WN

// cybersecurity enthusiast

Wakamiya Naufal_

Offensive Security · Blue Team · Red Team · Penetration Testing

I study how systems break so I can understand how to defend them. From CTF challenges and HTB labs to real-world security tooling, this is where I document the journey.

Who I Am

I'm Wakamiya Naufal, a cybersecurity enthusiast driven by curiosity, continuous learning, and a passion for understanding how systems work from both the offensive and defensive perspectives. What interests me most isn't the image of hacking. it's the logic behind attacks, the architecture of secure systems, and the challenge of solving complex security problems.

My journey began with Linux, networking, and programming before expanding into penetration testing, web application security, reverse engineering, Active Directory, and network security. Through hands-on practice with platforms like HackTheBox and TryHackMe, along with studying technical documentation, CVEs, and real-world security research, I've built a practical foundation in cybersecurity.

Although I explore multiple areas of cybersecurity to develop a broad understanding of modern security, my primary focus is Offensive Security and Red Teaming. I continuously deepen my knowledge of penetration testing, exploit development, Active Directory security, and adversary simulation while maintaining foundational knowledge across defensive security, cloud security, networking, and reverse engineering.

My long-term goal is to build a career in Offensive Security, continuously improving my technical skills through practical projects, CTFs, labs, and real-world security research while contributing to stronger and more resilient systems.

Focus Offensive Security
Platforms HTB · TryHackMe · CTFs

Technical Skills

Offensive Security

Penetration testing methodology, exploitation techniques, privilege escalation, and vulnerability research.

MetasploitWiresharkBurp SuiteNmapSQLmapHashcatGTFOBinsImpacketNetExecExploitDBGoogle Dorking

Blue Team

Threat detection, log investigation, incident response fundamentals, and EDR development.

iptablesSysmonHIDS/HIPSEDRCIA TriadAAA SecurityOpenVPNLynisLocalSecPolCryptography

Networking

TCP/IP stack, network protocols, packet analysis, traffic inspection, and network-based attack vectors.

TCP/IPDNSHTTP/SSSHSMBtcpdumpOSI LayerKerberosLDAPRDPRPC

Linux

Linux internals, shell scripting, privilege escalation, process management, and system hardening.

Sudo PermissionKaliBlackArch/ArchsystemdcronvimawkFile systemFile/Group Permission

Programming

Scripting for automation, security tooling, and building utility programs for offensive and defensive tasks.

PythonBashCPowerShell

Reverse Engineering

Binary analysis, disassembly, debugging, and understanding malware or obfuscated code at the assembly level.

GhidraobjdumpGDBAssemblyILSpy

Cloud Security

Cloud infrastructure security, IAM misconfigurations, S3 exposure, and cloud-native attack paths.

AWSIAMS3CloudTrail

Web Security

OWASP Top 10, web application testing, SQL injection, XSS, IDOR, authentication bypass, and API security.

OWASPDVWAPath TraversalSSTI/SSRFCSRFLFIRCEGit Exposure

The Journey

2022

Started Programming

First steps into coding with Python and some basic knowledge about Web Development. Learned the basics of logic, automation, and problem-solving through small projects and exercises.

2024

Moved to Linux

Switched environment to Linux using virtualization machine. Learned the shell, file system, permissions, and began appreciating the control it offers.

2025

Discovered Cybersecurity

Realized security was the direction I wanted to pursue seriously. Started reading/learning CVEs, security blogs, online courses and understanding how vulnerabilities work.

2025

Started TryHackMe

Began structured learning on TryHackMe. Covered networking, web exploitation, Linux privilege escalation, and introductory penetration testing paths.

2025

Started Hack The Box

Joined HTB Academy and began working through more challenging boxes. learning/practicing in a modules available and developed a methodical approach to enumeration and exploitation.

2026

Smart Parking System Project

Built a hardware integrated Smart Parking System project combining programming and embedded systems,sharpened problem solving and project planning skills.

2026

CTFs

Dived into reverse engineering,Web Exploit,Active Directory and OSINT challenges. Started participating in CTF competitions.

2026

Project Blue Team

Built a proof of concept Endpoint Detection & Response tool, exploring Windows internals, event logging, and real-time threat monitoring.

2026

Offensive Security

I do enjoy learning different areas of cybersecurity to build a well-rounded foundation. However, my primary focus is Offensive Security and Red Teaming, where I dedicate most of my time to penetration testing, exploit development, Active Directory/Web Security, and real-world attack methodologies.

