German
link to LinkedIn profile link to Youtube channel link to uTest profile (login required)
photo

Martin Fürholz

Senior Penetration Tester · Test Team Lead · AI Red-Teaming

Rostock, Germany

High-Performance Security Leadership & Agentic AI Development

The Technical Backbone of Modern Security Testing.
From November 2018 to May 2026, exclusive Test Team Lead for the Applause Security Practice. I acted as an Active Principal: not just architecting frameworks, but leading from the front with elite manual exploitation skills. Pioneer in the development of custom Agentic AI security tools that revolutionized testing efficiency. Final escalation point for high-risk scopes: Host/Infrastructure (OSCP scope), IoT, DRM, and AI Red-Teaming.

Recent Role & Engagements:

Exclusive Security Test Team Lead at Applause (2018-2026, Freelance Retainer since 2022):
Acted as the singular technical safety net. Personally handled the deepest technical dives that others could not solve. Recent benchmark: Identified 28 vulnerabilities in a single AWS subnet of a US online bank (Dec 2025).

Developer of Agentic AI Systems:
Building autonomous, bespoke AI agents (C#/Python) to automate complex reconnaissance and exploitation tasks beyond human speed.

Core Competencies & Innovation:

Deep-Dive Infrastructure & Network Pentesting: Mastery of manual enumeration (Nmap/Wireshark), protocol analysis, and exploitation of complex network environments without relying solely on automated scanners.

AI Red-Teaming & Jailbreaking: Defining the playbook for testing LLM safety and robustness since day one.

Full-Spectrum Coverage: From low-level IoT Hardware & DRM reversing to high-level Web & Mobile App security.

Language: Native German, Fluent English, Conversational French (B1).

ABOUT ME

Personal Details

NAME:

Martin Fürholz

Residence:

Rostock, Germany (since 2012)

Born:

July 18, 1980 in Vienna, Austria

Occupation:

Senior Penetration Tester, Test Team Lead,
Professional Trainer & Subject Matter Expert

Driver's License:

European Type B (own vehicle available)

Professional Competencies

Elite Security Leadership: Exclusive Test Team Lead for the Applause Security Practice (2018-2026).

Proven Track Record: Over 1,500 verified vulnerabilities personally reported at a 99.7% approval rate; author of the official uTest Academy curricula for API Testing and Security Testing (2021-2025).

Advanced Penetration Testing: Expert mastery of Web, Mobile, API, Host/Infrastructure (OSCP scope), IoT, DRM, Cloud (AWS), and Desktop, plus AI Red-Teaming (LLM Jailbreaking & Robustness).

Development & Scripting: Deep proficiency in C#, C++, Java, Python, and Wolfram Language for custom tool development.

Technical Foundation: ECDL Advanced Expert (since 2007): Certified mastery of Office productivity suites, Databases, and Presentation tools.

Interests and Hobbies

Sport:

Wakeboarding (most active rider at Cable Park Rostock since 2023), Trail Running, Skiing/Snowboarding.

Music & Arts:

Music production. Past collaborations with international artists (e.g., London Community Gospel Choir). Early education in Photography (Die Graphische, Vienna).

Broadcasting & Media:

Operator of a professional in-house content studio (set up late 2025) featuring 4K camera gear, teleprompter, studio lighting, and sound isolation. Already producing security workshop videos and music recordings; building toward dedicated channels on Security and Digital Business.

Science & Mind:

Astronomy (observatory access via iTelescope.net), drone photography, and daily chess.

Short Biography

Martin Fürholz is a Senior Penetration Tester with over twelve years of offensive security experience, including eight years (2018-2026) as the exclusive Test Team Lead for the Security Practice at Applause, the world's leading crowdtesting provider. In that role he served as the technical backbone for global testing operations, ensuring delivery quality across high-risk scopes including AI Red-Teaming, IoT ecosystems, and banking infrastructure. Beyond his leadership role, Martin is a hands-on expert with over 1,500 personally reported vulnerabilities at a 99.7% approval rate, and a deep background in software development (C#/C++/Python) dating back to 2000.

