
2nd Runner-up
Thailand Banking AI Red Team Challenge 2026
Thailand Banking Sector CERT (TB-CERT)

Security Research Engineer
Red Teaming • AI Security • Identity & AppSec
I am a Security Research Engineer with an offensive security background across vulnerability research, red teaming, AI security, identity security, application security, and security tooling. My experience spans enterprise banking security and cybersecurity consulting, including end-to-end assessments across Web, API, Mobile, Network, and Identity environments, as well as red team operations focused on real-world attack scenarios, security-control bypasses, and adversary simulation.
My research interests sit at the intersection of Security, AI, and Systems, particularly AI Systems & Agent Security, Identity & Authorization, Mobile/OS Security, Vulnerability Research, and Systems Security. I also remain interested in applied AI research, especially computer vision and deep learning systems. My long-term direction is to deepen into AI systems security, identity and authorization, reverse engineering, fuzzing, mobile/OS internals, and security-focused systems engineering.
I enjoy turning research into practical outputs: PoCs, tools, open-source projects, CVEs, academic publications, and conference talks. My applied AI/ML background includes computer vision and deep learning systems. I am the creator of Oblivion Token, presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs, a speaker at Red x Blue Pill 2026, and an upcoming speaker at Black Hat India 2026 Briefings. I have also presented academic research at IEEE QRS 2023 and IEEE InCIT 2022, and I am credited on 33 CVEs with 3 IEEE publications spanning Android OAuth 2.0 security and applied AI/ML systems.
Open to research collaborations, speaking opportunities, and graduate research pathways.


Key Responsibilities & Achievements


Key Responsibilities & Achievements


Key Responsibilities & Achievements
This briefing presents a systematic methodology for evaluating Microsoft 365 Conditional Access enforcement across applications and explores how cross-application trust relationships can create unintended privilege amplification.
Waris Damkham and Nuttakorn Tungpoonsup present a systematic methodology for mapping Microsoft 365 Conditional Access enforcement across users, resources, client applications, authentication flows, and Microsoft first-party app behavior.
Presented for DEF CON Singapore 2026 Demo Labs. Oblivion Token is an offensive research utility for practical, repeatable testing of Microsoft 365 Conditional Access (CA) edge cases. It systematizes token-centric workflows to help identify where device, network, or app-context assumptions can fail in real-world environments.
TENCON 2024
2024IEEE Region 10 Conference 2024
QRS 2023
202323rd IEEE International Conference on Software Quality, Reliability, and Security
InCIT 2022
20226th International Conference on Information Technology

2nd Runner-up
Thailand Banking Sector CERT (TB-CERT)

Rising Award
KASIKORN Business-Technology Group (KBTG)
An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations.
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.



Al Governance Week 2026
View CredentialAl Governance Week 2026
View CredentialHack The Box
View CredentialRed Team Leaders
View CredentialHands-on assessment, adversary simulation, exploitation, and vulnerability validation.
Penetration Testing · Red Teaming · Web Exploitation · Network Exploitation · Privilege Escalation · Burp Suite · Kali Linux
Security review and testing across web, API, mobile, OAuth, and Android attack surfaces.
Application Security · API Security · Mobile Security · Android Security · OAuth 2.0 · OIDC · OWASP Top 10
Identity-centered cloud security research, policy testing, and Microsoft 365 attack paths.
Microsoft Entra ID · Microsoft 365 · Conditional Access · Microsoft Graph API · Azure · AWS · Cloud Security
AI security readiness, LLM threat modeling, and applied machine-learning research experience.
AI Security · LLM Security · AI Red Teaming · Prompt Injection · MCP Security · OWASP LLM Top 10 · TensorFlow
Automation and engineering used to scale testing, reporting, triage, and repeatable workflows.
Python · JavaScript · Bash · Power Automate · Power Apps · GitHub Actions · Selenium
Turning technical findings into clear executive, engineering, academic, and public-facing output.
Executive Reporting · Technical Reporting · Vulnerability Triage · CVE Research · Risk Communication · Security Briefing · Public Speaking

Senior project / thesis focused on classifying chicken diseases from fecal images through a LINE Official Account.
Joined the exhibition showcasing B.Sc. ICT International Program student internships. Proudly shared my experience from Ritsumeikan University among esteemed peers. An enriching platform for insights and networking.

University application portfolio and supporting academic showcase.
waris_m@portfolio:~$ ls -lh latest-resume.pdf
Waris_Resume_2026.pdf
Preview the document here or download the original PDF.
waris_m@portfolio:~$ whoami
Waris Damkham
Security Research Engineer
# CONTACT
# PROFILES
waris_m@portfolio:~$