Scroll to top
Red Team · Blue Team · Ethical Hacker · Tokyo

JoeCyberTech

12 years protecting the digital frontier. Red Team. Blue Team. Ethical Hacker. Cybercrime Investigator. Full-Stack Developer. Based in Tokyo, Japan — operating globally.

Book a Consult View Credentials
138 Credly-verified badges · 104+ certifications · 7 domains

Need a Red Team, an Investigator, or a Security Engineer?

How I Work

Full-Spectrum Security From a Single, Trusted Operator

12+

Years protecting the digital frontier

Cyber Defense Dashboard
Security Monitoring Interface
Offensive Security Icon

Offensive Security

Nation-state APT emulation, physical & digital penetration, social engineering and C2 deployment — I find the gaps before real adversaries do.

Defensive Operations Icon

Defensive Operations

SOC architecture, SIEM engineering (Splunk, ELK, QRadar), threat hunting, detection engineering and 24/7 monitoring strategy.

Investigation Icon

Investigation & Forensics

Darknet surveillance, cryptocurrency tracing (BTC, XMR, ETH), OSINT attribution and court-admissible evidence. Wherever they hide, I find them.

Red Team / Blue Team & SOC / Penetration Testing / OSINT / Digital Forensics / Cybercrime Investigation / Incident Response /
What I Do

Six Disciplines. One Security Partner.

From adversary emulation to incident response, cybercrime investigation and secure development, I cover the full attack surface — so you don't need six different vendors to stay protected.

Red Team Operations

Nation-state APT emulation, physical & digital penetration, social engineering and C2 framework deployment.

Learn More

Blue Team & SOC

SOC architecture, SIEM engineering (Splunk, ELK, QRadar), threat hunting and detection engineering.

Learn More

Penetration Testing

Web, mobile, API, network, cloud, IoT and hardware — OWASP/CVSS-rated reports with exploit chains.

Learn More

Cybercrime Investigation

Digital forensics, darknet surveillance, crypto tracing (BTC, XMR, ETH) and OSINT attribution analysis.

Learn More

Secure Development

Zero-trust architecture, secure SDLC, DevSecOps pipelines and cloud hardening across AWS, Azure and GCP.

Learn More

Full-Stack Engineering

React, Node, Python, Rust, Go, PostgreSQL — custom security tooling, SIEM dashboards and breach-resistant SaaS.

Learn More
Why Work With Me

Elite Skills, Proven Under Pressure

Every credential is verifiable, every engagement is documented, and every finding ships with a clear path to remediation — one expert who has operated across offense, defense and investigation at the highest level.

0+

Years on the Frontier

0

Credly-Verified Badges

0+

Certifications Earned

0

Security Domains
About Joe

From Tokyo to the Front Lines Worldwide

I'm Joe — a Tokyo-based cybersecurity expert with 12+ years across offense, defense, investigation and development. I've led adversarial simulations and APT campaigns against financial institutions and government networks, and multi-jurisdictional darknet investigations for international law enforcement.

Request Consultation
Credly Verified
138 badges
Selected Engagements

Real-World Operations, Real Results

A selection of engagements across finance, government and law enforcement — adversary simulation, incident response, and cross-border cybercrime investigation.

Led adversarial simulations and full APT campaigns against major financial institutions across Japan.
View Details

APT Simulation — Financial Sector

Multi-jurisdictional darknet investigations, crypto tracing and forensics supporting international law enforcement.
View Details

Darknet Investigation — Law Enforcement

Full-spectrum security operations for government networks — from infiltration testing to detection engineering.
View Details

Government Network Defense

Verified Credentials

138 Credly-Verified Badges

Every badge is publicly verifiable on Credly. Here's a sample of the collection — explore the full wall for all 133.

Certification Library

104+ Certifications Across 7 Domains

Red Team, Blue Team, AI Security, Cloud, Development, Data & Business, and GRC — every certificate viewable and downloadable.

Red Team & Offensive Blue Team & Threat Intel AI & Security Cloud & Infrastructure Development & Design Data, Analytics & Business GRC, IT & Foundations
Vulnerability Research

Discovered CVEs

Security vulnerabilities responsibly disclosed and assigned CVE or GitHub Security Advisory (GHSA) identifiers, coordinated with the affected vendors and maintainers.

