Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 

Repository files navigation

header

typing

Visit Website

GitHub LinkedIn Medium Email

Executive Summary

I am Waris Damkham (Waariss), a Security Research Engineer based in Bangkok, Thailand. I focus on offensive security, red teaming, AI security, identity and M365 security, application security, vulnerability research, and security tooling — with an emphasis on research-driven, practical security outcomes.

  • Current: Offensive Security Engineer @ KASIKORN Business-Technology Group (KBTG) (Nov 2024 - Present)
  • Focus in 2026: AI red teaming, Microsoft 365 Conditional Access edge-case research, prompt-attack simulation, vulnerability research, and scalable security tooling
  • Delivery: 40+ penetration tests, 40+ executive/technical summaries, and 25+ stakeholder briefings

Performance Snapshot (Website Data: 2026)

32
CVEs Published/Credited
3
IEEE Publications
18
Featured Credentials
10
Talks / Contributions
Research & Tooling
Public Projects
40+
Security Assessments

Featured Work

  • Oblivion Token: M365 Conditional Access Policy Bypass OST Offensive research utility for practical and repeatable Microsoft 365 Conditional Access edge-case testing, presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs.
  • whitebox-secure-scan Offline, read-only white-box secure-code triage / static-analysis tooling for penetration testers.
  • jailbreakit Go CLI for authorized iOS pentest lab readiness, jailbreak compatibility, Frida/Objection, SSH, iproxy and IPA-testing workflows.
  • UploadSmith Caido plugin for file-upload security testing, including multipart Content-Type mutation, filename-extension bypass presets and magic-byte helpers.
  • NCSA AI CTF 2026 (Thailand) Challenge author representing KBTG for Thailand's first Cyber AI CTF, with AI-security and prompt-attack scenarios.

Domain Focus

Offensive Security Red Team Vulnerability Research AI Security Identity and M365 Web AppSec API Mobile Cloud

Tooling Stack

Burp Suite Caido Kali Metasploit Nmap sqlmap Wireshark Nessus Python Go JavaScript TypeScript Power Automate

Highlighted Certifications

Show all certifications

OSCP+ OSCP CPTS PNPT CRTP CARTP BSCP CWES eWPTX

PAPA PMPA ASCP CDSA PSAA CJCA PT1 Cloud Digital Leader GHF

Talks & Contributions

Completed

  • Black Hat Asia 2026 Arsenal — Oblivion Token: M365 Conditional Access Policy Bypass OST
  • DEF CON Singapore 2026 Demo Labs — Oblivion Token: M365 Conditional Access Policy Bypass OST
  • NCSA AI CTF 2026 (Thailand) — Challenge author for AI-security and prompt-injection scenarios
  • ICT Mahidol Cybersecurity Club — Real-World Cybersecurity Without Filters
  • KBTG Knowledge Sharing 2025 — AI Security Unmasked: The Hidden Danger Behind Your AI Tools
  • TBCert Monthly Meeting 2025 — AI Security Research: The Rise of AI Threat

Upcoming / Accepted

  • Black Hat India 2026 BriefingsPolicy per App, Trust per Family: Cross-Application Privilege Amplification in Microsoft 365 📅 30 Oct 2026 · Track 2 · 16:00 IST · Bengaluru, India Official session page · Black Hat India announcement

  • Red x Blue Pill 2026Your Clients Think MFA Means Secure. Prove Them Wrong: Systematic M365 Conditional Access Bypass via Microsoft First-Party Apps 📅 12 Sep 2026 Facebook · LinkedIn

Selected Research Outputs

CVE Research

32 CVEs published/credited. Recent highlights:

  • CVE-2026-0294 — Palo Alto Networks Prisma Access Agent: Local Privilege Escalation
  • CVE-2026-0292 — Palo Alto Networks Prisma Access Agent: Local Security Inspection Bypass on Windows

View all 32 CVEs on the portfolio

GitHub Activity

stats langs

streak

activity graph

Connect

footer line

Offense with discipline. Research with impact.

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors