Waris Damkham

Offensive Security Engineer | eWPTX | PNPT | PMPA | CPTS | CBBH | BSCP | CRTP | GHF | C-APIPen | CCPenX-AWS | C-AI/MLPen | CMPen-Android & iOS | CAPenX | CNPen | CAPen | CAP | CRTA | CRT-ID | MCRTA


Take a moment to explore my skills, experiences, and projects below.

Resume

About Me

I am an Offensive Security Engineer, Penetration Tester, and AI Security Researcher with a strong passion for Linux 馃惂, Cybersecurity 馃敀, AI 馃, and DevOps 鈿欙笍. My expertise spans Offensive Security, AI-driven threat research, Web security, and Mobile security, with hands-on experience in penetration testing and security assessments. I have led significant research projects, including the development of an Automated COVID-19 Screening Framework Using Deep CNN With Chest X-Ray Medical Images, research on Detecting Vulnerable OAuth 2.0 Implementations in Android Applications, and the creation of Practical Mobile-Based Services for Identification of Chicken Diseases From Fecal Images. These projects have been presented at conferences and featured in publications. I am actively seeking full-time opportunities where I can continue to grow, gain valuable industry insights, and contribute innovatively to a collaborative security research environment.

TryHackMeHackTheBoxCredential.NetMedium
Web Application Penetration Tester eXtreme
Practical Network Penetration Tester
Practical Mobile Pentest Associate
Hack The Box Certified Penetration Testing Specialist
Hack The Box Certified Bug Bounty Hunter
Burp Suite Certified Practitioner
Certified Red Team Professional
GitHub Foundations
Certified API Pentester (C-APIPen)
Certified Cloud Pentesting eXpert - AWS (CCPenX-AWS)
Certified AI/ML Pentester (C-AI/MLPen)
Certified Mobile Pentester (CMPen-IOS)
Certified Mobile Pentester (CMPen-Android)
Certified AppSec Pentesting eXpert (CAPenX)
Certified Network Pentester (CNPen)
Certified AppSec Pentester (CAPen)
Certified AppSec Practitioner (CAP)
Certified Red Team Analyst
Certified Red Team Infra Developer
Multi-Cloud Red Team Analyst
Postman API Fundamentals Student Expert
GitOps Fundamentals
Cyber Threat Intelligence 101
Google IT Support Certificate
Meta Full-Stack Engineer Certificate
Open Source Software Development, Linux and Git Specialization
Google Cybersecurity Certificate
AWS Academy Graduate - AWS Academy Cloud Foundations

Skills & Tools

Programming Languages
Web Development
Backend, Frameworks & Testing
Data Management & Search Engines
Cloud & Container Platforms
DevOps & CI/CD Tools
Penetration Testing & Vulnerability Assessment
Machine & Deep Learning
Productivity & Collaboration

Experience

Internship Experience
Offensive Security Engineer
Kasikorn Business Technology Group 路 Full-time
Nov 2024 - Present
Bangkok, Thailand 馃嚬馃嚟 路 Hybrid

- TBA

Skills: Penetration test 路 Kali linux 路 Burp Suite 路 AI Security 路 Reporting 路 Power Automate

Internship Experience
Security Consultant (Penetration tester)
ALPHASEC 路 Full-time
Jun 2024 - Oct 2024 路 5 mos
Bangkok, Thailand 馃嚬馃嚟 路 Hybrid

As a Penetration Tester, I conduct in-depth security assessments of IT infrastructure, identifying vulnerabilities in operating systems, applications, configurations, and user behaviors. I specialize in security and vulnerability assessments for software, mobile, and web applications, adhering to OWASP guidelines. I provide actionable recommendations and detailed analysis to strengthen overall security posture. To date, I have successfully worked on 16 projects.

