Hello, I’m Chris Hippensteel, Ethical Hacker and Cybersecurity Specialist … So, What Exactly Do I Do?
Hi, I’m Chris Hippensteel, and I’m an Ethical Hacker and Cybersecurity Specialist. I know that when most people hear the word “hacker,” they picture someone in a dark hoodie typing furiously in a basement, trying to break into systems for personal gain. But that’s not me. Not even close.
An ethical hacker is a cybersecurity professional who is authorized to attempt to break into systems, networks, and devices on purpose, so that organizations can discover their weaknesses before the bad guys do. Think of it like hiring a locksmith to test every door and window in your house, then reporting back with a list of everything that needs a better lock. Ethical hackers have all the same tools, skills, and knowledge as malicious hackers. The difference is the permission slip and the intent.
The field has its own formal recognition structure. Ethical hackers operate under strict legal guidelines, with written authorization, defined scope, and a clear mission: find it before the bad guys do.
The Color of Your InfoSec Team Matters: Red, Blue, Purple, and Others
The cybersecurity world has borrowed some vocabulary from the military and sports worlds: teams are color-coded by the roles they play. You have likely heard of red teams and blue teams. Let me break down what those actually mean.
The Red Team — The Attackers
Red teams are the offensive side of the house. Their job is to think and act like a real-world threat actor, a hacker, an organized cybercriminal group, or even a nation-state attacker. Red team members use tactics like social engineering, phishing simulations, penetration testing, network infiltration, and exploitation of known vulnerabilities to probe every corner of an organization’s defenses. If a red teamer can get in, a real attacker can too, and finding that out in a controlled environment is infinitely better than learning it during an actual breach.
Some common red team activities include:
- Penetration testing (active attempts to exploit system vulnerabilities)
- Intercepting communications
- Credential harvesting through social engineering
- Testing physical security controls
- Providing blue teams with actionable intelligence for improvement
The Blue Team — The Defenders
Blue teams are the defensive counterparts. While the red team is knocking on every door, blue teamers are watching the network, analyzing logs, monitoring for anomalies, and responding to incidents in real time. Blue teams implement and fine-tune security information and event management (SIEM) systems, harden infrastructure, manage threat intelligence, and run incident response playbooks. If the red team is the attacker in a sparring match, the blue team is the one landing the blocks and counter-strikes.
Blue team professionals typically focus on:
- Monitoring networks for anomalous activity
- Detecting and responding to security incidents
- Strengthening identity and access management controls
- Managing and improving detection and response capabilities
- Digital footprint analysis and threat intelligence
The Purple Team — Both Sides of the Coin
Now here’s where I fit in: I operate on what is known as the purple team. Purple team practitioners do both red and blue team functions, and more importantly, they act as the bridge between the two. Rather than running entirely separate exercises, a purple team approach has offense and defense work in parallel. The red team executes a simulated attack while the blue team detects and responds, and then both sides immediately debrief together to improve defenses.
A purple team exercise typically follows four phases:
- Planning Define scope, systems to test, and attack scenarios
- Simulation Red team attacks while blue team detects and defends
- Debrief Both teams review results, identify gaps, and discuss what worked
- Implementation Improvements are made based on findings
Being a purple team specialist means you see the full picture. I know how attackers think and how defenders need to respond. That perspective makes me a significantly more effective partner for any organization looking to improve its security posture.
Why Ethical Hacking Is Good — Really Good
It might feel counterintuitive. Why would a company invite someone to hack them? The answer is simple: because the alternative is far worse.
Every organization, from a small dental office to a Fortune 500 company, has vulnerabilities. Software gets misconfigured. Old accounts go undeleted. Wi-Fi networks aren’t hardened properly. An employee clicks a phishing link. These things happen. Ethical hacking uncovers these gaps in a controlled, legal, and documented way, before a malicious actor finds them and exploits them for financial gain, data theft, or operational disruption.
The statistics are stark. Breaches cost organizations millions of dollars on average in direct remediation, regulatory fines, reputational damage, and lost business. Ethical hackers provide a proactive defense rather than a reactive scramble. When I walk out of an engagement, the organization has a detailed roadmap of exactly where it is vulnerable and precisely what needs to be fixed. That’s not scary; that’s empowering.
