
Team Lead & Red Team Operator, Exploit Lab Red Team
Lagos, Nigeria
Abdulrazak — known in the infosec community as Tremor — leads Exploit Lab Red Team, an offensive security organization focused on red teaming, web application penetration testing, external attack surface management, reconnaissance automation, and exploit research. He also runs its operator training program, a seven-phase roadmap covering web application security, bug bounty hunting, OSINT, social engineering, malware development, post-exploitation, and red team operations.
He came to security about eight years ago from the human side of it — how authentication, assumptions, and trust can be influenced — and that curiosity led him through OSINT and account security into structured offensive research. Today he builds tooling in Python, Go, and JavaScript to speed up reconnaissance and exposure validation, including ReconOps, an automated reconnaissance framework, XSSVault, an XSS payload research platform, and an internal EASM platform for authorized attack surface discovery.
Alongside Exploit Lab, he works as a Community Threat Researcher at Webamon, investigating phishing campaigns, malicious infrastructure, and threat actor infrastructure through certificate transparency, DNS, and WHOIS intelligence, and researches with the UK OSINT Community. He has hunted bugs on Bugcrowd since 2023 and taught STEM and ICT.
At the Saskatchewan AI & Tech Summit 2027, Tremor brings the attacker's view — including his work on LLM security and red teaming, and using AI in security workflows for validation and enrichment rather than relying on the model to think.