Skills: Penetration test 路 Kali linux 路 Burp Suite 路 OWSAP 路 Vulnerability Assessment

Internship Experience
Cybersecurity Consultant (Penetration tester)
KPMG 路 Advisory 路 Tech-Cyber 路 Internship
Jan 2024 - Apr 2024 路 4 mos
Bangkok, Thailand 馃嚬馃嚟 路 Hybrid

As a Penetration Tester intern at KPMG, I assisted in conducting security assessments for software, mobile, and web applications, utilizing Kali Linux, Burp Suite, and OWASP best practices to identify vulnerabilities and simulate cyber attacks. I contributed to developing a secure website for KPMG and performed vulnerability assessments using Nessus, focusing on KPMG鈥檚 internal network. During my time at KPMG, I successfully completed two penetration testing projects and one vulnerability assessment project, strengthening my technical expertise and ability to communicate complex security findings effectively. I remain committed to expanding my knowledge in this fast-evolving field.

Skills: Penetration test 路 Kali linux 路 Burp Suite 路 OWSAP 路 Cybersecurity 路 Vulnerability Assessment

Internship Experience
Detecting Vulnerable OAuth 2.0 Implementations in Android Applications
Ritsumeikan University 路 Internship
May 2023 - July 2023 路 3 mos
Shiga, Japan 馃嚡馃嚨 路 On-site

I conducted research on the security vulnerabilities in Android apps that use OAuth 2.0 with Google accounts, with a focus on the risks of cross-site request forgery (CSRF). My findings were presented at the Workshop on Cyber Forensics, Security, and E-discovery, during the 23rd IEEE International Conference on Software Quality, Reliability, and Security in 2023. By developing an app and analyzing others, I evaluated critical components such as the state parameter and authorization code, which are essential for CSRF prevention. The study reveals the level of protection against CSRF in implementations of OAuth 2.0 on Android. Our goal is to enhance user safety by identifying vulnerable apps and emphasizing the necessity for robust security measures. This research establishes a benchmark for future security audits of apps.

Skills: Android Development 路 OAuth2.0 路 Application Security 路 Security 路 Cybersecurity 路 Java

Internship Experience
Automated COVID-19 Screening Framework Using Deep CNN With Chest X-Ray Medical Images
National Central University 路 Internship
Jun 2022 - Jul 2022 路 2 mos
Taoyuan City, Taiwan 馃嚬馃嚰 路 Remote

I contributed to a project on automated COVID-19 diagnosis using chest X-rays, presented at the 2022 6th International Conference on Information Technology (InCIT). We proposed an AI-based screening method utilizing transfer learning and deep neural networks. Using Grad-CAM visualization, our convolutional neural network model showcased superior performance in accuracy, precision, recall, and F-measure on public datasets. This work advanced early COVID-19 detection and highlighted my skills in AI, deep learning, and medical imaging.

Skills: Public Speaking 路 Jupyter 路 Convolutional Neural Networks (CNN) 路 Deep Learning 路 Artificial Intelligence (AI) 路 Communication 路 Python

Education

HackTheBox Logo
Self-Learning on HackTheBox
Online Platform for Cybersecurity Training

Activities and societies:

Pro Hacker
HackTheBox Profile

TryHackMe Logo
Self-Learning on TryHackMe
Online Platform for Cybersecurity Training

Activities and societies:

waris.dam [0xA][WIZARD]
TryHackMe Profile

Mahidol University Logo
Bachelor of Science in Information and Communication Technology
Mahidol University, Thailand 馃嚬馃嚟
International Program
2020 - 2024

Activities and societies:

ICT Internship Poster Exhibition 2023 at ICT Mahidol
Sep 2023
Joined the exhibition showcasing B.Sc. ICT International Program student internships. Proudly shared my experience from Ritsumeikan University among esteemed peers. An enriching platform for insights and networking.

Bangkok Christian College Logo
Bangkok Christian College
Smart Computer 路 GPAX 3.48
2008 - 2020

Activities and societies:

Leader of Academic Computer & Careers of Bcc Showcase 2018
I served as the president of the Computer & Careers group during our school's academic day, 'The New Frontier' for the BCC Showcase. Our event featured a cooking competition named 'BCC FOOD FEST' and a 'TECHZONE' highlighting modern innovations, such as a futuristic house concept.