9+ CVEsdisclosed
coordinated disclosure in progress Additional disclosures

More CVEs are currently in coordinated disclosure. They will be listed here as soon as the advisories are published.

coming soon

// more coming — new disclosures added as they are published

Open Source

DSSRF — An OWASP-Listed SSRF Defense Library

A JavaScript library I wrote and maintain: it validates and sanitizes URLs before your application makes an outbound request, so server-side request forgery never leaves the gate.

DSSRF — Defend. Validate. Protect. A JavaScript library that blocks SSRF attacks by validating URLs before outbound requests.
300K+npm downloads
1M+reached via GitHub
OWASPlisted as a defense tool
MITfree & open source
OWASP listed

“dssrf — Defend Against SSRF attacks by providing huge of utils for validation; you integrate it with your web client before making request, you validate the url for eliminating SSRF attacks.”

— OWASP Foundation, Free for Open Source Application Security Tools (Defense Tools)

Coordinated Disclosure

Reported to Vendors and Government Agencies

Every vulnerability I find goes through responsible, coordinated disclosure — with the affected vendor first, and with the national authorities when the impact reaches beyond a single product. Router firmware, exposed devices, malicious domains and phishing email infrastructure alike.

TP-Link PSIRT
Vendor disclosure · router & IoT

Multiple vulnerabilities reported against TP-Link consumer router firmware — static private keys baked into every unit, unencrypted management paths and unauthenticated administrative protocols — all disclosed through the vendor’s PSIRT process.

CISA
US Cybersecurity & Infrastructure Security Agency

When a vendor is unresponsive or a product is widely deployed, I escalate through CISA’s coordinated vulnerability disclosure program. CVE-2026-58378 (network-exposed ADB) was published by CISA as VA-26-190-03.

GCHQ
UK Government Communications Headquarters

Reported a denial-of-service flaw in CyberChef, GCHQ’s open-source “Cyber Swiss Army Knife”: the Generate Lorem Ipsum operation had no bounds check on its Length parameter and could take down a CyberChef Node backend. Coordinated with GCHQ and fixed in v11.1.1 (GHSA-hjwj-84x5-h7gr).

FBI · IC3
Law-enforcement referral · cybercrime

Criminal infrastructure surfaced during investigations — credential-harvesting kits, mule email accounts, malware distribution hosts — is referred to the FBI’s Internet Crime Complaint Center (IC3) with the supporting evidence and attribution analysis.

National CERTs & government bodies
Global vulnerability reporting

Cross-border issues and flaws touching critical infrastructure or public-sector systems are reported to the relevant national CERT/CSIRT and government bodies, and I stay engaged until a fix is rolled out.

Malicious domains & email
Takedown reporting

Phishing domains, spoofed email infrastructure and fraud sites are mapped and reported to registrars, hosting providers, mail providers and national abuse desks so they get taken down rather than just blocked locally.

// policy — responsible disclosure only; no details published before a fix ships

Capture The Flag

CTF Achievements

Competitive hacking results from international CTF competitions — offensive skills, proven under pressure.

Hack for a Change
September 2026 · UN SDG 16
Top 1international contest

Finished #1 in the international contest built around UN Sustainable Development Goal 16 (Peace, Justice and Strong Institutions).

View scoreboard ↗
Hack for a Change
July 2026 · UN SDG 7
Top 2international contest

Placed in the top 2 of the international contest built around UN Sustainable Development Goal 7 (Affordable and Clean Energy).

View scoreboard ↗
Hack for a Change
May 2026 · UN SDG 1
Top 4/ 1888 experts

Ranked top 4 out of 1888 expert engineers and hackers, building solutions for UN Sustainable Development Goal 1 (No Poverty).

View scoreboard ↗
Cyber CTF (Global)
International
#5 World · #1 Asia/ 5000+ players

Placed 5th worldwide and 1st in Asia among more than 5000 players in a global capture-the-flag competition.

SECCON Beginners CTF
2024 · Japan
Top 7/ 1000 teams

Ranked in the top 7 out of 1000 teams in Japan's premier beginner CTF — pwn, web, crypto & reversing.

View scoreboard ↗

// more coming — new competitions added each season

Need a Red Team, an Investigator, or a Security Engineer?