WELCOME TO MY WORLD

Hi, I'm ryuukhagetsu

a 

I am an experienced penetration tester with 5 years of expertise and certifications including CAPenX, CMPen-Android, WEB-RTA, CEHv13, eJPT, CNSP, CAP, and CRTA. Specializing in fortifying security across diverse sectors including Banking, Finance, Ecommerce, and Healthcare.

About Me

ryuukhagetsu
5+ Years Experience

My name is Septio Noerdiansyah, known online as RyuuKhagetsu — a passionate cybersecurity professional with over 5 years of experience in penetration testing, vulnerability assessment, and red teaming. My journey began as a CTF enthusiast while studying Computer Science, and quickly evolved into a professional career in security.

My mission is to help organizations strengthen their security posture by identifying and mitigating vulnerabilities before they can be exploited by malicious actors. I believe in responsible disclosure and ethical hacking principles.

Certifications

  • SecOps Group Certified AppSec Pentesting eXpert (CAPenX)
  • SecOps Group Certified Mobile Pentester (CMPen-Android)
  • Cyberwarfare Labs Certified Web Red Team Analyst (WEB-RTA)
  • Certified Ethical Hacker (CEH) v13
  • INE eLearnSecurity Junior Penetration Tester (eJPT)
  • Cyberwarfare Labs Certified Red Team Analyst (CRTA)
  • SecOps Group Certified Network Security Practitioner (CNSP)
  • Secops Group Certified AppSec Practitioner (CAP)
  • Cyberwarfare Labs Certified Process Injection Analyst (CPIA)
  • Cybersecurity Awareness Professional Certification (CAPC)
  • OSCP (In Progress)

Favorite Tools

  • Burp Suite Pro
  • Metasploit Framework
  • Frida & Ghidra
  • Wireshark & Nmap
  • Cobalt Strike & Covenant

Skills & Expertise

Penetration Testing

Expert in black/gray box penetration testing across web applications, networks, mobile apps, and cloud infrastructure.

Bug Hunting

Experienced bug bounty hunter with a track record of finding critical vulnerabilities across major platforms.

Reverse Engineering

Proficient in analyzing compiled binaries, identifying vulnerabilities, and creating custom exploits.

Network Security

Deep understanding of network protocols, traffic analysis, and infrastructure hardening techniques.

Mobile Security

Specialized in Android app assessments, API security, and mobile app architecture reviews.

Web Security

Expert in OWASP Top 10 vulnerabilities including XSS, SQLi, CSRF, and business logic flaws.

My Projects

A collection of tools and applications I've built

Security Automation Reconnaissance

LazyScan - Automated Recon & Vulnerability Scanner

LazyScan is an automated reconnaissance & vulnerability scanner that combines various tools for comprehensive scanning with real-time Telegram notifications.

Security Compliance Static Analysis

seccomp-cli

A security compliance tool that performs static analysis on Android APKs and passive security checks on web applications. All findings are automatically mapped to ISO/IEC 27001:2022 controls with CVSS 4.0 scoring for compliance reporting.

Bug Bounty Subdomain Enumeration

Subdomain Enumerator

Advanced subdomain enumeration tool designed for penetration testers and security researchers. Combines multiple reconnaissance techniques with intelligent analysis to discover and analyze subdomains with actionable pentesting insights.

Web Development Landing Page Bootstrap

Shirai Education

A simple landing page for a tutoring service called Shirai Education, built with HTML, CSS, JavaScript, and Bootstrap.

Web Development Dashboard Bootstrap

Akbar Photocopy

A landing page and simple dashboard website for a photocopy service, built with HTML, CSS, JavaScript, and Bootstrap.

Hall of Fame

Companies and platforms that have recognized my security contributions

My Journey

Work experiences and another activity.

Work Experience

PT Linuxhackingid Cyber Security

Lead IT Instructor & Offensive Security

Mar 2024 - Present • 2 yrs 4 mos

Jakarta, Indonesia • Remote

Progressed through instructional and offensive security leadership roles at Linuxhackingid, leading cybersecurity training programs, penetration testing labs, and client security engagements.

  • Lead IT Instructor & Offensive Security (Oct 2025 - Present) — Leading offensive security initiatives and advanced training programs, mentoring instructors, and validating security assessment methodologies and reports.
  • IT Instructor & Offensive Security (Mar 2024 - Oct 2025) — Developed cybersecurity curriculum, conducted network penetration testing, and delivered live training sessions and workshops.
  • VAPT - API Security Testing (cariilmu.co.id) (Mar 2025 - Apr 2025) — Performed API security testing on OTP-related endpoints and identified a race condition in dynamic OTP rate limiting, reported with reproduction steps and mitigations.
Offensive Security Penetration Testing Training & Education API Security Red Teaming Leadership

Bank Raya

Mobile Application Security Specialist

Jan 2025 - Present • 1 yr 6 mos

Jakarta, Indonesia • Contract

Specialized penetration testing of Visa product features within mobile banking application, focusing on payment security and user data protection.