The Tools of My Trade
Now for the part people are always curious about: the gear. Ethical hackers use a range of specialized hardware and software to test systems. Some of these tools look like something from a spy thriller, but they serve legitimate and critical security testing purposes. Let me walk you through a few of the hardware tools I use in the field.
The HackRF One — Software-Defined Radio for the Real World
The HackRF One, made by Great Scott Gadgets, is a Software Defined Radio (SDR) device capable of transmitting or receiving radio signals across an enormous frequency range: 1 MHz all the way up to 6 GHz. To put that in perspective, that range covers everything from AM radio to Wi-Fi, Bluetooth, cellular signals, GPS, and beyond.
In the hands of an ethical hacker, the HackRF One is an incredibly powerful testing instrument. It allows me to:
- Scan radio frequency spectrums to identify what signals an organization is broadcasting
- Test the security of wireless communications infrastructure
- Identify unauthorized transmitters on a network
- Analyze proprietary wireless protocols for vulnerabilities
- Perform signal capture and replay testing to check if systems are vulnerable to replay attacks
Here is where I need to be candid with you. The HackRF One is an open-source, commercially available device, and it does not care about intent. In the wrong hands, it can be used to intercept communications, capture and replay signals to unlock cars or building access systems, interfere with wireless devices, and conduct radio frequency attacks against mobile devices. The tool itself is neutral. The person holding it is not. That duality is something every ethical hacker takes seriously, and it’s why responsible use, proper authorization, and legal safeguards are non-negotiable in this profession.
The Wi-Fi Pineapple, The Network Auditor with a Funny Name
If you’ve never heard of a Wi-Fi Pineapple, you might smile when you learn how it got its name: the device is small and black with several antennas sticking up from it, loosely resembling, you guessed it, a pineapple. It’s manufactured by Hak5, and it’s one of the most well-known wireless network auditing tools in the industry.
You may have actually heard of it by name. The Wi-Fi Pineapple has been featured in TV shows and news stories, and it’s well known in both the security community and among threat actors looking for an easy way to intercept traffic. The Wi-Fi Pineapple Mark VII supports dual-band operations (2.4 GHz and 5 GHz), and its web-based interface allows security professionals to perform sophisticated wireless tests without requiring deep command-line expertise. When I use it in a legitimate pen test, I’m able to:
- Conduct network reconnaissance and client tracking
- Capture and analyze wireless traffic
- Test whether an organization’s devices would automatically connect to a rogue access point
- Perform man-in-the-middle (MITM) testing to see if network traffic can be intercepted
- Identify misconfigured or unsecured wireless networks
As with the HackRF One, the Pineapple’s power is exactly what makes it a dual-edged sword. A malicious actor or a script kiddie could deploy a Pineapple in a coffee shop or hotel lobby to create a fake Free Wi-Fi network. Unsuspecting users connect, and suddenly their traffic is being monitored. Credentials get harvested. Sensitive data gets exposed. That attack is silent and extremely difficult to detect in real time.
Protecting yourself from a Pineapple-style attack is straightforward:
- Avoid connecting to public Wi-Fi networks when possible. Use your cellular data instead.
- Use a VPN whenever you are on any network you don’t control.
- Make sure websites you visit use HTTPS (look for the padlock in the browser bar).
- Turn off Wi-Fi on your devices when you are not actively using it.
- Enable multi-factor authentication (MFA) on all accounts. Even if credentials are captured, MFA blocks access.
Other Tools of the Trade
Beyond hardware, ethical hackers and penetration testers rely on a range of software tools to do their work. Here are a few you may have heard of by name, because many of them also appear regularly in news reports about cyberattacks and data breaches.
Nmap (Network Mapper) is one of the most widely used network scanning tools in the world, by defenders and attackers alike. It maps out a network, identifies active hosts, discovers open ports, and fingerprints operating systems and services running on a target. For an ethical hacker, Nmap is typically the very first tool used in a penetration test during the reconnaissance phase. For a threat actor, it serves the exact same purpose, finding the doors worth trying before attempting to kick one in.
