I am Waris Damkham (Waariss), a Security Research Engineer based in Bangkok, Thailand. I focus on offensive security, red teaming, AI security, identity and M365 security, application security, vulnerability research, and security tooling — with an emphasis on research-driven, practical security outcomes.
- Current: Offensive Security Engineer @ KASIKORN Business-Technology Group (KBTG) (Nov 2024 - Present)
- Focus in 2026: AI red teaming, Microsoft 365 Conditional Access edge-case research, prompt-attack simulation, vulnerability research, and scalable security tooling
- Delivery: 40+ penetration tests, 40+ executive/technical summaries, and 25+ stakeholder briefings
| 32 CVEs Published/Credited |
3 IEEE Publications |
18 Featured Credentials |
| 10 Talks / Contributions |
Research & Tooling Public Projects |
40+ Security Assessments |
- Oblivion Token: M365 Conditional Access Policy Bypass OST Offensive research utility for practical and repeatable Microsoft 365 Conditional Access edge-case testing, presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs.
- whitebox-secure-scan Offline, read-only white-box secure-code triage / static-analysis tooling for penetration testers.
- jailbreakit Go CLI for authorized iOS pentest lab readiness, jailbreak compatibility, Frida/Objection, SSH, iproxy and IPA-testing workflows.
- UploadSmith Caido plugin for file-upload security testing, including multipart Content-Type mutation, filename-extension bypass presets and magic-byte helpers.
- NCSA AI CTF 2026 (Thailand) Challenge author representing KBTG for Thailand's first Cyber AI CTF, with AI-security and prompt-attack scenarios.
- Black Hat Asia 2026 Arsenal — Oblivion Token: M365 Conditional Access Policy Bypass OST
- DEF CON Singapore 2026 Demo Labs — Oblivion Token: M365 Conditional Access Policy Bypass OST
- NCSA AI CTF 2026 (Thailand) — Challenge author for AI-security and prompt-injection scenarios
- ICT Mahidol Cybersecurity Club — Real-World Cybersecurity Without Filters
- KBTG Knowledge Sharing 2025 — AI Security Unmasked: The Hidden Danger Behind Your AI Tools
- TBCert Monthly Meeting 2025 — AI Security Research: The Rise of AI Threat
-
Black Hat India 2026 Briefings — Policy per App, Trust per Family: Cross-Application Privilege Amplification in Microsoft 365 📅 30 Oct 2026 · Track 2 · 16:00 IST · Bengaluru, India Official session page · Black Hat India announcement
-
Red x Blue Pill 2026 — Your Clients Think MFA Means Secure. Prove Them Wrong: Systematic M365 Conditional Access Bypass via Microsoft First-Party Apps 📅 12 Sep 2026 Facebook · LinkedIn
- Oblivion Token: M365 Conditional Access Policy Bypass OST — Offensive research tool presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs
- Practical Mobile Based Services for Identification of Chicken Diseases From Fecal Images (IEEE TENCON 2024)
- Detecting Vulnerable OAuth 2.0 Implementations in Android Applications (IEEE QRS 2023)
- Automated COVID-19 Screening Framework Using Deep CNN With Chest X-Ray Medical Images (IEEE InCIT 2022)
32 CVEs published/credited. Recent highlights:
- CVE-2026-0294 — Palo Alto Networks Prisma Access Agent: Local Privilege Escalation
- CVE-2026-0292 — Palo Alto Networks Prisma Access Agent: Local Security Inspection Bypass on Windows
→ View all 32 CVEs on the portfolio
- Portfolio: waris-damkham.netlify.app
- LinkedIn: linkedin.com/in/waris-damkham
- GitHub: github.com/Waariss
- Medium: medium.com/@waaris_m
- ResearchGate: researchgate.net/profile/Waris-Damkham
- Google Scholar: scholar.google.com/citations?user=dug8UQQAAAAJ
- Credly: credly.com/users/waris-damkham
- TryHackMe: tryhackme.com/p/waris.dam
- HackTheBox: profile.hackthebox.com/profile/019c5786-35c7-7398-ad5e-32d60b572cdb
- Email: waris.dam@outlook.com
Offense with discipline. Research with impact.