Projects

Publications

Practical Mobile Based Services for Identification of Chicken Diseases From Fecal Images

Accepted at IEEE Region 10 Conference 2024 (TENCON 2024)

Poultry farming is crucial to the food chain, and chicken health directly impacts product quality and safety. Diagnosing poultry diseases using polymerase chain reaction is costly, particularly for small farms. To address this, we developed a mobile-based service for farmers, enabling the identification of common chicken diseases from fecal images via a Line account. Our system achieved 86.49% segmentation precision and 95.93% classification accuracy on a large dataset, offering a practical and accessible tool for local farmers.

IEEE 路 Mar 5, 2024
Detecting Vulnerable OAuth 2.0 Implementations in Android Applications

Presented at the Workshop on Cyber Forensics, Security, and E-discovery, as part of the 23rd IEEE International Conference on Software Quality, Reliability, and Security, 2023.

OAuth 2.0, commonly used for authorization, can be susceptible to CSRF attacks in Android applications. To address this, we developed an Android app to assess other apps' use of the OAuth 2.0 state parameter鈥攁 key defense against CSRF. Our analysis, conducted on both Chrome and the default browser, evaluates whether Android apps using OAuth 2.0 are adequately protected against CSRF attacks. Our research aims to protect users by highlighting apps with potentially vulnerable OAuth 2.0 implementations.

IEEE 路 Feb 19, 2024
Automated COVID-19 Screening Framework Using Deep CNN With Chest X-Ray Medical Images

Presented at The 6th International Conference on Information Technology (InCIT2022)

An automated COVID-19 screening framework using chest X-ray images is proposed in this study. It leverages artificial intelligence techniques and transfer learning for accurate diagnosis. The framework extracts features using transfer learning and applies modified deep neural networks. Grad-CAM visualization supports the predicted diagnosis. Experimental results demonstrate superior performance compared to other deep learning techniques. This framework has the potential to aid in early COVID-19 diagnosis and alleviate the burden on radiologists.

IEEE 路 Mar 21, 2023

Certifications

Web Application Penetration Tester eXtreme
INE Security - Mar 2025
Show Credential
Practical Network Penetration Tester
TCM Security - Feb 2025
Show Credential
HTB Certified Penetration Testing Specialist
Hack The Box - Jan 2025
Show Credential
Certified API Pentester (C-APIPen)
The SecOps Group - Jan 2025
Show Credential

Competitions

Competition Certificate
UMassCTF 2024
April 2024

UMass CTF is back and better than ever this year! Get ready to dive into a thrilling array of challenges that will test your skills and push your limits. Participants can look forward to tackling intricate puzzles in Reverse Engineering, unlocking the mysteries of Cryptography, uncovering clues in Forensics, navigating the complex world of Binary Exploitation, and outsmarting defenses in Web Exploitation. Plus, we've got a host of miscellaneous challenges that are sure to surprise and engage. Don't miss out on the action-packed excitement at UMass CTF!

Skills: Cybersecurity, Web Exploitation, Forensics, Cryptography, Radio Steganography , Misc, Reverse Engineering, Pwn

Blog

Internship Experience
My Exam Review
Medium
Oct 2024

My Exams Review on Medium

Internship Experience
Cybersecurity journey Writeup
Writeup
Mar 2024

Welcome to my Cybersecurity journey! I'm Waris Damkham, a passionate Information and Communication Technology student. Dive into my writeup to explore the intricacies of cybersecurity through the lens of my hands-on experiences at HackTheBox etc.

Internship Experience
From Thailand to Japan: My Cybersecurity Internship at Ritsumeikan University
Cybersecurity Laboratory
Oct 2023

Hello everyone! My name is Waris Damkham, and I'm currently a fourth-year student in Information and Communication Technology at Mahidol University. I was fortunate to secure an internship at the Cybersecurity Laboratory in the Faculty of Information Science and Engineering at Ritsumeikan University.[...]

My Resume

warris-m~$cat Contact & Follow

I'm always open to discussions, collaborations, or just a chat. Feel free to reach out through any of the platforms below or drop me an email.

$phone: +66 63 954 4447
$location: Bangkok, Thailand 馃嚬馃嚟
TryHackMeHackTheBoxCredential.NetMedium