Offensive security enthusiast, Co-founder of Offensys
Cas van Cooten
I test how organizations hold up against real attackers, build open-source offensive tooling, and talk about it at conferences like Black Hat and DEF CON.
Currently building - Offensys
Continuous Purple Teaming
The Offensys platform runs realistic, behavior-based attack simulations in your environment, so you can see what your controls block, what they detect, and what they miss.
Visit offensys.comSpeaking
2026
The Best Defense Is A Good Offense
A Pragmatic Path to Continuous Purple Teaming
2024
2023
- x33fcon,
2022
Nimbly Navigating a Nimiety of Nimplants
Writing Nim Malware Like The Cool Kids
- DEF CON 30 Adversary Village,
Open source
Most of my tooling starts as a side project in Go, Python, Rust or Nim, and I publish it as open source. Releasing offensive tools is a much-debated call, I know. I still think it's the right one: when the tools are out in the open, defenders get to test against them too.
1.8k stars
maldev-
for- dummies A workshop about Malware Development
Nim
1.5k stars
OSEP-
Code- Snippets A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.
C#
953 stars
Nim
Plant A light-weight first-stage C2 implant written in Nim (and Rust).
Rust
923 stars
Bug
Bounty Scanner A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
Shell
283 stars
Cloud
Labs AD Terraform + Ansible deployment scripts for an Active Directory lab environment.
Shell
207 stars
OSCP-
Markdown Reporting Templates Markdown reporting templates and Pandoc styling references to generate sleek reports for OSCP/PWK with little effort.
Writing
All 10 postsAbout
I'm Cas, an offensive security enthusiast and red teamer based in the Netherlands. These days most of my time goes into Offensys, the company I co-founded. I'm always up for a chat about offensive security and new programming languages.

Cas van Cooten
[email protected]
casvancooten.com