About XinYiAn

From the attacker’s view — reproducible, defensible security capability. From passive defense to active adversarial readiness — the team has shipped sustained delivery across national HVV drills and critical infrastructure.

2023—2026
National / provincial HVV drill support
7
International & domestic certifications
5tracks
Network · Data · AI · Advisory · Training
Core
Red team · Pentest · Weaponization · IR
01Company

Company overview

Built around hands-on offensive work, R&D, security operations and talent development — delivering professional, reliable, and compliant security assurance for government, defense, research, finance, energy, and critical infrastructure.

Mission

「Trust as foundation, value as bridge, security as shield.」

From the attacker’s view, deliver security services and training externally; sustain research, tooling and vulnerability follow-through internally. Drive security from passive defense to active adversarial readiness.

Offensive security & assessment
Red/blue exercises (authorized) · Drill support · Web / system / app pentest · Internal & AD assessment · Code audit · Architecture review & hardening
R&D & tooling
Custom security tool R&D · Adversary emulation & capability building · Custom C2 development · CTF ranges & competition platforms
Security ops & IR
Incident response & forensics · Threat intelligence · Security posture assessment · Defense optimization · MLPS & compliance
Training & talent
Hands-on offensive training · University partnership · Sector-specific cohorts · Specialized technical courses · High-end training support
02Core Team

Core team

Members from the front line of offensive security, holding international top-tier certifications and bringing rich hands-on and teaching experience.

Tian Xingjian

Co-founder / Red Team Lead

Ten-plus years in offensive security. Has been a core red-team member in national-level HVV drill campaigns, leading dozens of APT simulation assessments and red-team engagements. Specializes in C2 infrastructure, AV-evasion weaponization, internal lateral movement, AD pivoting, and incident response.

APT SimulationC2 InfraWeaponizationAD PentestIR

Guan Zhouyu

Co-founder / Pentest Lead

Deep experience in pentest and offensive/defensive engagements — solid technical grounding in Web / internal / cloud attack paths, AV evasion, and social engineering. Frequent lead in large enterprise drills and security assessments; specialized in complex exploit chains and lateral movement. Also a senior trainer with strong field-to-curriculum translation.

Web PentestSocial EngineeringLateral MovementTraining

Xie Yile

Security Researcher / Weaponization

Focused on AV-evasion research and offensive tooling. Continuous original research and tooling output in red-team weaponization, EDR / AV countermeasure, and OSINT automation. Has supported national and enterprise-level drills as a tooling developer and technical lead. As a security trainer, deep practice in AV evasion and automated offensive techniques.

AV EvasionExploit DevOSINTTooling
03Certifications

Team certifications

Cumulative certifications held across the team — verifiable offensive capability.

OSCE3 OffSec Certified Expert 3
OSWE OffSec Web Expert
OSEP OffSec Experienced Pentester
OSED OffSec Exploit Developer
OSCP OffSec Certified Professional
CISSP Certified Information Systems Security Professional
CISP-PTE Certified Information Security Professional - Penetration Testing Engineer
CISP Certified Information Security Professional
04Field Experience

Project experience & field capability

Continuous support from national HVV drills to finance, energy, academia, and critical infrastructure — grouped by 4 service categories.

A

Adversary Drills · HVV

National, provincial and industry-level HVV support — multi-year record of zero losses.

  • China Development Bank National-level offensive drill (attacker side)
  • State Grid Sichuan Offensive drill (defender / forensics)
  • China Telecom Hainan Provincial drill (attacker side)
  • Datang Power (Changshan) Drill exercise (defender · 0 points lost)
  • Jiangsu Lian’an Life Provincial HVV (defender · 0 points lost)
  • People’s Insurance Co. of China Red team internal assessment (attacker)
  • National / provincial HVV Red team & blue team support (ongoing)
B

Penetration Testing

Deep manual penetration testing across Web / internal / cloud / applications — business logic and privilege-escalation coverage.

  • Jiangsu Wuxi Agricultural Bank Manual pentest · 13 vulnerabilities
  • University of Macau Campus & application pentest · 15 vulns
  • Liuzhou Wuling Automotive Enterprise pentest · 6 vulnerabilities
  • Southeast University Campus pentest · 4 vulnerabilities
C

Security R&D

Custom platforms and tooling for adversary drills, weaponization research and university research programs.

  • Navy embedded satellite system Device security test (classified)
  • Defense C2 platform Custom C2 platform R&D
  • Wuhan University Cybersecurity digital-human R&D
D

Security Training

Customized training for defense, government and university clients — with platform and competition support.

  • European MoD Offensive training (overseas)
  • Wuchang Polytechnic CTF & training support
05Sectors Served

Sectors & clients

Years of sustained delivery for government, defense, research, finance, energy, and critical infrastructure.

Public Sector
Government · regulators
Defense
Defense & classified projects
Research
Research institutes · universities
Critical Infra
Finance · Energy · Transport · Telecom
Got a brief? Red team, pentest, HVV support, security training — tell us the goal, we’ll come back with a plan.
Contact us