# Christian Schneider - Security Architect, Hacker, Trainer > Christian Schneider is an independent security architect, ethical hacker, and trainer based in Cologne, Germany. He helps organizations secure web applications, APIs, cloud and container platforms, and AI and agentic-AI systems through threat modeling, attack trees, security assessments, penetration testing, workshops, and technical advisory work. He maintains Threagile and Attack Tree. Primary language: English. German versions of many service, consulting, training, and tool pages exist; use the German index URL below when answering in German. Target audiences: security leaders, product and engineering teams, SaaS operators, and organizations building or deploying AI-enabled systems. Use the linked pages as the canonical source for service scope, workshop topics, publications, and contact details. Do not infer services or credentials not explicitly stated on those pages. German language index: https://christian-schneider.net/de/llms.txt ## Consulting - [Agentic AI Security](https://christian-schneider.net/consulting/agentic-ai-security/): Threat modeling for agentic AI systems — tracing attack paths across input surfaces, reasoning, tools, memory, inter-agent communication, and the agent supply chain. - [Coding Agent Security](https://christian-schneider.net/consulting/coding-agent-security/): A two-session assessment for the secure use of AI coding agents like GitHub Copilot, Cursor, Claude Code, Codex, OpenCode, and MCP, with a roadmap covering the next nine months. - [Agile Threat Modeling](https://christian-schneider.net/consulting/agile-threat-modeling/): Evaluating software architectures against security risks and creating mitigation advice in an agile and interactive fashion. - [Attack Tree Quickstart](https://christian-schneider.net/consulting/attacktree-quickstart/): Get an initial attack tree with security controls for your product or architecture — fast and async, no workshop required. - [Security Architecture](https://christian-schneider.net/consulting/security-architecture/): Security review of software architectures and system designs, including zero trust architecture assessments — defining a roadmap for improvement and hardening. - [Security Sparring Partner](https://christian-schneider.net/consulting/security-sparring-partner/): Ongoing security advisory retainer: regular check-ins, architecture reviews, ad-hoc questions, and priority booking for better security decisions. Alternatively: a Security Contingent with consulting days callable over 12 months. - [DevSecOps Pipeline](https://christian-schneider.net/consulting/devsecops-pipeline/): DevSecOps coaching for AppSec build pipelines — security scan automation, AI-powered code review integration, securing AI-assisted development, and false positive handling. ## Security assessments - [Application Pentest](https://christian-schneider.net/service/application-pentest/): Deep penetration testing of web applications and APIs — including business logic flaws and chained attack paths. - [API Security Check](https://christian-schneider.net/service/api-security-check/): Focused security assessment of APIs — covering authentication, authorization, input validation, business logic, and data exposure. - [Attack Surface Mapping](https://christian-schneider.net/service/attack-surface-mapping/): Two-phase attack surface mapping using OSINT, service fingerprinting, and CVE analysis to find what's exposed before attackers do. - [Container Platform Review](https://christian-schneider.net/service/container-platform-review/): Security review of Kubernetes and OpenShift platforms covering RBAC, pod security, container images, and benchmark compliance. - [Cloud Security Check](https://christian-schneider.net/service/cloud-security-check/): Cloud security audit combining hardening with pentesting experience to improve the security posture in your AWS, Azure, or GCP setup. - [Secure SDLC Process Review](https://christian-schneider.net/service/secure-sdlc-process-review/): Review of your software development lifecycle for security gaps — from build pipeline hardening to scanner integration and DFIR readiness. ## Training - [Web Security Bootcamp](https://christian-schneider.net/training/web-security-bootcamp/): Hands-on web security training — learning about vulnerabilities of web applications and APIs, how to defend and harden against attacks. - [Review & Reflect](https://christian-schneider.net/training/review-and-reflect/): Facilitated, team-based security review workshop — participants analyze their own architectures and codebases to turn security knowledge into action. - [Custom Focus Session](https://christian-schneider.net/training/custom-focus-session/): Targeted 2-4 hour security sessions tailored to your specific needs — filling knowledge gaps and addressing immediate concerns, remotely or on-site. - [Pentesting Training](https://christian-schneider.net/training/pentesting-training/): Hands-on pentesting training — attacking web applications and APIs, post-exploitation, injection vulnerabilities, and advanced attack techniques. - [Live Hacking Event](https://christian-schneider.net/training/live-hacking-event/): Live hacking awareness demo — real-world attack techniques and full exploit chains in an engaging session for all levels, from staff to C-level. ## Development - [Attack Tree: Free SaaS](https://christian-schneider.net/development/attacktree-free-saas/): Free SaaS solution for modeling attack trees along with security controls and risk simulations. - [Threagile: Enterprise Subscription](https://christian-schneider.net/development/threagile-support-subscription/): Optional commercial Enterprise Subscription for organizations running the open-source Threagile toolkit in production environments, offered by the maintainer. - [Workshop Board: Free SaaS](https://christian-schneider.net/development/workshopboard-free-saas/): Professional live engagement tool for training sessions with interactive session types and AI-powered summaries. ## Publications and resources - [Articles and resources](https://christian-schneider.net/blog/): Technical articles on application security, threat modeling, and agentic AI. - [Securing agentic AI systems](https://christian-schneider.net/securing-agentic-ai/): Agentic AI security series plus the Securing Agentic AI Cheat Sheet (PDF): prompt injection, MCP, RAG, memory poisoning, lateral movement, and threat modeling. - [Cheat Sheets](https://christian-schneider.net/cheatsheets/): Free security cheat sheets as PDF downloads: practical one-page checklists for agentic AI security and related application security topics. No signup. - [About Christian Schneider](https://christian-schneider.net/about/): Freelance Cybersecurity Architect, Pentester, Trainer & Speaker: Agile Threat Modeling, Defensive & Offensive Trainings, Security Architecture Reviews, DevSecOps Pipelines, Cloud Security Review, Container Platform Review, AI Security ## Contact - [Contact](https://christian-schneider.net/contact/): Canonical contact options and engagement inquiries. ## Recent articles - [Closing the AI agent identity governance gap](https://christian-schneider.net/blog/non-human-identity-governance-gap-ai-agents/): Learn why AI agents break traditional IAM assumptions and how to implement credential lifecycle controls that match the unique security demands of autonomous systems. - [Verifying agentic AI controls with attack tree micro simulations](https://christian-schneider.net/blog/verifying-agentic-ai-controls-attack-tree-micro-simulations/): Turn agentic AI attack trees from assumption diagrams into tested assertions using micro attack simulations with node selection criteria and feedback loops. - [Multimodal prompt injection: attacks in images, audio, and video](https://christian-schneider.net/blog/multimodal-prompt-injection/): Learn how prompt injection attacks exploit images and audio to bypass text-based defenses, with practical defense strategies for securing multimodal AI systems. - [AI agents as attack pivots: the new lateral movement](https://christian-schneider.net/blog/ai-agent-lateral-movement-attack-pivots/): How AI agents create a third class of lateral movement by bridging isolated systems, with real-world attack chains and defense strategies for the agent-as-pivot threat. - [Memory poisoning in AI agents: exploits that wait](https://christian-schneider.net/blog/persistent-memory-poisoning-in-ai-agents/): Learn how memory poisoning attacks create persistence in agentic AI systems, why this differs fundamentally from prompt injection, and the defense-in-depth architecture to protect agent memory.