Metasploit is arguably the most well-known exploitation framework in existence. It is a platform that contains thousands of prebuilt exploit modules, allowing a tester to identify a vulnerability and then launch a controlled attack to prove it is exploitable. When I use Metasploit in an engagement, I’m demonstrating to an organization exactly what a real attacker would do after finding an unpatched system. It is also one of the tools most commonly referenced in threat actor activity reports, because sophisticated attackers and script kiddies alike use it to automate attacks against known vulnerabilities.
Wireshark is a network protocol analyzer that captures and reads every packet of data traveling across a network in real time. It is genuinely one of those tools that every IT professional, network engineer, and security specialist should know. On the defensive side, it helps incident responders understand exactly what an attacker did after a compromise. On the offensive side, it allows a tester to see whether sensitive data is traveling across a network unencrypted or to analyze traffic patterns that reveal exploitable paths. Threat actors use it for the same reason: to quietly listen and look for credentials, session tokens, or other valuable data moving across a network without proper encryption.
Mimikatz is a tool that many IT and security professionals will recognize by name, often because they have read about it in a breach report. It was originally created as a proof-of-concept to demonstrate a flaw in Windows credential handling. It has since become one of the most widely used post-exploitation tools in the world, both by ethical hackers testing whether a compromised system could be used to move laterally through a network and by real threat actors doing exactly that. Nation-state groups, ransomware gangs, and advanced persistent threat actors have all been documented using Mimikatz as part of their attack chains. In a penetration test, if I can run Mimikatz successfully on a system, it tells the organization that their endpoint protections need significant improvement.
Burp Suite is the go-to tool for web application security testing. It acts as a proxy that sits between a browser and a web server, allowing a tester to intercept, inspect, and modify web traffic in real time. It is used to find vulnerabilities like SQL injection, cross-site scripting, and broken authentication in web applications. As organizations continue to move more of their business operations into web-based platforms and cloud applications, tools like Burp Suite become increasingly important for validating that those applications are not exposing sensitive data or handing attackers a way in through the front door.
All of these tools share something important in common: they are legitimate, widely respected, and in many cases open-source instruments used daily by defenders and testers around the world. They are also all documented in CISA advisories and threat intelligence reports as tools actively wielded by malicious actors. That is not a reason to fear the tools. It is a reason to understand them and to make sure the people testing your environment know how to use them responsibly.
A Note on Script Kiddies vs. Skilled Threat Actors
I want to take a moment to address something important. Not everyone misusing these tools is a sophisticated attacker. In the security world, we have a term “script kiddie” for individuals who run pre-built tools and scripts created by others, often without fully understanding what the tools actually do. They’re not skilled hackers; they rely on the work of others and are typically motivated by the desire to cause disruption, show off, or just see what happens.
The danger? Even a script kiddie can do real damage with the right tool. A Wi-Fi Pineapple purchased for a few hundred dollars can be configured in minutes to intercept the traffic of dozens of users. A HackRF One in the wrong hands can disrupt wireless communications or conduct replay attacks against access control systems. The tools themselves don’t discriminate. This is precisely why the ethical hacking community takes authorization, documentation, and rules of engagement so seriously, and why organizations need to take wireless and RF security just as seriously as they take endpoint and perimeter security.
What IT Leaders Should Be Doing Right Now
I want to talk directly to the IT leaders, executives, and decision-makers reading this. You likely have firewalls. You probably have endpoint protection. You may have a written incident response plan gathering digital dust somewhere. But there are two things I see consistently underutilized in organizations of all sizes: tabletop exercises and penetration testing.
Tabletop Exercises — Fire Drills for Cyber Attacks
A cybersecurity tabletop exercise is exactly what it sounds like: your leadership, IT team, and key stakeholders sit around a table (or video call) and walk through a realistic cyberattack scenario, step by step, to evaluate how your organization would actually respond. No systems are affected. No data is at risk. But the insights are invaluable.
Think of it like a fire drill. You don’t want the first time your team practices evacuating the building to be when there’s actual smoke in the hallway. Similarly, you don’t want the first time your incident response team coordinates a ransomware response to be at 2 a.m. on a Tuesday when the CFO is on the phone about encrypted servers.
