Skip to content
View lawbyte's full-sized avatar
🏠
Working from home
🏠
Working from home

Highlights

  • Pro

Organizations

@seccodeid @sksd-id

Block or report lawbyte

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
lawbyte/README.md
Azka Ainul Ma'arij, Offensive Security Engineer



LinkedIn Hack The Box GitHub followers


I break into web apps, mobile apps, APIs, Active Directory, and industrial control systems for a living, then write the report that gets them fixed. Based in Singapore, working mostly across financial-sector and enterprise engagements.

Currently

  • Senior Security Consultant at Vantage Point Security: web, API, and mobile penetration testing, adversary simulation, and Active Directory compromise chains for enterprise and financial-sector clients, backed by custom exploit tooling when off-the-shelf doesn't cut it.
  • Mobile challenge author for Hack The Box, building production-grade Android reverse-engineering and exploitation challenges.
  • Organizer for Hack The Box Indonesia; competes internationally with r3kapig, SKSD, and PETIR; occasional speaker and trainer in offensive security.

Focus

Offense: web & API exploitation, Android reverse engineering and dynamic instrumentation, mobile app security (MASVS-aligned), SCADA / OT attack simulation, Active Directory abuse and post-exploitation.

Research: binary reverse engineering, custom exploit development, cryptographic analysis, security bypass techniques.

Toolbox: Python · Frida · IDA Pro · Ghidra · Burp Suite · Metasploit · BloodHound · Wireshark · Docker

Certifications

OSCP+ · CREST CRT · CREST CPSA · Burp Suite Certified Practitioner · CXMAP · CAPT

Elsewhere

LinkedIn · Hack The Box

Pinned Loading

  1. Active-Directory-Exploitation-Cheat-Sheet Active-Directory-Exploitation-Cheat-Sheet Public

    Forked from S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet

    A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

    1

  2. avs avs Public

    APK Vulnerability Scanner (AVS)

    Python 3 1

  3. Android-Protection-Bypass-Stuff Android-Protection-Bypass-Stuff Public

    Forked from WangChongwen-me/Android-Protection-Bypass-Stuff

    Android Protection Bypass Stuff that I compiled from few resources.

    JavaScript

  4. jwt-lab jwt-lab Public

    Python 1