// About

Security testing from someone who’s been on the inside.

Crooker Security LLC was founded to give small and mid-sized businesses access to the same caliber of offensive security testing that large enterprises rely on.

// Founder

Hi, I’m William Crooker.

I’ve spent almost ten years in information security, most of it focused on the financial industry — an environment where security has to be rigorous, documented and able to stand up to auditors and regulators.

Along the way I’ve helped multiple small and mid-sized businesses measurably improve their security posture and raise the bar for what attackers have to get through. Again and again I saw the same pattern: smaller organizations face the same threats as large enterprises, but rarely get the same quality of testing.

Crooker Security exists to close that gap. When you work with us, you work directly with me — from the first scoping call through testing, reporting and retest. No hand-offs, no junior staff learning on your network.

My favorite work is Active Directory. Untangling years of permissions, delegations and certificate templates to find the one path an attacker would use — and then helping a team close it for good — is the most satisfying part of the job.

// Certifications

Hands-on, practical credentials.

The core certifications are performance-based: multi-day practical exams in live lab environments that require actually compromising systems — not just answering questions.

OSCP

OffSec Certified Professional

OffSec

CAPE

Certified Active Directory Pentesting Expert

Hack The Box

CPTS

Certified Penetration Testing Specialist

Hack The Box

PenTest+

CompTIA PenTest+

CompTIA

CySA+

CompTIA Cybersecurity Analyst

CompTIA

Security+

CompTIA Security+

CompTIA

// Principles

How we work.

Impact over volume

We’d rather show you the three issues that would actually sink you than bury them in 300 pages of scanner output.

Plain English

Findings are explained so leadership understands the risk and IT knows exactly what to change.

Discretion

Your vulnerabilities are confidential. We handle data carefully and never name clients without permission.

Partnership

Testing isn’t the goal — a more secure business is. We stay available to help you fix what we find.

// Next step

Know where you stand before someone else finds out.

Start with a no-obligation scoping call. We’ll talk through your environment, what’s driving the test and the timeline that works for you.