  • Conducted security assessment of Visa payment integration features
  • Identified exploitable vulnerabilities affecting user security
  • Analyzed Flutter/Dart mobile application security architecture
  • Delivered comprehensive remediation guidance to development teams
Mobile Banking Security Payment Systems Flutter/Dart Visa Integration

Universitas Pamulang

University Systems Security Auditor

Nov 2023 - Present

Jakarta, Indonesia • Long-term Contract

Comprehensive security assessment of university IT infrastructure, covering both production and pre-launch educational systems.

  • Performed VAPT across all IT-related subdomains and applications
  • Assessed security of academic management systems and student portals
  • Conducted pre-launch security testing for new educational platforms
  • Established ongoing security monitoring and assessment protocols
Educational Systems Infrastructure Security Pre-launch Testing Academic Platforms

Intigriti

Penetration Tester

Nov 2022 - Present • 2 yrs 7 mos

Brussels, Belgium • Freelance

Active researcher on European bug bounty platform, focusing on advanced reconnaissance techniques and penetration testing methodologies.

  • Conducted comprehensive security assessments for European enterprises
  • Developed innovative reconnaissance methodologies and tools
  • Contributed to platform community through knowledge sharing
  • Maintained high-quality vulnerability reports with detailed remediation guidance
Advanced Reconnaissance European Compliance Tool Development Technical Writing

Bugcrowd

Penetration Tester

Feb 2022 - Present • 3 yrs 4 mos

San Francisco, CA • Freelance

Active bug bounty hunter on one of the world's leading crowdsourced cybersecurity platforms, identifying critical vulnerabilities for global enterprises.

  • Discovered and reported 100+ vulnerabilities across web applications
  • Specialized in reconnaissance, penetration testing, and vulnerability research
  • Maintained consistent top researcher ranking in multiple programs
  • Contributed to securing Fortune 500 companies through responsible disclosure
Bug Bounty Reconnaissance Web Application Security Responsible Disclosure

HackerOne

Penetration Tester

Aug 2021 - Present • 3 yrs 10 mos

Remote • Freelance

Long-standing member of the HackerOne community, conducting security research and vulnerability assessments for major technology companies.

  • Participated in 50+ private and public bug bounty programs
  • Achieved recognition in multiple Hall of Fame programs
  • Mentored junior researchers in responsible vulnerability disclosure
  • Specialized in complex attack chains and business logic flaws
Vulnerability Research Security Testing Ethical Hacking Community Mentoring

PT. Intikom Berlian Mustika

Cyber Security Engineer

Feb 2024 - Jan 2026 • 2 yr

Jakarta, Indonesia • Full-time

Specialized in enterprise cybersecurity engineering, implementing robust security infrastructure and conducting comprehensive security assessments.

  • Designed and implemented enterprise-level security architectures
  • Conducted regular penetration testing and vulnerability assessments
  • Developed security policies and incident response procedures
  • Collaborated with development teams to integrate security best practices
Security Architecture Penetration Testing Incident Response Enterprise Security

PT Multidaya Dinamika

Senior Web Application Penetration Tester

Jan 2025 - Jun 2025

Jakarta, Indonesia • Contract

Executed advanced penetration testing on staging web applications, successfully achieving server access through critical vulnerability exploitation.

  • Identified high to critical risk vulnerabilities enabling server compromise
  • Conducted impact analysis and validated exploit chains
  • Performed bypass testing and coordinated retesting with internal teams
  • Provided strategic security recommendations and mitigation strategies
Advanced Web Pentesting Server Compromise Exploit Development Bypass Techniques

PT Pos Indonesia

VAPT Consultant - Enterprise Systems

Feb 2025 - Apr 2025

Jakarta, Indonesia • Contract

Conducting comprehensive vulnerability assessment and penetration testing on critical financial systems for Indonesia's national postal service.

  • Performed VAPT on PosPay mobile application and Core Giro System
  • Identified critical vulnerabilities in authentication and authorization mechanisms
  • Assessed Remittance System security and data protection controls
  • Delivered detailed security reports with remediation recommendations
Enterprise VAPT Financial Systems Mobile Security Data Protection

Universitas Pandanaran Semarang

Academic Information Systems Penetration Tester

Mar 2025 - Apr 2025

Semarang, Indonesia • Project-based

Security assessment of academic information systems with focus on student data protection and system integrity.

