Matthew Eidelberg

Red Teamer at Black Hills Information Security

Old Toronto, Ontario, Canada
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Matthew Eidelberg is a Red Teamer with nine years of offensive security experience, currently consulting at Black Hills Information Security after senior roles at Optiv where he led breach and threat management efforts. He combines deep hands-on exploit and payload development with engineering rigor—contributing to open-source tooling such as ScareCrow, Ivy, and SourcePoint that focus on EDR/AMSI bypass, VBA in-memory execution, and C2 profile generation. His background spans wireless pentesting tooling and novel delivery techniques (including a ZIP-exec loader), reflecting a blend of low-level attack techniques and backend engineering. Known for practical evasions like ETW/AMSI bypasses, code-signing work, and loader innovation, he bridges red team operations and developer-centric tooling. Based in Old Toronto, he holds a Bachelor of Technology in Informatics and Security from Seneca@York and has a track record of shipping reproducible offensive frameworks that practitioners use to emulate real-world adversaries.
code10 years of coding experience
job7 years of employment as a software developer
bookYork Mills
bookBachelor of Technology, Infomatics and Security, Bachelor of Technology, Infomatics and Security at Seneca@York
github-logo-circle

Github Skills (41)

process-injection10
shellcode10
code-signing10
injection10
zip-archive10
inject10
scapy10
python10
wp-api10
it-security10
audit10
vba10
winapi10
zip10
security10

Programming languages (8)

C#PowerShellRustCVBAGoPythonKotlin

Github contributions (5)

github-logo-circle
Tylous/SniffAir

Feb 2017 - Oct 2020

A framework for wireless pentesting.
Role in this project:
userSecurity Engineer
Contributions:4 releases, 82 commits, 14 PRs in 3 years 8 months
Contributions summary:Matthew contributed significantly to the `sniffair` repository, which is a framework for wireless pentesting. The user's commits primarily focused on developing the core sniffing functionalities, including packet capturing, SSID identification, MAC address extraction, channel analysis, and encryption detection. They also implemented modules related to handshaking, proof packets, and other pentesting-related tasks. The user also worked on setting up modules, including hostapd and captive portal capabilities.
pentestingwireless
Tylous/SourcePoint

Aug 2021 - Jul 2022

SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.
Role in this project:
userBackend Engineer
Contributions:13 releases, 24 commits, 9 PRs in 11 months
Contributions summary:Matthew's primary contribution involves generating Cobalt Strike command and control profiles, a core functionality of the `tylous/sourcepoint` repository. The code changes focus on building various profile components, including communication, HTTP, and SSL configurations. Furthermore, the commits highlight modifications to custom URI generation and profile selection features. These contributions indicate a focus on enhancing the functionality and flexibility of the profile generation process.
sourcepointstrikecobalt-strikeprofile-generatorcommand-and-control
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial