WELCOME TO MY WORLD

Hi, I'm ryuukhagetsu

a 

I am an experienced penetration tester with 5 years of expertise and certifications including CEHv13, eJPT, CNSP, CAP, and CRTA. Specializing in fortifying security across diverse sectors including Banking, Finance, Ecommerce, and Healthcare.

About Me

ryuukhagetsu
5+ Years Experience

My name is Septio Noerdiansyah, known online as RyuuKhagetsu — a passionate cybersecurity professional with over 5 years of experience in penetration testing, vulnerability assessment, and red teaming. My journey began as a CTF enthusiast while studying Computer Science, and quickly evolved into a professional career in security.

My mission is to help organizations strengthen their security posture by identifying and mitigating vulnerabilities before they can be exploited by malicious actors. I believe in responsible disclosure and ethical hacking principles.

Certifications

  • Certified Ethical Hacker (CEH) v13
  • INE eLearnSecurity Junior Penetration Tester (eJPT)
  • Cyberwarfare Labs Certified Red Team Analyst (CRTA)
  • SecOps Group Certified Network Security Practitioner (CNSP)
  • Secops Group Certified AppSec Practitioner (CAP)
  • Cyberwarfare Labs Certified Process Injection Analyst (CPIA)
  • Cybersecurity Awareness Professional Certification (CAPC)
  • OSCP (In Progress)

Favorite Tools

  • Burp Suite Pro
  • Metasploit Framework
  • Frida & Ghidra
  • Wireshark & Nmap
  • Cobalt Strike & Covenant

Skills & Expertise

Penetration Testing

Expert in black/gray box penetration testing across web applications, networks, mobile apps, and cloud infrastructure.

Bug Hunting

Experienced bug bounty hunter with a track record of finding critical vulnerabilities across major platforms.

Reverse Engineering

Proficient in analyzing compiled binaries, identifying vulnerabilities, and creating custom exploits.

Network Security

Deep understanding of network protocols, traffic analysis, and infrastructure hardening techniques.

Mobile Security

Specialized in Android app assessments, API security, and mobile app architecture reviews.

Web Security

Expert in OWASP Top 10 vulnerabilities including XSS, SQLi, CSRF, and business logic flaws.

My Projects

A collection of tools and applications I've built

Security Automation Reconnaissance

LazyScan - Automated Recon & Vulnerability Scanner

LazyScan is an automated reconnaissance & vulnerability scanner that combines various tools for comprehensive scanning with real-time Telegram notifications.

Security Compliance Static Analysis

seccomp-cli

A security compliance tool that performs static analysis on Android APKs and passive security checks on web applications. All findings are automatically mapped to ISO/IEC 27001:2022 controls with CVSS 4.0 scoring for compliance reporting.

Bug Bounty Subdomain Enumeration

Subdomain Enumerator

Advanced subdomain enumeration tool designed for penetration testers and security researchers. Combines multiple reconnaissance techniques with intelligent analysis to discover and analyze subdomains with actionable pentesting insights.

Web Development Landing Page Bootstrap

Shirai Education

A simple landing page for a tutoring service called Shirai Education, built with HTML, CSS, JavaScript, and Bootstrap.

Web Development Dashboard Bootstrap

Akbar Photocopy

A landing page and simple dashboard website for a photocopy service, built with HTML, CSS, JavaScript, and Bootstrap.

Hall of Fame

Companies and platforms that have recognized my security contributions

My Journey

Work experiences and another activity.

Work Experience

PT. Intikom Berlian Mustika

Cyber Security Engineer

Feb 2024 - Jan 2026 • 2 yr

Jakarta, Indonesia • Full-time

Specialized in enterprise cybersecurity engineering, implementing robust security infrastructure and conducting comprehensive security assessments.

  • Designed and implemented enterprise-level security architectures
  • Conducted regular penetration testing and vulnerability assessments
  • Developed security policies and incident response procedures
  • Collaborated with development teams to integrate security best practices
Security Architecture Penetration Testing Incident Response Enterprise Security

PT Linuxhackingid Cyber Security

Vulnerability Assessment & Penetration Testing – API Security Testing (cariilmu.co.id)

Mar 2025 - Apr 2025 • Project-based

Jakarta, Indonesia • Remote

Participated as a penetration testing team member in a Vulnerability Assessment and Penetration Testing (VAPT) engagement conducted by Linuxhackingid, focusing on API security testing for the cariilmu.co.id platform.