  • Conducted penetration testing on academic information system subdomains
  • Identified critical vulnerabilities affecting active student data
  • Performed manual testing and comprehensive vulnerability documentation
  • Coordinated with university IT team for responsible disclosure and mitigation
Academic Systems Student Data Security Manual Testing Responsible Disclosure

Activities & Events

Personal Project

LazyScan

Automated Recon & Vulnerability Scanner

2025 Sep - Present

Open Source • GitHub

Developed LazyScan, an automated reconnaissance and vulnerability scanning framework designed to support penetration testing and bug bounty activities by integrating multiple popular security tools.

  • Implemented subdomain discovery and live host enumeration using Subfinder and Httpx
  • Automated URL discovery and classification, including JavaScript files and parameterized endpoints
  • Integrated Nuclei for vulnerability scanning (general templates, JavaScript, and DAST scans)
  • Built real-time Telegram notifications for scan progress and vulnerability findings
  • Designed structured and readable output to streamline analysis and reporting

The project focuses on efficiency, automation, and operational visibility to accelerate recon workflows and improve testing productivity.

🔗 Repository: github.com/ryuukhagetsu/lazyscan

Python Automation Reconnaissance Vulnerability Scanning Bug Bounty
Personal Project

Subdomain Enumerator

Advanced Reconnaissance Tool

2025 Jul - Present

Open Source • GitHub

Developed an advanced subdomain enumeration tool designed to support penetration testers and security researchers during the reconnaissance and information gathering phase.

  • Aggregated data from 8+ passive reconnaissance sources including Certificate Transparency, ThreatCrowd, DNSDumpster, and Wayback Machine
  • Implemented high-performance DNS brute-force enumeration using customizable wordlists
  • Performed technology fingerprinting for 20+ stacks including CMS, frameworks, and web servers
  • Analyzed security headers, identified admin panels, and detected staging or development environments
  • Provided risk scoring and actionable exploitation recommendations to support decision-making
  • Generated scan results in multiple formats (interactive HTML, TXT, CSV, JSON) for reporting and documentation
  • Optimized for multi-threaded execution with cross-platform support (Windows, Linux, macOS)

The tool emphasizes actionable intelligence by transforming raw reconnaissance data into structured, prioritized security insights.

🔗 Repository: github.com/ryuukhagetsu/subdomain-enumerator

Python Penetration Testing Reconnaissance Automation Information Gathering
Personal Project

Seccomp-CLI

Security Compliance Tool

2025 Sep - Present

Open Source • GitHub

seccomp-cli is a security compliance tool that performs static analysis on Android APKs and passive security checks on web applications. All findings are automatically mapped to ISO/IEC 27001:2022 controls with CVSS 4.0 scoring for compliance reporting.

  • Android Static Analysis: Manifest checks, cryptographic analysis, WebView security
  • Web Security Scanning: HTTP headers, TLS/SSL, CORS configuration
  • Import from External Tools: MobSF and Nuclei report normalization
  • CVSS 4.0 Scoring: Automatic vulnerability scoring per FIRST specification
  • ISO 27001 Mapping: Comprehensive mapping to 70+ Annex A controls
  • Risk Assessment: Severity scoring and compliance grading
  • Multiple Output Formats: JSON, CSV, Markdown, HTML

🔗 Repository: github.com/ryuukhagetsu/seccomp-cli

Python Security Compliance Android Security ISO 27001 CVSS
Personal Project

Shirai Education

Educational Platform

2024 - Present

Open Source • GitHub

Developed an educational platform designed to provide learning resources and interactive content for students and educators.

  • Built responsive web interface with modern UI/UX principles
  • Implemented interactive learning modules and content management
  • Designed user-friendly navigation and accessible layout

🔗 Repository: github.com/ryuukhagetsu/shirai_education

Web Development Education UI/UX
Personal Project

Akbar Photocopy

Business Management Application

2024 - Present

Open Source • GitHub

Developed a business management application for a photocopy shop, providing features for transaction tracking, inventory management, and sales reporting.

  • Implemented transaction management and point-of-sale functionality
  • Built inventory tracking and stock management system
  • Designed sales reporting and business analytics dashboard
  • Created user-friendly interface for daily business operations

🔗 Repository: github.com/ryuukhagetsu/akbar_photocopy

Web Development Business Application Inventory Management
Webinar Speaker

PT Linuxhackingid Cyber Security

Practical Web Security Webinar Series

May 2024 - Aug 2025

Online Webinar • Linuxhackingid

Delivered a series of practical, hands-on cybersecurity webinars for the Linuxhackingid community, combining offensive techniques with defensive best practices.

