Group Purchasing
Group Purchasing

Joshua Wright

FellowDirector and Senior Security Analyst at CounterHack

Specialities

Offensive Operations, Digital Forensics and Incident Response

Connect with Joshua

Joshua Wright

About Joshua Wright

Joshua Wright is a SANS Faculty Fellow, Senior Technical Director at Counter Hack Innovations, and the author of SEC504: Hacker Tools, Techniques, and Incident Handling, one of the most widely taken courses in the SANS curriculum. Over more than two decades, he has trained thousands of professionals worldwide while contributing groundbreaking research, tools, and publications to the security community.

Joshua’s professional journey began when, after being caught hacking into his alma mater, Johnson & Wales University, he was subsequently hired to strengthen its systems. From there, he built his early career conducting penetration tests and vulnerability assessments that exposed critical weaknesses in enterprises and national infrastructure. As a Senior Security Analyst at InGuardians, he specialized in offensive operations and protocol exploitation. Today, at Counter Hack, he leads a team of cybersecurity consultants, specializing in penetration testing and red-team simulations, experiences that have shaped his teaching and research.

Joshua is the co-author of Hacking Exposed Wireless, Third Edition and the developer of widely used open-source tools. These include KillerBee, a toolkit for testing ZigBee wireless networks; KillerZee, designed for Z-Wave research; and several other tools. His research and technical contributions laid the foundation for SEC504, a course that set the standard for developing incident response skills and supporting students pursuing the GIAC Certified Incident Handler (GCIH) certification.

Joshua has been part of the SANS instructor community since 2003, shaping the curriculum for more than two decades and mentoring both students and instructors. He also serves as the Dean of Students at the SANS Technology Institute, an NSA Centers of Academic Excellence in Cyber Defense, a multi-year winner of the National Cyber League competition, and was named 2023 Instructor of the Year by his peers.

In the classroom, Joshua is recognized for his approachable teaching style and focus on practical, hands-on learning. Students describe his ability to break down complex concepts and build resilience through exercises that replicate real adversary behavior. Beyond his professional roles, Joshua supports the broader community by maintaining open-source projects, mentoring emerging professionals, and volunteering his time as a nonprofit photographer. His career embodies a steadfast belief that strong defenders are developed not only through technical skills but also through collaboration, creativity, and human connection.

Qualifications Summary
  • SANS Faculty Fellow and Senior Technical Director at Counter Hack Challenges
  • Dean of Students, SANS Technology Institute (an NSA Centers of Academic Excellence in Cyber Defense)
  • Member of the SANS instructor community since 2003, shaping curriculum and mentoring instructors for over two decades
  • Bachelor of Science in Information Science, Johnson & Wales University
  • Author, SEC504: Hacker Tools, Techniques, and Incident Handling
  • Co-author, Hacking Exposed Wireless, Third Edition
  • Developer of open-source tools including KillerBee, KillerZee, and many others
  • Trainer of thousands of students worldwide, designer of large-scale capture-the-flag and red-team challenges at Counter Hack
  • Active contributor to the security community through open-source development, mentoring, and nonprofit volunteer work.

Press & Media

More From Joshua

  • KillerBeeKillerBee is a framework, programming API, and suite of tools for testing the security of ZigBee wireless networks.
  • KillerZee KillerZee is a framework, programming API, and suite of tools for testing the security of Z-Wave wireless networks.
  • BitFitBitFit is a tool for guaranteeing an integrity check for distributed data files.
  • PPTXIndexPPTXIndex generates a Microsoft Word indexed document from PowerPoint PPTX files.
  • PlistSubtractorPlistSubtractor simplifies the process of assessing nested plist data.
  • PPTXSanityPPTXSanity evaluates all of the links in a PowerPoint file to check for dead links.
  • DynaPstalkerDynaPstalker assists when fuzzing a Windows process by color-coding reached blocks for use in IDA Pro.
  • PPTXUrlsPPTXUrls generates a HTML report of all links in one or more PowerPoint files.
  • NM2LPNM2LP converts NetMon wireless packet capture data to libpcap format.
  • MFSmartHackMFSmartHack is a suite of tools for hacking MIFARE DESFire and ULC high frequency RFID cards.
  • BTFindBTFind is a graphical and audio interface for tracking the location of Bluetooth and Bluetooth Low Energy devices.
  • CoWPAtty CoWPAtty is a WPA2-PSK password cracking tool.
  • PCAPHistogramPCAPHistogram assesses the payload of libpcap packet capture data, generating a histogram to characterize data entropy.
  • EAPMD5PassEAPMD5Pass is a password cracking tool for EAP-MD5 packet captures.
  • AsleapAleap is a Cisco LEAP and generic MS-CHAPv2 password cracking tool.
  • TIBTLE2Pcap TIBTLE2Pcap converts Bluetooth and Bluetooth Low Energy packet captures using the proprietary TI SmartRF format into libpcap-compatible files.
  • BluecryptBluecrypt is a simple implementation of the Bluetooth authentication cryptographic functions including E0, E21 and E22. Includes some wrapper functions to make Bluetooth authentication functions a little simpler.
  • evtxResourceIDGapsevtxResourceIDGaps is a script to evaluate Windows EVTX logging data to identify evidence of tampered loging data.