About · Practitioner-Led

Founded by a working penetration tester.

Forethreat is a focused, founder-led offensive security practice. Every engagement is delivered by a hands-on practitioner who lives in Burp Suite and on the command line — not handed to a junior behind a logo.

Belizaire Bassette II — Founder & Lead Penetration Tester

Belizaire is an offensive security practitioner and penetration tester who built his craft inside a Penetration Testing as a Service (PTaaS) consulting environment. Across five client engagements he identified 73 vulnerabilities — including high-impact findings such as IDOR/BOLA, stored and reflected XSS, arbitrary file upload, CSRF, and mass assignment — each documented with proof-of-concept exploits and business-impact-driven reporting. He was promoted from intern to Junior Penetration Tester on the strength of his findings and the quality of his client deliverables.

He founded Forethreat on a simple belief: most reports stop at what is broken. Clients deserve to understand how an attacker would actually chain those issues into a breach — and which risks genuinely threaten the business.

Credentials & focus
Offensive security, done by hand.
eJPT certified
  • Certifications: eJPT (INE). OSCP (Offensive Security) & BSCP (PortSwigger) in progress.
  • Education: B.S. Information Management & Technology, Syracuse University — Information Security concentration, Computer Science minor.
  • Specialties: Web app, Network, API, and Active Directory testing.
  • Toolset: Burp Suite, Nmap, Nessus, Hydra, Metasploit; Python & Bash.
  • Frameworks: OWASP Top 10, MITRE ATT&CK, NIST CSF.

Experience that translates to your risk

PTaaS consulting

Black-box and gray-box testing across multiple web engagements, with CVSS-rated, reproduction-ready reports written for both leadership and engineers.

Regulated-data experience

Prior IT risk & compliance work included HIPAA-aligned access-control and policy audits and secure handling of sensitive data (PHI) — confidentiality treated as a baseline, not a checkbox.

Defensive perspective

Enterprise network hardening (pfSense, DMZ redesign) and SOC-style alert triage — so remediation guidance is realistic, not theoretical.

“It's not about how many vulnerabilities exist — it's which ones actually put your business at risk.”