He combines this technical depth with strong pedagogical skills, having authored the official uTest Academy courses for API Testing and Security Testing as well as Applause's 60-page AI Red-Teaming Field Guide, and having served as a professional ISTQB lecturer. Martin grounds his cutting-edge security work in solid administrative proficiency (ECDL Advanced Expert since 2007) and diverse creative talents. He is currently pursuing a Bachelor's degree in Digital Business with a focus on AI Economics, to further bridge the gap between technical execution and strategic management.

Continuing Education

B.A. Digital Business (English)
IU International University of Applied Sciences (since September 2024, focus on AI Economics, expected 2027)

Offensive Security Certification (OSWE/WEB-200)
Preparation ongoing, exam scheduled for Fall 2026

NOTABLE ACCOMPLISHMENTS & PROJECTS

from

2025

TO

Present

(1 Year)

Critical Infrastructure

eID AI Security Scan: Agentic AI for the EUDI Wallet

Bridging Offensive AI and Government-Grade Secrecy: To secure Android-based eID implementations and the European EUDI Wallet reference architecture, I engineered a fully automated, agentic AI pentesting scanner from scratch. This system eliminates the friction between rigid public sector compliance and cutting-edge offensive AI capabilities.

Hybrid Methodology & Technical Execution: The system merges deep Static Application Security Testing (SAST) with dynamic runtime analysis (DAST) via Frida. It autonomously evaluates hardware-backed cryptographic operations (Secure Enclave, Keystore), complex authentication flows (OIDC4VP, SIOPv2), and certificate pinning bypasses, concluding with fully actionable Proof of Concept (PoC) validation.

NDA Compliance & Privacy-by-Design (Public Sector Foundation): Cloud-based AI traditionally hits a hard wall in government environments due to data privacy concerns. My architecture solves this at its core: Operating as a strict Data Sovereignty Engine, all sensitive eID infrastructure data and backend communications remain entirely local. External LLM APIs are strictly flag-gated, subjected to automated secret redaction, and utilized exclusively for sanitized, atomic decision trees. Architectural data leakage is impossible.

Government-Compliant Audit Mapping: Every identified attack vector is deterministically mapped against the eIDAS 2.0 Architecture and Reference Framework (ARF), BSI TR-03124 (eID-Client), BSI TR-03110, and ISO/IEC 18013-5 (Proximity/mDL). The output provides tangible, immediately auditable reports tailored for both technical decision-makers and project managers.

from

2023

TO

Present

(3 Years)

Agentic AI Development

GoingLLM: The Autonomous Intelligence Backbone

Visionary Timing: I architected and deployed GoingLLM in early 2023. Recognizing the limitations of static models early on, I built the solution the market was missing: an autonomous agent capable of intelligent, live reconnaissance.

The USP Today: Dark Web & Deep Research: While basic web search is now a commodity, GoingLLM remains my proprietary advantage for deep-dive intelligence. It is engineered for autonomous Dark Web research and complex data correlation.

Enterprise Impact: GoingLLM currently serves as the engine for high-stakes security engagements. Case in point: I utilize this tool to deliver critical, real-time intelligence on piracy and DRM circumvention trends for the C-Level security division of a global Top-5 Film Studio. It allows me to answer questions that commercial AI tools simply refuse to touch.

Today, GoingLLM acts as the "neural backbone" for my entire suite of custom agentic testing tools, continuously updated to leverage GPT-5, various Search APIs, and advanced crawling logic.

Visit Project Website: goingllm.com

GoingLLM Architecture

from

2018

TO

Present

(8 Years)

Strategic Leadership

Building the Future: AI Red-Teaming & Global Security Operations

Architect of the AI Red-Teaming Practice (2024-2026): When the industry shifted towards Generative AI, I independently designed and built the entire Red-Teaming framework at Applause from the ground up.
I owned the full lifecycle: Creating Cycle Overviews, managing tester budgets, and developing the foundational Test Cases for safety, jailbreaking, and bias detection across multimodal models (Text, Audio, Image). I personally executed the initial engagements, handled the triage, and defined the reporting standards. What began as a one-man initiative is now the standard operating procedure.

