Senior cybersecurity & AI advisor
CGI · Montréal
Offensive security, Active Directory hardening, Python automation and applied AI in regulated environments.
Raphael Benoit
Senior advisor · Cybersecurity, AI & automation
Trained in software engineering in Montréal, I develop end-to-end products and tools across applied AI, Python automation, full-stack software and offensive security.
Achievements
Worldwide on HackTheBox in 2023, a cyber training platform with over 4M members.
CTF team#1ADMinions in the worldwide HackTheBox team ranking in 2024, 2025 and 2026.
Cybersecurity CTF11thCyber Apocalypse 2025, an international HackTheBox competition — 8,130 teams.
Cybersecurity CTF17thCyber Apocalypse 2024, an international HackTheBox competition — 5,693 teams.
CGI Innovation 2025 — Greater Montréal BU ranking.
CGI Innovation 2025 — solution’s global ranking.
StayInTheBoxCorp, a reverse-engineering GamePwn challenge published on HackTheBox.
Publication reach~100kReads in one week for my reverse-engineering and Windows kernel research.
Publications
From long-form articles to practical ADMinions books, my publications connect reverse engineering, Windows internals, Active Directory and offensive security.
Experience
Analysis, design, development, technical evidence and remediation guidance: I take ownership of the complete cycle.
CGI · Montréal
Offensive security, Active Directory hardening, Python automation and applied AI in regulated environments.
CGI · Montréal
IBM i/AS400 exfiltration-risk analysis, CyberArk/Power BI automation, SAST auto-remediation and penetration-test reporting tools.
Letico · Saint-Laurent
Led Python, industrial automation, IT integration and internal security projects from requirements through maintenance.
Selected projects · 01
Computer vision, full-stack products, local LLMs, automation and demonstrable industrial systems.

Data preparation, assisted annotation, reproducible versions and visual review.
Case studyBoxes, polygons and segmentation under occlusion in an anonymized demonstration.

Full-stack product: async Quart, OAuth, Stripe, AWS and a published extension.
Case study
Server designed and assembled for LLMs, RAG, fine-tuning, vision and cybersecurity workloads.
View projectFile ingestion, contextual search and fully local operation.
Conversation and form inputs into a structured, reviewable report.
Search and synthesis in a specialized document collection.
Answers grounded in selected sources within a Web interface.
Timestamps and speaker separation in a complete workflow.

Sensors, SAP/ERP, CIP/Modbus, real-time events and anomaly detection.
Selected projects · 02
Offensive tools, reverse engineering, Windows kernel work and DevSecOps automation, with public studies and demonstrations.
Orchestration with memory, tools, scope enforcement, evidence and human validation.
Case study
Compact binary exports, configurable LLM analysis and preserved provenance.
Case study
Memory analysis, hooking, Windows drivers, WinDbg, page tables and detection surfaces.
Case study
SAST auto-remediation, assisted fixes and automated penetration-test reporting.
View public toolsSelected demonstrations
A selection of the most representative demonstrations. Explore the 11-video catalog →
GitHub
Eight representative original projects. Forks and small utilities are not featured.
GitHub profileDesktop workspace for visual data, YOLO annotations and reproducible datasets.
Compact Ghidra exports and defensive analysis with multiple LLM backends.
Cybersecurity instruction datasets for LLM training and evaluation.
Backup-first recovery for Codex Desktop local state and SQLite metadata.
Windows x64 target for pointer chains and memory primitives.
Companion code for the external/internal memory analysis and hooking articles.
Lab tool for testing authorized KeePass v4 databases.
RID/SID enumeration of MSSQL users and groups in authorized environments.
Contact & profiles
LinkedIn summarizes the professional path; GitHub, HackTheBox and YouTube provide the projects, rankings and technical demonstrations.