  • Performed API security testing with emphasis on OTP-related endpoints
  • Identified a race condition vulnerability caused by dynamically adjustable OTP rate limiting
  • Demonstrated that parallel request manipulation could trigger multiple OTP deliveries and extend subsequent cooldown periods
  • Evaluated potential impact including OTP spam, light denial-of-service (DoS), and increased brute-force risk
  • Reported findings with clear reproduction steps and mitigation recommendations following responsible disclosure practices
Penetration Testing API Security Race Condition Vulnerability Assessment

PT Pos Indonesia

VAPT Consultant - Enterprise Systems

Feb 2025 - Apr 2025

Jakarta, Indonesia • Contract

Conducting comprehensive vulnerability assessment and penetration testing on critical financial systems for Indonesia's national postal service.

  • Performed VAPT on PosPay mobile application and Core Giro System
  • Identified critical vulnerabilities in authentication and authorization mechanisms
  • Assessed Remittance System security and data protection controls
  • Delivered detailed security reports with remediation recommendations
Enterprise VAPT Financial Systems Mobile Security Data Protection

PT Multidaya Dinamika

Senior Web Application Penetration Tester

Jan 2025 - Jun 2025

Jakarta, Indonesia • Contract

Executed advanced penetration testing on staging web applications, successfully achieving server access through critical vulnerability exploitation.

  • Identified high to critical risk vulnerabilities enabling server compromise
  • Conducted impact analysis and validated exploit chains
  • Performed bypass testing and coordinated retesting with internal teams
  • Provided strategic security recommendations and mitigation strategies
Advanced Web Pentesting Server Compromise Exploit Development Bypass Techniques

Bank Raya

Mobile Application Security Specialist

Jan 2025 - Present • 1 yr 6 mos

Jakarta, Indonesia • Contract

Specialized penetration testing of Visa product features within mobile banking application, focusing on payment security and user data protection.

  • Conducted security assessment of Visa payment integration features
  • Identified exploitable vulnerabilities affecting user security
  • Analyzed Flutter/Dart mobile application security architecture
  • Delivered comprehensive remediation guidance to development teams
Mobile Banking Security Payment Systems Flutter/Dart Visa Integration

Universitas Pamulang

University Systems Security Auditor

Nov 2023 - Present

Jakarta, Indonesia • Long-term Contract

Comprehensive security assessment of university IT infrastructure, covering both production and pre-launch educational systems.

  • Performed VAPT across all IT-related subdomains and applications
  • Assessed security of academic management systems and student portals
  • Conducted pre-launch security testing for new educational platforms
  • Established ongoing security monitoring and assessment protocols
Educational Systems Infrastructure Security Pre-launch Testing Academic Platforms

Universitas Pandanaran Semarang

Academic Information Systems Penetration Tester

Mar 2025 - Apr 2025

Semarang, Indonesia • Project-based

Security assessment of academic information systems with focus on student data protection and system integrity.

  • Conducted penetration testing on academic information system subdomains
  • Identified critical vulnerabilities affecting active student data
  • Performed manual testing and comprehensive vulnerability documentation
  • Coordinated with university IT team for responsible disclosure and mitigation
Academic Systems Student Data Security Manual Testing Responsible Disclosure

PT Linuxhackingid Cyber Security

Lead IT Instructor & Offensive Security

Oct 2025 - Present

Jakarta, Indonesia • Remote

Leading offensive security initiatives and overseeing advanced cybersecurity training programs.

  • Designed and led offensive security training focused on real-world attack simulations
  • Supervised penetration testing labs covering web, network, and infrastructure security
  • Mentored instructors and analysts in advanced exploitation techniques
  • Reviewed and validated security assessment methodologies and reports
Offensive Security Penetration Testing Red Teaming Leadership

PT Linuxhackingid Cyber Security

IT Instructor & Offensive Security

Mar 2024 - Oct 2025 • 1 yr 7 mos

Jakarta, Indonesia • Remote

Leading cybersecurity education and conducting advanced security assessments including network penetration testing and vulnerability analysis.

