Daniel Oz

Daniel Oz

Head of Offensive Cyber Division  ·  Security Researcher  ·  Red Teamer

I research how systems fail. Then I prove it.

01

Offensive Research

Vulnerability discovery, attack surface analysis, and exploitation of modern systems and protocols.

02

Red Team Ops

Adversary emulation, realistic TTPs, and end-to-end attack simulations against enterprise environments.

03

Capability Dev

Building offensive tooling, custom exploits, and attack infrastructure from scratch.

I am a security researcher driven by a simple question: how do systems really work and how I can exploit them to my advantage?

Vulnerabilities are interesting, but they are rarely the most interesting part. Every exploit is the result of design decisions, trust relationships, architectural constraints, and assumptions that seemed reasonable until someone proved otherwise.

Today, I lead the Offensive Cyber Division at one of Israel's largest healthcare organizations, where I focus on offensive security research, adversary emulation, Red Team operations, and offensive capability development.

This blog is a collection of research, ideas, and technical deep dives. Some posts are focused on vulnerability research and exploit development, others explore attack surfaces, reverse engineering, or the internals of modern systems. Many begin with a simple question and end somewhere completely unexpected.

I am particularly interested in how small observations evolve into meaningful offensive opportunities - whether through a design flaw, an overlooked trust relationship, or the interaction between otherwise legitimate components.

Offensive security is not a job title. It is a way of life. The way I see systems, interact with technology, and ask questions is shaped by one underlying drive: to understand how things truly work, and find exactly where they fail.

Being a hacker is not just a word. It is a mindset that changes how you look at everything - every trust relationship, every design decision, every assumption someone made and never questioned.

The exploit is rarely the interesting part. The interesting part is the model you built to understand why it should work. The exploit is just proof that the model was correct.

Understand the system. The vulnerabilities will follow.