Roger Andras

Founder and CTO at AiTM Security

Washington DC-Baltimore Area, United States

About Roger Andras

Roger Andras is Founder and CTO at AiTM Security. Location: Washington DC-Baltimore Area, United States.

I've spent 24 years on the aftermath of the breach. I started in law enforcement, performing computer forensics for the Pennsylvania State Police. I built enterprise security programs for the Commonwealth of PA. Then 14 years at Guidance Software/OpenText as a federal team lead, where "pre-sales" barely describes it: hundreds of pilot implementations, thousands of hours training practitioners, and hands-on work in hundreds of federal and Fortune 500 compromise investigations — mostly APT intrusions. Root-cause analysis, disk/registry/memory indicator development, and enterprise-wide compromise scans across thousands of endpoints. Today I'm a senior cloud security engineer defending a Microsoft 365 enterprise — Defender, Sentinel, KQL, incident response, the full stack. Across every seat — investigator, architect, responder, defender — I've lived the same truth: by the time tooling reacts, the attacker is in, and everything after is cleanup. And in the cloud era, the attacker's real target isn't your password — it's the proof you already logged in. AiTM phishing kits proxy the real login page and capture the session live. Info-stealers lift session cookies, refresh tokens, and app credentials straight off the endpoint. Either way, MFA never gets a second chance — it was already satisfied. So I founded AiTM Security and built HijackShield — a security platform against adversary-in-the-middle credential theft in every form it takes. It starts in the browser: a layered detection engine with 300+ heuristics, structural and behavioral page analysis, and a hybrid design pairing cloud intelligence with a local ML model — blocking AiTM kits and never-before-seen phishing pages at render, with zero-touch remediation that purges the source email tenant-wide across Microsoft 365 in minutes. It now extends to the endpoint: ETW-based behavioral detection of credential and token theft — processes reading browser cookie stores, app token stores, and the credentials AI coding assistants leave on disk, an emerging target class most tooling isn't watching yet. Because "malware removed" is not "token not stolen," HijackShield treats a theft alert as the starting gun, not the finish line — watching sign-in activity for the stolen token's replay, and revoking it. Two decades of root-causing intrusions taught me exactly what to build to stop the theft — and catch the replay when something slips through. If you run security for a cloud-first business and you're tired of being the cleanup crew — let's talk. hijackshield.ai

Skills

  • Proof of Concept
  • SME Consulting

Additional experience

  • Senior Cloud Security Engineer

    Talking Rain Beverage Company

    Started January 2023

Education

  • Bachelor's degree, Commonwealth University-Bloomsburg