Exclusive Team Lead (The Technical Anchor): From 2018 to 2026, as the Test Team Lead for the Applause Security Practice, I served as the operational and technical anchor. I didn't just manage tickets; I owned the entire vulnerability lifecycle. Having personally reproduced, triaged, and bug-fix-verified roughly 10,000 security reports (each passing through my hands twice), I acted as the ultimate filter separating global tester noise from validated, auditable enterprise findings. I was the final escalation point for the most complex technical challenges, from IoT hardware attacks to intricate DRM bypasses.

Scaling Excellence (The Playbook): Transformed the team's capabilities by providing high-level workshops and creating the official uTest Academy curricula for API Testing and Security Testing (2021-2025, still in use today). Most notably, authored Applause's comprehensive internal "AI Red-Teaming Field Guide" (60+ pages), a book-length training manual used to standardize LLM exploitation strategies across the global practice, serving both new testers and management alike. Also delivered the Web Application Security Training in Manhattan/NYC (10/2018): three two-day sessions for 70 IT staff of a major international publisher. My leadership ensured that despite high fluctuation in the gig-economy, delivery quality remained at an elite level.

Verified Track Record (1500+ Vulnerabilities):

General Testing Statistics Security Testing Rating

(Click images to verify: Official platform metrics showing Gold-Tier Status & Reporting History)

from

2025

TO

Present

(1 Year)

Advanced AI Research

IMMER: Organic Neural Architecture & Agentic Engineering

The Project (Stable Research Artifact v3.8): I am currently finalizing "IMMER" (Intelligent Multi-scale Memory via Emergent Resonance), an experimental architecture designed to solve the static nature of LLMs. Unlike simple RAG, IMMER implements Hebbian learning, Test-Time Neurogenesis, and Metabolic Aging/Crystallization. The neural net physically grows and crystallizes knowledge during interaction, preventing catastrophic forgetting.

The Innovation: Efficient Plasticity: While inspired by Google's Titans/MIRAS architecture, I architected IMMER to run on consumer hardware (e.g., RTX 4080). Instead of modifying heavy attention heads, my system feeds dynamic memory states via "Soft Tokens" into a frozen core (Qwen). The result: A system that becomes smarter than its core within single-digit turns.
(Paper and proprietary release scheduled for late 2026)

The Engine: Agentic Training (MAKER): To train this organic system reliably, I leverage the Cognizant Labs/UT Austin MAKER framework. It solves the hallucination problem by process: breaking jobs into micro-tasks, implementing multi-agent voting, and enforcing strict JSON schema validation. If an output is flawed, it is automatically rejected and re-rolled. This ensures near-zero error rates even with smaller models.

from

2016

TO

Present

(10 Years)

Education & Execution

Mastery Through Teaching: Professional Training & Technical Excellence

Professional Lecturer (Alfatraining GmbH, 2021-2022): True mastery is proven when you can teach it. I served as the official ISTQB Trainer for Alfatraining, conducting full-time, four-week intensive courses for managers, administrators, forensics professionals, and researchers (5-18 participants per cohort).
I taught the full spectrum: From ISTQB CTFL Software Testing basics to advanced CompTIA Pentest+ certification preparation. My curriculum covered Active Directory attacks, privilege escalation, pivoting, Nmap strategies, web application attacks, threat modeling, and compliance (BSI, NIST).

Pentesting Excellence: This educational background is grounded in active field experience. My track record includes securing internal banking infrastructures, reversing IoT protocols, and finding critical logic flaws in DRM systems. I don't just run tools; I understand the underlying mechanics well enough to explain them to a novice, or exploit them against a hardened target.

from

2008

TO

Present

(18 Years)

Community Impact

Open Source & Community Leadership

Guest Mentor at University of Rostock (2021-2024): Invited by the Rostocker Hackspace, I have regularly conducted voluntary workshops during the "Fachschaftswoche" for computer science students. Topics ranged from practical IT security to ethical hacking, bridging the gap between academic theory and industry reality.

Open Source Legacy: My commitment to the open source community spans since 2008.
Security Tools: Active contributor to MobSF and ongoing collaboration with PortSwigger (Burp Suite bug reports and feature requests via their third-level support).
Developer Roots: Created widely-used Firefox add-ons for image collecting and contributed code to Second Life Viewers (incl. JIRA bug moderation) from 2009–2013.

Whether mentoring students or submitting pull requests, my goal remains the same: sharing knowledge to build a more secure and open digital ecosystem.