Offensive Operations
Penetration testing and red team operations across web applications, network infrastructure, and mobile apps — blackbox and graybox engagements for clients where downtime is not an option.
Personal Dossier — Security & Engineering
Security Consultant · Penetration Tester · Builder
I break into web applications, networks, and mobile apps — legally — and write the reports that help teams fix what matters. 2,500+ professional hours across financial, insurance, and medical clients.
When I'm not on an engagement, I build things: full-stack apps, game-jam games, and an LLM agent that runs my digital life around the clock.
I'm a security consultant specializing in offensive security. For the past years I've run penetration tests and red team operations against web applications, network infrastructure, and mobile applications — blackbox and graybox — for clients in finance, insurance, and healthcare.
Before going on the offensive, I built things: full-stack web apps with MERN and Java Spring Boot microservices at IBM, data visualisation tooling for neural-network research in Germany, and more game-jam games than I can count. That engineering background is why I can read your code, not just your responses.
I also publish vulnerability research — CVE-2025-51962, an HTML injection in MicroStudio — and speak at community events, most recently a deep dive into CVE-2025-55182 ("React2Shell") at 2600TH × OWASP Bangkok.
No meters, no made-up percentages — just the work, and the tools it runs on.
Penetration testing and red team operations across web applications, network infrastructure, and mobile apps — blackbox and graybox engagements for clients where downtime is not an option.
Deep assessment practice across the full web attack surface — a certified Burp Suite Professional — plus Android tooling for mobile engagements, from static analysis to runtime instrumentation.
Full-stack foundations from MERN to Java Spring Boot microservices built at IBM, plus LLM agent systems and workflow automation that run in production, around the clock, on my own infrastructure.
Published CVE researcher and conference speaker. Every engagement ends the way it should — a clear, professional technical report that your team can actually act on.
Penetration testing and red team operations for web applications, network infrastructure, and mobile applications across financial, insurance, and medical clients — each engagement closed with a professional technical report.
Built Java Spring Boot microservices for client applications, supporting backend teams on production-grade service development.
Visualised neural-network experiment data on GPU with Python (Flask) and D3.js / Plotly.js, and built the web GUI used to run and observe experiments. IAESTE Erlangen 2023.
Developed and maintained web applications with HTML/CSS/JavaScript, React, MongoDB, Node-RED, and the LINE Front-end Framework.
Three live pages from this site's own workshop — an agent, an institute, and a classroom.
An always-on LLM agent living in a VPS — orchestrating schedules, automating workflows, managing repositories, and assisting with security assessments, 24/7.
The Institute's public face — an anime official-site-style directory of six member dossiers, with keyboard navigation and layered scroll choreography.
กวดวิชากระดานขาว — a Thai tutoring page that makes AI, AI agents, and cybersecurity approachable for absolute beginners. No code required.
// More in the archive: Songkran Mix · Carrot Rush · EXIE · Minigame.py · Dynamic Malware Detection · GPS Map-Matching · OAuth 2.0 Cloud API · Journalor · Arduino RC Car · CanSat
A security engagement, a collaboration, or a question about a report — my inbox is open, and I actually read it.