Tabletop exercises reveal:
- Gaps in your incident response plan and communication protocols
- Unclear roles and responsibilities during a crisis
- Missing escalation paths and vendor contact information
- Whether your disaster recovery plan actually works under pressure
- How well your executive team makes decisions under stress
Organizations should aim to conduct tabletop exercises at least once per year, with the strongest security programs running them quarterly. They typically last between one and three hours and should involve not just IT, but HR, legal, communications, and executive leadership. A skilled facilitator will introduce injects—surprise twists mid-exercise, such as a key team member being unavailable or the backup system being compromised—to truly stress test your team’s adaptability.
These exercises are also an excellent way to validate your disaster recovery (DR) plan. Walking through a simulated data center outage or ransomware event reveals whether your RTO/RPO assumptions are realistic, whether your communication trees are up to date, and whether your recovery runbooks actually contain the right steps in the right order. Many organizations discover mid-exercise that their DR plan references systems, contacts, or procedures that no longer exist.
Penetration Testing: Proof, Not Promises
If a tabletop exercise is the fire drill conversation, a penetration test is actually pulling the alarm and timing the evacuation. Penetration testing involves a skilled ethical hacker, someone like me, actively attempting to exploit vulnerabilities in your real systems, with your full authorization and defined rules of engagement.
A well-structured penetration test typically covers:
- Perimeter and external attack surface — What can an attacker see and exploit from the internet?
- Wireless security — Are your Wi-Fi networks segmented and hardened?
- Internal network security — How far can an attacker move once inside?
- Application security — Are your web apps and internal applications exposing sensitive data?
- Social engineering — Will your employees hand over credentials if asked the right way?
The findings from a penetration test give you something no compliance checklist or vulnerability scanner can: proof of exploitability. It’s one thing to know a vulnerability exists. It’s another to have a professional demonstrate exactly how it would be exploited, what data would be exposed, and what the real-world impact would be.
Penetration tests also pair perfectly with tabletop exercises. Run the tabletop to identify process and communication gaps, then run a pen test to find the technical gaps. Together, they give you a comprehensive picture of where your organization stands.
Work With Ethical Hackers/Pentesters
Organizations often assume they need a large security team to benefit from ethical hacking services. They don’t. Engaging an external ethical hacker or a specialized cybersecurity firm for a targeted engagement, even once a year, provides enormous value at a fraction of the cost of responding to a real breach.
When you work with someone like me, you get:
- An independent, unbiased assessment of your security posture
- Real-world attack simulations tailored to your specific environment
- A detailed findings report with prioritized remediation recommendations
- Hands-on validation of your incident response capabilities
- An honest conversation about where your greatest risks actually live
This isn’t about scaring you. It’s about preparing you. The threat landscape is real, and it’s evolving constantly. But the organizations that invest in proactive testing, realistic simulation, and continuous improvement are the ones that respond to incidents faster, recover more efficiently, and, most importantly, prevent many of them from happening in the first place.
Practical Steps You Can Take Today
You don’t need to hire an ethical hacker tomorrow to start improving your security posture. Here are some concrete, actionable steps any organization can take right now:
- Enable MFA everywhere. Multi-factor authentication is the single highest-impact, lowest-cost security control available. Deploy it on email, VPN, cloud services, and every application that supports it.
- Conduct a Wi-Fi audit. Identify every wireless access point in your environment. Ensure guest networks are properly segmented from internal resources. Remove any rogue or unauthorized access points.
- Keep systems patched and updated. The majority of successful attacks exploit known vulnerabilities with available patches. Script kiddies and advanced threat actors alike target unpatched systems.
- Train your people. Humans are consistently the most exploited attack vector. Regular security awareness training, including simulated phishing, builds the human firewall.
- Dust off your incident response plan. If you have one, review it. Make sure contacts are current, steps are realistic, and your team knows it exists. If you don’t have one, start there.
- Schedule a tabletop exercise. You don’t need a vendor or a fancy platform to run a basic tabletop. Pick a realistic scenario (ransomware is a great starting point), gather the right people, and walk through it. The conversations that emerge are worth more than any policy document.
- Talk to an ethical hacker. Reach out to a cybersecurity specialist for an initial conversation about your risk profile. You may be surprised at what a focused engagement can reveal.




