SAMUEL VALMIKI

Available for work

SAMUEL VALMIKI

Security Researcher & Ethical Hacker / cyber_anna

I break into applications and networks so the people who own them don't have to find out the hard way — then I help them fix it.

WebApplication testing
ADNetwork & domain
REReversing & malware
Scroll
Web ExploitationReverse EngineeringPrivilege EscalationOSINTBinary ExploitationNetwork PentestingCryptographyMalware AnalysisCloud Security
What I do

Areas of focus

Four disciplines I work in day to day, and the tooling behind each.

01

Web application testing

Authentication bypasses, IDOR chains, SSRF into internal metadata services, deserialization, and the business-logic flaws that automated scanners never surface. Burp Suite, custom tooling, and a lot of patience.

02

Binary exploitation

Stack and heap corruption, ROP chains, format strings. pwntools is a second language.

03

Reverse engineering

Ghidra, IDA and x64dbg — unpacking, deobfuscating and reading what a binary won't admit.

04

Network & Active Directory

Kerberoasting, AS-REP roasting, NTLM relay and BloodHound path-finding — from a single low-privilege shell to Domain Admin.

05

OSINT & recon

The attack surface is always larger than the asset list.

06

Tooling & automation

Python, Bash and Go. If I do it twice, I script it.

How I work

The method

01
02
03
04
05
  1. 01

    Recon

    Map everything — subdomains, tech stack, forgotten staging boxes, leaked keys.

  2. 02

    Foothold

    One weak input or one reused credential. That is all it ever takes.

  3. 03

    Escalate

    Local user to root, or a low-privilege domain account to Domain Admin.

  4. 04

    Document

    Every step reproducible, evidenced, and mapped to MITRE ATT&CK.

  5. 05

    Remediate

    The report isn't the deliverable. The fix is.

Writing

From the blog

All posts →
Elsewhere

Find me online

Have something that needs breaking?

Authorized testing only — happy to talk scope, timelines and what a report looks like.