  • DomLink - Tool to discover more domains owned by the organisation based on reverse WHOIS.
Automated Shellcode MutationBackdoor SeriesTool DevelopmentExploitationPayload GenerationCybersecurity

Fusionx advanced adversary team

Red Team, Security Principal

Oct 2017Jun 2018 · 8 mos · Manchester, Greater Manchester, United Kingdom

  • FusionX UK Red Team
  • Vincent simulates realistic threats utilising both private and commonly adopted threat actor Techniques, Tactics, and Procedures (TTP) to identify valuable systemic issues in client environments. These systemic issues allow for a fast track towards improving security strategy and readiness to fend off real cyber attacks.
  • Speaker at Jingdong Security Conference Beijing 2017 - Cloudjacking for Command and Control

Accenture

Security Consulting Manager

Oct 2017Jun 2018 · 8 mos · Manchester, Greater Manchester, United Kingdom

  • Lead and Manager for FusionX Red Team services in the UK.

Mitnick security

Ghost Team

Aug 2017Sep 2022 · 5 yrs 1 mo · Remote

  • Thank my good friend Kevin for his support and vision. We battled the world as part of the Ghost Team and helped many customers understand their cyber risk.

Mdsec

ActiveBreach - RED TEAM | CHECK Team Leader

Sep 2016Oct 2017 · 1 yr 1 mo · UK Wide

  • MDSec consulting is a leading firm in the cyber security space. I operate as a member of the ActiveBreach team. Present to CISO/Head of security. Work for many in FTSE 100. Vincent is often requested by name.
  • Security Consultancy
  • Scenario Based Penetration Testing
  • Product and Security Research
  • Tool and Exploit development
  • Red Team Lead / Attack Simulation / STAR
  • Asset and Goal Driven Assessments
  • Specialise in Active Directory and Windows
  • Digital Forensics and Incident Response
  • Network Infrastructure, Architecture, Web Applications and Services (Internal/External)
  • Build and Configuration Review
  • Firewall Configuration Review
  • Network Segregation and Architecture Review
  • Wireless Security Assessments
  • Security Gateway Assessments (Proxy, E-mail, Sandbox (FireEye))
  • Active Directory review
  • GPO review
  • ACL review
  • VPN and remote access infrastructure review
  • Citrix and Locked down Environment Breakouts
  • Multi tenant attack path modelling and PoC where possible
  • CHECK Team Leader
  • Purple team consultant
  • Develop and define methodologies for new areas of testing as required
  • Attend strategic client meetings / Board level de-briefs
  • UK Wide
  • Speaker at Snoopcon 2017 - A Year in the Red
  • Speaker at Steelcon 2017 - A Year in the Red
  • Speaker at BSides Manchester 2017 - A Year in the Red
  • Speaker at HITB GSEC 2017 - A Year in the Red
  • Invited Speaker at CISO Security Information Group Q4 2017

Mwr infosecurity

Security Consultant

May 2015Sep 2016 · 1 yr 4 mos · UK Wide & Asia

  • MWR is a global cyber security firm. As a consultant, I deliver a wide range of services for our clients. Performing activities from scoping all the way to delivery of the report. Work with FTSE 100.
  • Author of wePWNise
  • Security Research
  • Interview candidates
  • Project Scoping
  • Client relationship
  • Red Team / STAR / Targeted Attack Simulation
  • Web application testing
  • Web service testing
  • Security Systems Architecture review
  • Infrastructure testing
  • PCI DSS
  • Desktop / Environment Breakout
  • Build / Configuration reviews
  • Network Segregation review
  • Exploit development
  • Custom protocol review
  • UK Wide & Hong Kong
  • Speaker at Snoopcon 2016 - One Template to Rule Them All

Cyber security challenge uk

CSC Masterclass Finalist 2015

Nov 2014Mar 2015 · 4 mos · London, United Kingdom

  • Finalist at Masterclass 2015 which took place on the HMS Belfast in London.
  • Competed in approximately 5 separate challenge events in total.
  • News & Media:
  • Independent:
  • http://www.independent.co.uk/life-style/gadgets-and-tech/news/cyber-security-challenge-hack-into-hms-belfast-and-blow-up-the-mayor-10104947.html
  • Telegraph:
  • http://www.telegraph.co.uk/technology/internet-security/11467748/UKs-largest-cyber-terror-attack-simulation-gets-underway-on-HMS-Belfast.html
  • Wired:
  • http://www.wired.co.uk/news/archive/2015-03/13/cyber-war-game-hms-belfast
  • BBC:
  • http://www.bbc.co.uk/news/uk-31875832

Undisclosed

Information Security

Jun 2014Aug 2014 · 2 mos

  • Spread importance and awareness of common cyber security threats.
  • Project and Security Risk Management.

Undisclosed

Undisclosed

Mar 2007Sep 2013 · 6 yrs 6 mos

Education

University of Warwick

Master of Engineering (M.Eng.) with Honours — Computer Science

Harvard University

Cybersecurity: Managing Risk in the Information Age

Sep 2021Nov 2021

Stackforce found 100+ more professionals with Cybersecurity & Tool Development

Explore similar profiles based on matching skills and experience