Explicit Authorization
Every engagement begins with written authority, an agreed scope, and Rules of Engagement.
Our philosophy
Not only “What vulnerabilities exist?” but “What can an attacker actually accomplish?”
Terminal Cyber Consultants approaches assessments from the perspective of a real attacker: identify exposed paths, challenge trust boundaries, test controls, and determine how technical weaknesses could affect the organization.
That perspective is always balanced by strict scope, safety, and communication. Testing takes place only with explicit authorization and within agreed Rules of Engagement. Objectives, boundaries, escalation procedures, and sensitive actions are established before work begins.
The goal is not activity for its own sake or a longer list of findings. It is a clear understanding of exploitable risk, supported by evidence and paired with remediation guidance that security, engineering, and leadership teams can use.
Working principles
Effective offensive security depends as much on disciplined delivery and communication as it does on technical skill.
Every engagement begins with written authority, an agreed scope, and Rules of Engagement.
Testing methods are selected and controlled to protect systems, data, users, and business operations.
Clear contacts, status updates, and escalation procedures keep stakeholders informed throughout the work.
Findings connect technical evidence to impact, priority, and remediation—not just severity labels.
Leadership
Terminal Cyber Consultants was founded to help organizations understand the difference between theoretical exposure and risk an attacker can actually use.
Founder // Terminal Cyber Consultants
Trevor is an offensive security architect with more than 13 years of experience spanning enterprise red teaming, penetration testing consulting, application security, AI and machine-learning security testing, military cyber operations, and digital forensics.
He has built offensive-security and application-security programs and led full-scope assessments across web applications, APIs, internal and external networks, Active Directory, AWS, Azure, Kubernetes, containers, and identity systems. His work combines attacker tradecraft and exploit validation with detection engineering, secure-coding guidance, and remediation support so findings lead to measurable improvements.
Trevor served in the Utah National Guard as a Cyber Operations NCO focused on cyber threat emulation and previously as a Human Intelligence Collection Sergeant and Mandarin linguist. His background also includes court-ready digital forensics work and collaboration with federal investigative partners.
He holds a Master of Science in Cybersecurity and Information Assurance from Western Governors University. His selected certifications include OSCE3, OSED, OSWE, OSEP, OSCP+, GXPN, and CISSP.
Red teaming · Web and API security · Cloud and Kubernetes · Active Directory · Social engineering · AI security · Detection validation
OSCE3 · OSED · OSWE · OSEP · OSCP+ · GXPN · CISSP
Work with Terminal
Start with your environment, concerns, and objectives. We will help identify the right assessment approach.