  • Practical Web Exploitation for Bug Bounty (Aug 2025) — End-to-end web exploitation methodology for bug bounty, covering reconnaissance, vulnerability discovery, and exploitation chains with live demonstrations.
  • Practical Webinar: Finding SQL Injection Bugs and Prevention (May 2024) — Discovering and preventing SQL injection vulnerabilities, from exploitation patterns to secure coding practices for developers.
Web Exploitation SQL Injection Bug Bounty Public Speaking Live Demonstrations
Speaker

Universitas Pamulang

The Future of Cybersecurity: Emerging Trends and Predictions

November 2024

Universitas Pamulang, Jakarta

Delivered keynote presentation on emerging cybersecurity trends and future threat predictions at National Seminar, featuring live cyber attack demonstrations.

  • Presented cutting-edge cybersecurity trends and threat landscape analysis
  • Conducted live cyber attack demonstrations on prepared targets
  • Enhanced audience awareness of evolving cyber threats and countermeasures
  • Engaged with 200+ students and faculty members
Public Speaking Live Demonstrations Threat Analysis Education
Guest Speaker

Universitas Gunadarma

Cybersecurity Career Opportunities and Future Challenges

Oct 2024 - Nov 2024

Community Cybersecurity Universitas Gunadarma (CCUG)

Invited speaker for cybersecurity career webinar series, sharing insights on industry opportunities and challenges facing the next generation of cybersecurity professionals.

  • Discussed current cybersecurity career landscape and growth opportunities
  • Shared practical insights from bug bounty and penetration testing experience
  • Provided guidance on skill development and certification pathways
  • Mentored aspiring cybersecurity professionals during Q&A sessions
Career Guidance Industry Insights Mentoring Professional Development
Recognition

Government Recognition Programs

Multiple Certificate of Appreciation Awards

2021 - 2024

Indonesia • Various Locations

Received multiple certificates of appreciation from government agencies and prestigious institutions for contributions to cybersecurity awareness and vulnerability research.

  • Badan Siber dan Sandi Negara (BSSN) - National Cyber Security Agency
  • Kementerian Komunikasi dan Informatika (Kominfo) - Ministry of Communication
  • CSIRT Cimahi - Computer Security Incident Response Team
  • Transjakarta Hall of Fame - White Hacker Recognition
Government Recognition White Hat Hacking Public Service National Security
Academic Recognition

University Appreciation Programs

Multiple University Recognition Awards

2021 - Present

Indonesia • Academic Institutions

Honored by multiple prestigious universities for cybersecurity contributions and educational support through vulnerability research and responsible disclosure.

  • Universitas Brawijaya - Cybersecurity Research Contribution
  • Universitas Bina Sarana Informatika (BSI) - Multiple recognitions
  • Universitas Telkom - Bug Bounty Hall of Fame
  • Educational platform partnerships and mentoring programs
Academic Collaboration Research Contribution Educational Support Knowledge Transfer
Professional Development

Continuous Learning & Certification

Advanced Cybersecurity Certifications

2021 - Present

Global • Online & On-site

Continuously advancing professional expertise through industry-leading certifications and specialized training programs.

  • The SecOps Group Certified AppSec Pentesting eXpert (CAPenX)
  • The SecOps Group Certified Mobile Pentester (CMPen-Android)
  • CyberWarFare Labs Certified Web Red Team Analyst (WEB-RTA)
  • eLearnSecurity Junior Penetration Tester (eJPT)
  • EC-Council Certified Ethical Hacker (CEH V13)
  • CyberWarFare Labs Certified Red Team Analyst (CRTA)
  • The SecOps Group Certified AppSec Practitioner (CAP)
  • The SecOps Group Certified Network Security Practitioner (CNSP)
  • CyberWarFare Labs Certified Process Injection Analyst (CPIA)
  • Certified Computer Forensics Analyst (CCFA)
  • Cybersecurity Awareness Professional Certification (CAPC)
  • Scrum Foundation Professional Certification (SFPC)
CEH V13 Red Team Operations Digital Forensics Continuous Learning

Certifications & Achievements

Professional certifications, achievements, and recognition in cybersecurity field

Certificate

Latest Articles

Sharing knowledge through detailed write-ups and tutorials

Time-Based SQL Injection in Coffee Ordering App
Time-Based SQLi Mobile API

The Coffee Order That Made the Database Sleep

What started as a casual coffee order turned into a Time-Based SQL Injection discovery in a mobile ordering API.

Read More
Out-of-Band SQL Injection
SQL Injection OOB SQLi

Breaking Past 403: A Deep Dive into Out-of-Band SQL Injection Discovery

Discovered Out-of-Band SQL Injection on MSSQL server, bypassing 403 restrictions through directory fuzzing and payload crafting.

Read More
Broken Access Control
Broken Access Control SQL Injection

Abusing Broken Access Control and SQL Injection in the Wild

Discovered Broken Access Control exposing admin dashboard with full CRUD functionality, chained with SQL Injection vulnerability.

Read More