Michael Kim

Michael Kim

Red Team, Offensive Security Consultant

Actions

Michael Kim’s journey into cybersecurity is a story of resilience and reinvention. Having lived in seven countries, he faced relentless bullying, racism, and isolation growing up, which were challenges that once pushed him to the brink. After pursuing paths in veterinary medicine, pharmacy, law, and biology, and graduating with a zoology degree, he shifted careers entirely during the pandemic. He left behind his life as a DJ and music producer to chase a completely new purpose.

Through persistence and a relentless drive, he rose from a boot camp graduate to his current role as a Red Team Security Consultant at Mandiant (Google Cloud). In this role, he conducts advanced adversary simulations and full-spectrum offensive operations. His day-to-day focus covers AI red teaming, custom tool development, and full-cycle penetration testing to identify systemic vulnerabilities and harden critical global infrastructure.

His multicultural background and lived experiences deeply shape his unique approach to hacking and problem-solving. His journey is proof that adversity can be transformed into strength and that anyone, regardless of their background, can build a powerful career in cybersecurity.

redStack: Boot-To-Breach Red Team Platform

A two-hour hands-on workshop/tactic where attendees stand up a red team operator stack (https://github.com/BaddKharma/redStack) and execute a multi-C2 kill chain against a live cyber range. Each attendee gets their own range instance delivered over an OpenVPN tunnel, so no public DNS or exposed infrastructure is required.

Agenda:
10 min, theory and setup verification. Attendees arrive prepped per the prereq packet (AWS CLI, Terraform, AWS account, OpenVPN client). I frame the session with the multi-C2 segmentation tradecraft pattern that the rest of the time builds on.

40 min, staging and provisioning, narrated live. Attendees stand up their operator stack while I talk through each component, the design choices behind it, and the operator decisions that show up at deploy time.

10 min break.

45 min, attack path on a live cyber range. Each attendee runs against their own individually instanced range over OpenVPN. We work through the chain together: Mythic for initial access, Sliver for lateral movement, Havoc for domain dominance. I stay at the table answering questions while attendees execute.
15 min, Q&A, and teardown. I remain available after the slot for one-on-ones with anyone who wants more time on a specific piece.

A prerequisites packet will be published in advance and will cover AWS account setup, CLI and Terraform install, OpenVPN client, and any local tooling. Total AWS footprint stays within default account quotas at 8 instances and 16 vCPU, so no quota increase request is required.

Michael Kim

Red Team, Offensive Security Consultant

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top