Skip to content

03 About


Security from the offensive side.

HavocSec was built around a simple idea: the best way to understand how secure a system is, is to understand how it can be broken.

We combine offensive security, technical research, and engineering to uncover weaknesses and turn those lessons into stronger technology.

HAVOCSEC / EST. 2026 / INDEPENDENT

How we think HV/ABT-001

Five principles.

  1. Authorization first

    01

    Nothing is tested without explicit permission and an agreed scope. This is what separates a professional from a threat.

  2. Evidence over claims

    02

    Every finding carries proof, impact, and context. A vulnerability that cannot be demonstrated is a hypothesis, not a finding.

  3. Think like the attacker

    03

    Real attackers chain small weaknesses into serious ones. Assessment follows the same paths.

  4. The report is the start

    04

    The value is not the list of problems. It is the understanding that lets a team fix them and not rebuild them.

  5. Build to endure

    05

    Every lesson from offensive work feeds back into engineering. Breaking is the method, resilience is the goal.

Portrait of Daniel Wambua

FOUNDER / HV/FOU-001

Daniel Wambua

Known as Havoc

Daniel is the offensive security researcher behind HavocSec and the HavocSec blog. He works across penetration testing, security research, and security engineering, and builds the tooling HavocSec uses in the field.

04 Contact

Have something that needs breaking?

Let's identify the weaknesses before someone else does.

All security testing is performed only with explicit authorization and agreed scope.