
2nd Runner-up
Thailand Banking AI Red Team Challenge 2026
Thailand Banking Sector CERT (TB-CERT)

Security Research Engineer
Red Teaming • AI Security • Identity & AppSec
I am a Security Research Engineer with an offensive security background, working across vulnerability research, red teaming, AI security, identity security, application security, and security tooling. My professional experience spans enterprise banking security and cybersecurity consulting, conducting end-to-end security assessments across Web, API, Mobile, Network, and Identity environments, alongside red team operations focused on real-world attack scenarios, security-control bypasses, and adversary simulation.
I am particularly interested in research at the intersection of Security, AI, and Systems, including Identity & Access Security, AI/LLM and Agent Security, Mobile/iOS Security, vulnerability discovery, and increasingly low-level software and systems security. I also remain interested in applied AI research beyond security, particularly in computer vision, biometrics, medical AI, and AI systems. My long-term direction is to deepen into vulnerability research, AI systems security, reverse engineering, fuzzing, OS/kernel internals, and security-focused systems engineering.
Beyond security testing, I enjoy turning research into practical outputs: PoCs, tools, open-source projects, CVEs, academic publications, and conference presentations. My background in applied AI/ML research includes computer vision and deep learning systems. I am the creator of Oblivion Token (presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs), an upcoming speaker ats Black Hat India 2026 Briefings and Red x Blue Pill 2026, credited on 32 CVEs, and author of 3 IEEE publications spanning Android OAuth 2.0 security testing and applied AI/ML systems.
Open to global opportunities in Security Research, Offensive Security, AI Security, Vulnerability Research, and graduate research pathways.


Key Responsibilities & Achievements


Key Responsibilities & Achievements


Key Responsibilities & Achievements
This briefing presents a systematic methodology for evaluating Microsoft 365 Conditional Access enforcement across applications and explores how cross-application trust relationships can create unintended privilege amplification.
Waris Damkham and Nuttakorn Tungpoonsup present a systematic methodology for mapping Microsoft 365 Conditional Access enforcement across users, resources, client applications, authentication flows, and Microsoft first-party app behavior.
Presented for DEF CON Singapore 2026 Demo Labs. Oblivion Token is an offensive research utility for practical, repeatable testing of Microsoft 365 Conditional Access (CA) edge cases. It systematizes token-centric workflows to help identify where device, network, or app-context assumptions can fail in real-world environments.
TENCON 2024
2024IEEE Region 10 Conference 2024
QRS 2023
202323rd IEEE International Conference on Software Quality, Reliability, and Security
InCIT 2022
20226th International Conference on Information Technology

2nd Runner-up
Thailand Banking Sector CERT (TB-CERT)

Rising Award
KASIKORN Business-Technology Group (KBTG)
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
The TableOn plugin for WordPress is vulnerable to blind SQL Injection via the 'comment_count' filter parameter in all versions up to, and including, 1.0.5.1 due to insufficient escaping on user-supplied input and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to extract sensitive information from the database.



Hack The Box
View CredentialRed Team Leaders
View Credential8kSec
View CredentialHands-on assessment, adversary simulation, exploitation, and vulnerability validation.
Penetration Testing · Red Teaming · Web Exploitation · Network Exploitation · Privilege Escalation · Burp Suite · Kali Linux
Security review and testing across web, API, mobile, OAuth, and Android attack surfaces.
Application Security · API Security · Mobile Security · Android Security · OAuth 2.0 · OIDC · OWASP Top 10
Identity-centered cloud security research, policy testing, and Microsoft 365 attack paths.
Microsoft Entra ID · Microsoft 365 · Conditional Access · Microsoft Graph API · Azure · AWS · Cloud Security
AI security readiness, LLM threat modeling, and applied machine-learning research experience.
AI Security · LLM Security · AI Red Teaming · Prompt Injection · MCP Security · OWASP LLM Top 10 · TensorFlow
Automation and engineering used to scale testing, reporting, triage, and repeatable workflows.
Python · JavaScript · Bash · Power Automate · Power Apps · GitHub Actions · Selenium
Turning technical findings into clear executive, engineering, academic, and public-facing output.
Executive Reporting · Technical Reporting · Vulnerability Triage · CVE Research · Risk Communication · Security Briefing · Public Speaking

Senior project / thesis focused on classifying chicken diseases from fecal images through a LINE Official Account.
Joined the exhibition showcasing B.Sc. ICT International Program student internships. Proudly shared my experience from Ritsumeikan University among esteemed peers. An enriching platform for insights and networking.

University application portfolio and supporting academic showcase.
waris_m@portfolio:~$ ls -lh latest-resume.pdf
Waris_Resume_2026.pdf
Preview the document here or download the original PDF.
waris_m@portfolio:~$ whoami
Waris Damkham
Security Research Engineer
# CONTACT
# PROFILES
waris_m@portfolio:~$