I am Waris Damkham (Waariss), a Security Research Engineer based in Bangkok, Thailand. My background spans vulnerability research, red teaming, AI security, identity security, application security, and security tooling, including end-to-end assessments across web, API, mobile, network, and identity environments.
- Current: Cyber Security Engineer @ Cyber Test Systems (Sep 2026 - Present)
- Previous: Offensive Security Engineer @ KASIKORN Business-Technology Group (KBTG) (Nov 2024 - Sep 2026)
- Research: Creator of Oblivion Token, presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs; speaker at Red x Blue Pill 2026 and upcoming speaker at Black Hat India 2026 Briefings
- Delivery: 45+ penetration tests, 40+ executive/technical summaries, and 25+ stakeholder briefings
| 35 CVEs Published/Credited |
3 IEEE Publications |
18 Featured Credentials |
| 10 Talks / Contributions |
20 Public Projects |
40+ Security Assessments |
- Oblivion Token: M365 Conditional Access Policy Bypass OST Offensive research utility for practical and repeatable Microsoft 365 Conditional Access edge-case testing, presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs.
- whitebox-secure-scan Offline, read-only white-box secure-code triage / static-analysis tooling for penetration testers.
- jailbreakit Go CLI for authorized iOS pentest lab readiness, jailbreak compatibility, Frida/Objection, SSH, iproxy and IPA-testing workflows.
- UploadSmith Caido plugin for file-upload security testing, including multipart Content-Type mutation, filename-extension bypass presets and magic-byte helpers.
- Meeting Shrinker Browser-first tool for compressing recordings, extracting audio, cleaning transcripts, and preparing Thai/English meeting content for NotebookLM while processing files locally by default.
- NCSA AI CTF 2026 (Thailand) Challenge author representing KBTG for Thailand's first Cyber AI CTF, with AI-security and prompt-attack scenarios.
- Red x Blue Pill 2026 β Your Clients Think MFA Means Secure. Prove Them Wrong: Systematic M365 Conditional Access Bypass via Microsoft First-Party Apps π 12 Sep 2026 Facebook Β· LinkedIn
- DEF CON Singapore 2026 Demo Labs β Oblivion Token: M365 Conditional Access Policy Bypass OST
- Black Hat Asia 2026 Arsenal β Oblivion Token: M365 Conditional Access Policy Bypass OST
- NCSA AI CTF 2026 (Thailand) β Challenge author for AI-security and prompt-injection scenarios
- ICT Mahidol Cybersecurity Club β Real-World Cybersecurity Without Filters
- KBTG Knowledge Sharing 2025 β AI Security Unmasked: The Hidden Danger Behind Your AI Tools
- TBCert Monthly Meeting 2025 β AI Security Research: The Rise of AI Threat
- Black Hat India 2026 Briefings β Policy per App, Trust per Family: Cross-Application Privilege Amplification in Microsoft 365 π 30 Oct 2026 Β· Track 2 Β· 16:00 IST Β· Bengaluru, India Official session page Β· Black Hat India announcement
- Oblivion Token: M365 Conditional Access Policy Bypass OST β Offensive research tool presented at Black Hat Asia 2026 Arsenal and DEF CON Singapore 2026 Demo Labs
- Practical Mobile Based Services for Identification of Chicken Diseases From Fecal Images (IEEE TENCON 2024)
- Detecting Vulnerable OAuth 2.0 Implementations in Android Applications (IEEE QRS 2023)
- Automated COVID-19 Screening Framework Using Deep CNN With Chest X-Ray Medical Images (IEEE InCIT 2022)
35 CVEs published/credited. Recent highlights:
- CVE-2026-15710 β Netskope Client Endpoint DLP Kernel Driver Information Leakage
- CVE-2026-0294 β Palo Alto Networks Prisma Access Agent: Local Privilege Escalation
- CVE-2026-0292 β Palo Alto Networks Prisma Access Agent: Local Security Inspection Bypass on Windows
β View all 35 CVEs on the portfolio
Open to research collaborations, speaking opportunities, and graduate research pathways.
- Portfolio: waris-damkham.netlify.app
- LinkedIn: linkedin.com/in/waris-damkham
- GitHub: github.com/Waariss
- Medium: medium.com/@waaris_m
- ResearchGate: researchgate.net/profile/Waris-Damkham
- Google Scholar: scholar.google.com/citations?user=dug8UQQAAAAJ
- Credly: credly.com/users/waris-damkham
- TryHackMe: tryhackme.com/p/waris.dam
- HackTheBox: profile.hackthebox.com/profile/019c5786-35c7-7398-ad5e-32d60b572cdb
- Email: waris.dam@outlook.com
Offense with discipline. Research with impact.












