SAMUEL VALMIKI

Available for work

SAMUEL VALMIKI

Security Researcher & Ethical Hacker / cyber_anna

I break into applications and networks so the people who own them don't have to find out the hard way — then I help them fix it.

WebApplication testing
ADNetwork & domain
REReversing & malware
Scroll
Web ExploitationReverse EngineeringPrivilege EscalationOSINTBinary ExploitationNetwork PentestingCryptographyMalware AnalysisCloud Security
What I do

Areas of focus

Four disciplines I work in day to day, and the tooling behind each.

01

Web application testing

Authentication bypasses, IDOR chains, SSRF into internal metadata services, deserialization, and the business-logic flaws that automated scanners never surface. Burp Suite, custom tooling, and a lot of patience.

02

Binary exploitation

Stack and heap corruption, ROP chains, format strings. pwntools is a second language.

03

Reverse engineering

Ghidra, IDA and x64dbg — unpacking, deobfuscating and reading what a binary won't admit.

04

Network & Active Directory

Kerberoasting, AS-REP roasting, NTLM relay and BloodHound path-finding — from a single low-privilege shell to Domain Admin.

05

OSINT & recon

The attack surface is always larger than the asset list.

06

Tooling & automation

Python, Bash and Go. If I do it twice, I script it.

Anatomy

The way in

  1. 01

    One name

    Every engagement starts with a single domain on a scope document.

  2. 02

    It multiplies

    Certificate transparency, DNS history, a decade of deploys nobody archived.

  3. 03

    Every host is a promise

    Each service here is something a person has to remember to patch.

  4. 04

    One of them is forgotten

    Stood up for a demo, never decommissioned, missing from the asset list.

  5. 05

    Ten seconds — what’s wrong here?

    A perfectly ordinary request. The response is the tell.

  6. 06

    The way in is rarely exotic

    It is usually an authorization decision made in the wrong place, on a box nobody owns.

  7. 07

    One box becomes all of them

    Shared credentials, trusted internal traffic, a flat network. The first host is never the last.

Writing

From the blog

All posts →
Elsewhere

Find me online

Have something that needs breaking?

Authorized testing only — happy to talk scope, timelines and what a report looks like.