Senior expertise, start to finish.
Prox Offensive is a focused boutique practice. You work directly with a senior offensive security specialist from scope to final report. No junior bench, no handoffs, no diluted attention.
Felix Gutierrez
Founder & Offensive Security Specialist
I'm Felix, offensive security specialist and founder of Prox Offensive Information Security. I help organizations see what attackers see, before the attackers do.
My work centers on external exposure assessment, adversary simulation, and AI-assisted reconnaissance, backed by open-source tooling I build and publish. When you engage Prox Offensive, you work directly with me, from the first scan to the final call.
I believe in digital sovereignty: knowing exactly what you're exposing, controlling your signal, and building systems that don't require blind trust. Every engagement is authorized in writing, evidence-based, and focused on findings you can actually act on.
Credentials & community
Certifications & training
- CompTIA PenTest+
- Harvard/edX CS50 — Web Programming with Python & JavaScript
- Hack The Box Academy — Network Enumeration, Web App Testing, Payloads & Metasploit
- Hack The Box Academy — Pivoting, Tunneling & Adversary Simulation
- TryHackMe — Path to Cyber, Jr Penetration Tester, Red Teaming
Security community
- Volunteer — BSides St. Pete, BSides Orlando, HackSpaceCon, HackRedCon
- Participant — HackMiami, BSides Tampa
Active in the Florida and national security community. The collaboration and "maker" energy come back with me into every engagement.
Research & open source
I run a dedicated research effort: LLM adversarial-robustness testing, multi-agent AI security tooling, adversary-emulation case studies (including APT33), and reconnaissance automation, all published in the open on github.com/DonTrabajo.
This research informs the commercial work: studying how attackers view a public attack surface is exactly what sharpens how we map your external exposure. It stays separate from the engagements themselves; our assessments remain non-intrusive. Research feeds the method; it isn't the engagement.
AI Red-Team Lab
Local-first, reproducible harness for evaluating LLM robustness: 33 adversarial cases across 8 attack categories, with a CI-enforced OPSEC gate.
DonTrabajo/ai-redteam-lab ↗Prox Recon
Offline-first reconnaissance core: linPEAS parsing and CVE matching, with CI-enforced OPSEC gates. The public core of our recon tooling.
DonTrabajo/prox-recon ↗AI Multi-Agent Lab
Local-first multi-agent red-team lab: orchestration, LLM routing, and OPSEC-first workflows. Sanitized architecture and demos.
DonTrabajo/ProxOffensive-AI-MultiAgent-Lab ↗APT33 Case Study
Adversary-emulation case study with detections, threat-hunting queries, and results/tuning notes.
DonTrabajo/apt33-scythe-case-study ↗Recon Audit Sample
A public-safe external-exposure audit: methodology, report structure, and a full example report.
DonTrabajo/recon-audit-sample ↗Try the free DIY Recon Toolkit, or browse everything on GitHub.
How I work
Authorized & ethical
Every engagement requires written authorization. No testing without explicit owner permission.
Evidence-based
Every finding ships with proof: screenshots, requests, and reproduction steps you can verify.
Business-context first
We translate technical exposure into impact your leadership and auditors actually understand.
Remediation-focused
Every report ends in a prioritized roadmap with verification steps, ordered by what would hurt you first.
Want senior eyes on your exposure?
Book a short call, tell us what you're running, and we'll scope the right engagement.