Security engineer. Incident responder. Father of three small humans who have absolutely no respect for my sleep schedule... Not that I have that myself either?
I have spent days rebuilding Active Directory after ransomware hits around the world, navigating NIS2 compliance for organisations that thought they had more time, and explaining to boards why "we have a firewall" is not a security strategy.
When I'm not doing that, I'm at home with my wife and our three kids, which has taught me more about crisis management, negotiation under pressure, and maintaining composure in chaotic environments than any IR engagement ever could.
- Dummy.Lab, Hyper-V lab automation for Windows Server and Active Directory environments. PowerShell module with 52 composable cmdlets, pipeline-first design, golden image pattern, and a central audit trail that survives lab teardown. Built because repeatable, instrumented test environments should not be a manual process.
- Scripts and utilities from real consulting work, published when they are useful beyond the engagement they came from.
| Repository | Description |
|---|---|
| Dummy.Lab | Hyper-V lab automation platform for Windows Server and Active Directory environments |
| ADObjectOwner | PowerShell module for auditing and correcting AD object ownership, available on the PowerShell Gallery |
| Active-Directory-Unknown-SID | Guide on orphaned and unresolvable SIDs in Active Directory, with risk context and remediation tooling |
| EventViewerCustomViews | Windows Event Viewer Custom View filters for security auditing and forensics |
| EventFromCustomView | PowerShell module for querying the Windows Event Log using Event Viewer Custom View XML files |
| PowerShell | Scripts covering Active Directory, Microsoft Defender, logging, and general automation |
| PowerShell-InMemory-Execution | Explanation and samples of PowerShell InMemory Execution, written from a defender's perspective |
20+ years in IT and cybersecurity. The last several focused on:
- Active Directory recovery and hardening from scratch
- Board and senior leadership advisory, kinda like helping the elder...
- Ransomware incident response, the "everything is on fire" kind
- NIS2 and CIS18 compliance work for critical infrastructure
GICSP certified. Based just outside Copenhagen, Denmark. Operating across Europe, Africa, and the US.
- LinkedIn, professional content and occasional strong opinions
- sndnss.dk, my own company (sndnss aps), where development and side projects happen
- Globeteam, the consulting house, where client engagements run
Three kids. One wife. Zero tolerance for unpatched domain controllers.