Now

Continuing the Path

practicing more, actively building, studying, and documenting everything on my social media.

Projects

A selection of what I've built. Full documentation and source code on GitHub.

NightWatch EDR
Blue Team
Defense / EDR Advanced

NightWatch EDR

A Proof-of-Concept Endpoint Detection & Response (EDR) inspired tool built to monitor host activity, detect suspicious behavior using custom rules, log security events, and send real-time Telegram alerts.

PythonTelegram Bot APIHost-based Intrusion Detection (HIDS)
Smart Parking System Project
Engineering
Hardware / Software Intermediate

Smart Parking System

An IoT-based smart parking system that uses ESP32 and Infrared sensors to detect parking slot occupancy, synchronize data with a web dashboard in real time, and provide live parking availability monitoring.

C++ESP32IR SensorsIoT
placeholder
BlueTeam
Medium Intermediate

HoneySOC Agent

Real-time SOC monitoring agent for Cowrie Honeypot with Discord alerting and offline GeoIP enrichment.

PythonDiscord APIGeoIP
VM
Virtual Machine
Oracle VM VirtualBox Beginner

Building My Own Virtual Machine Lab

Personal web security lab built with PHP, Apache, and MariaDB to explore authentication, SQL Injection, session management, password hashing, and secure coding practices through hands-on experimentation.

LinuxNetworkingApacheMariaDBPHPBurpSuite
placeholder
Red Team
soon Advanced

soon

soon

TECH_1TECH_2TECH_3
placeholder
Network
soon Intermediate

soon

soon

TECH_1TECH_2
placeholder
RE
soon Advanced

soon

soon

TECH_1TECH_2TECH_3
placeholder
Cloud
soon Intermediate

soon

soon

TECH_1TECH_2

Writeups

Documentation of challenges, labs, and CTF solutions. Full writeups/documentary available on GitHub & Insta.

Quantum Scrambler CTF
PicoCTF Medium

Quantum Scrambler

PicoCTF | Reverse Engineering

Analyzed binary logic and reverse engineered the program to understand its functionality and recover the challenge flag.

DearQA Challenges
TryHackMe Easy

DearQA

TryHackMe | Binary Exploitation

Exploited a classic stack buffer overflow vulnerability using a ret2win technique to redirect execution and gain shell access.

Enigma
HackTheBox Easy

Enigma

HackTheBox · Web Exploitation

Compromised a multi-stage Hack The Box machine by chaining NFS enumeration, mail service abuse, OpenSTAManager command injection (CVE-2025-69212), password cracking, and privilege escalation through a misconfigured OliveTin instance.

Nexus
HackTheBox Medium

Nexus

HackTheBox · Web Exploitation

Nexus is a retired easy-to-medium difficulty Linux machine on Hack The Box that focuses on web application enumeration, credential exposure, and path traversal.

Colddbox Challenges
TryHackMe Easy

ColddBox

TryHackMe · Web Exploitation

Wordpress Compromise Through Credential Discovery and Privilege Escalation

Active Directory Challenges
TryHackMe Medium

SoupeDecode01

TryHackMe · Active Directory

Practiced Active Directory enumeration, privilege escalation, and post-exploitation techniques in a Windows domain environment.

Opacity Challenges
TryHackMe Easy

Opacity

TryHackMe · Web Exploitation

An easy level Boot2Root challenge designed to test essential penetration testing skills. The objective is to enumerate the target, find two flags (user and root), and elevate privileges to become the system administrator.

Room
HackTheBox Advanced

soon

HackTheBox · Active Directory

soon

Room
HackTheBox Advanced

soon

HackTheBox · Active Directory

soon

Certificates

PUSDATIN Certificate
PUSDATIN Internship (6 Month) Automation Control Systems & AI
Axioo Certificate
Axioo Class Program (3 Month) Industry Based IT Training Program
Intro To Cysec Certificate
Intro To Cyber Security CyberSecurity Fundamentals
EndPoint Security Certificate
EndPoint Security EndPoint Protection & Defense
English Certificate
EF SET English Certificate CEFR B1 Intermediate
Certificate 6
MikroTik Certified Network Associate Foundation in MikroTik RouterOS configuration and network administration
× Certificate Preview

Get in Touch

I'm open to conversations about IT/cybersecurity, collaboration, or opportunities.