NightWatch EDR
A Proof-of-Concept Endpoint Detection & Response (EDR) inspired tool built to monitor host activity, detect suspicious behavior using custom rules, log security events, and send real-time Telegram alerts.
// cybersecurity enthusiast
Offensive Security · Blue Team · Red Team · Penetration Testing
I study how systems break so I can understand how to defend them. From CTF challenges and HTB labs to real-world security tooling, this is where I document the journey.
01 / about
I'm Wakamiya Naufal, a cybersecurity enthusiast driven by curiosity, continuous learning, and a passion for understanding how systems work from both the offensive and defensive perspectives. What interests me most isn't the image of hacking. it's the logic behind attacks, the architecture of secure systems, and the challenge of solving complex security problems.
My journey began with Linux, networking, and programming before expanding into penetration testing, web application security, reverse engineering, Active Directory, and network security. Through hands-on practice with platforms like HackTheBox and TryHackMe, along with studying technical documentation, CVEs, and real-world security research, I've built a practical foundation in cybersecurity.
Although I explore multiple areas of cybersecurity to develop a broad understanding of modern security, my primary focus is Offensive Security and Red Teaming. I continuously deepen my knowledge of penetration testing, exploit development, Active Directory security, and adversary simulation while maintaining foundational knowledge across defensive security, cloud security, networking, and reverse engineering.
My long-term goal is to build a career in Offensive Security, continuously improving my technical skills through practical projects, CTFs, labs, and real-world security research while contributing to stronger and more resilient systems.
02 / skills
Penetration testing methodology, exploitation techniques, privilege escalation, and vulnerability research.
Threat detection, log investigation, incident response fundamentals, and EDR development.
TCP/IP stack, network protocols, packet analysis, traffic inspection, and network-based attack vectors.
Linux internals, shell scripting, privilege escalation, process management, and system hardening.
Scripting for automation, security tooling, and building utility programs for offensive and defensive tasks.
Binary analysis, disassembly, debugging, and understanding malware or obfuscated code at the assembly level.
Cloud infrastructure security, IAM misconfigurations, S3 exposure, and cloud-native attack paths.
OWASP Top 10, web application testing, SQL injection, XSS, IDOR, authentication bypass, and API security.
03 / journey
First steps into coding with Python and some basic knowledge about Web Development. Learned the basics of logic, automation, and problem-solving through small projects and exercises.
Switched environment to Linux using virtualization machine. Learned the shell, file system, permissions, and began appreciating the control it offers.
Realized security was the direction I wanted to pursue seriously. Started reading/learning CVEs, security blogs, online courses and understanding how vulnerabilities work.
Began structured learning on TryHackMe. Covered networking, web exploitation, Linux privilege escalation, and introductory penetration testing paths.
Joined HTB Academy and began working through more challenging boxes. learning/practicing in a modules available and developed a methodical approach to enumeration and exploitation.
Built a hardware integrated Smart Parking System project combining programming and embedded systems,sharpened problem solving and project planning skills.
Dived into reverse engineering,Web Exploit,Active Directory and OSINT challenges. Started participating in CTF competitions.
Built a proof of concept Endpoint Detection & Response tool, exploring Windows internals, event logging, and real-time threat monitoring.
I do enjoy learning different areas of cybersecurity to build a well-rounded foundation. However, my primary focus is Offensive Security and Red Teaming, where I dedicate most of my time to penetration testing, exploit development, Active Directory/Web Security, and real-world attack methodologies.
practicing more, actively building, studying, and documenting everything on my social media.
04 / projects
A selection of what I've built. Full documentation and source code on GitHub.
A Proof-of-Concept Endpoint Detection & Response (EDR) inspired tool built to monitor host activity, detect suspicious behavior using custom rules, log security events, and send real-time Telegram alerts.
An IoT-based smart parking system that uses ESP32 and Infrared sensors to detect parking slot occupancy, synchronize data with a web dashboard in real time, and provide live parking availability monitoring.
Real-time SOC monitoring agent for Cowrie Honeypot with Discord alerting and offline GeoIP enrichment.
Personal web security lab built with PHP, Apache, and MariaDB to explore authentication, SQL Injection, session management, password hashing, and secure coding practices through hands-on experimentation.
05 / writeups
Documentation of challenges, labs, and CTF solutions. Full writeups/documentary available on GitHub & Insta.
CTF
PicoCTF | Reverse Engineering
Analyzed binary logic and reverse engineered the program to understand its functionality and recover the challenge flag.
Challenges
TryHackMe | Binary Exploitation
Exploited a classic stack buffer overflow vulnerability using a ret2win technique to redirect execution and gain shell access.
HackTheBox · Web Exploitation
Compromised a multi-stage Hack The Box machine by chaining NFS enumeration, mail service abuse, OpenSTAManager command injection (CVE-2025-69212), password cracking, and privilege escalation through a misconfigured OliveTin instance.
HackTheBox · Web Exploitation
Nexus is a retired easy-to-medium difficulty Linux machine on Hack The Box that focuses on web application enumeration, credential exposure, and path traversal.
Challenges
TryHackMe · Web Exploitation
Wordpress Compromise Through Credential Discovery and Privilege Escalation
Challenges
TryHackMe · Active Directory
Practiced Active Directory enumeration, privilege escalation, and post-exploitation techniques in a Windows domain environment.
Challenges
TryHackMe · Web Exploitation
An easy level Boot2Root challenge designed to test essential penetration testing skills. The objective is to enumerate the target, find two flags (user and root), and elevate privileges to become the system administrator.
06 / CERTIFICATES