  • Developed comprehensive cybersecurity curriculum and training materials
  • Conducted network penetration testing to evaluate password strength and router security
  • Performed security assessments to identify network vulnerabilities and unauthorized access points
  • Delivered live cybersecurity training sessions and workshops
Network Security Penetration Testing Training & Education Bug Bounty

Intigriti

Penetration Tester

Nov 2022 - Present • 2 yrs 7 mos

Brussels, Belgium • Freelance

Active researcher on European bug bounty platform, focusing on advanced reconnaissance techniques and penetration testing methodologies.

  • Conducted comprehensive security assessments for European enterprises
  • Developed innovative reconnaissance methodologies and tools
  • Contributed to platform community through knowledge sharing
  • Maintained high-quality vulnerability reports with detailed remediation guidance
Advanced Reconnaissance European Compliance Tool Development Technical Writing

Bugcrowd

Penetration Tester

Feb 2022 - Present • 3 yrs 4 mos

San Francisco, CA • Freelance

Active bug bounty hunter on one of the world's leading crowdsourced cybersecurity platforms, identifying critical vulnerabilities for global enterprises.

  • Discovered and reported 100+ vulnerabilities across web applications
  • Specialized in reconnaissance, penetration testing, and vulnerability research
  • Maintained consistent top researcher ranking in multiple programs
  • Contributed to securing Fortune 500 companies through responsible disclosure
Bug Bounty Reconnaissance Web Application Security Responsible Disclosure

HackerOne

Penetration Tester

Aug 2021 - Present • 3 yrs 10 mos

Remote • Freelance

Long-standing member of the HackerOne community, conducting security research and vulnerability assessments for major technology companies.

  • Participated in 50+ private and public bug bounty programs
  • Achieved recognition in multiple Hall of Fame programs
  • Mentored junior researchers in responsible vulnerability disclosure
  • Specialized in complex attack chains and business logic flaws
Vulnerability Research Security Testing Ethical Hacking Community Mentoring

Activities & Events

Personal Project

LazyScan

Automated Recon & Vulnerability Scanner

2025 Sep - Present

Open Source • GitHub

Developed LazyScan, an automated reconnaissance and vulnerability scanning framework designed to support penetration testing and bug bounty activities by integrating multiple popular security tools.

  • Implemented subdomain discovery and live host enumeration using Subfinder and Httpx
  • Automated URL discovery and classification, including JavaScript files and parameterized endpoints
  • Integrated Nuclei for vulnerability scanning (general templates, JavaScript, and DAST scans)
  • Built real-time Telegram notifications for scan progress and vulnerability findings
  • Designed structured and readable output to streamline analysis and reporting

The project focuses on efficiency, automation, and operational visibility to accelerate recon workflows and improve testing productivity.

🔗 Repository: github.com/ryuukhagetsu/lazyscan

Python Automation Reconnaissance Vulnerability Scanning Bug Bounty
Personal Project

Subdomain Enumerator

Advanced Reconnaissance Tool

2025 Jul - Present

Open Source • GitHub

Developed an advanced subdomain enumeration tool designed to support penetration testers and security researchers during the reconnaissance and information gathering phase.

  • Aggregated data from 8+ passive reconnaissance sources including Certificate Transparency, ThreatCrowd, DNSDumpster, and Wayback Machine
  • Implemented high-performance DNS brute-force enumeration using customizable wordlists
  • Performed technology fingerprinting for 20+ stacks including CMS, frameworks, and web servers
  • Analyzed security headers, identified admin panels, and detected staging or development environments
  • Provided risk scoring and actionable exploitation recommendations to support decision-making
  • Generated scan results in multiple formats (interactive HTML, TXT, CSV, JSON) for reporting and documentation
  • Optimized for multi-threaded execution with cross-platform support (Windows, Linux, macOS)

The tool emphasizes actionable intelligence by transforming raw reconnaissance data into structured, prioritized security insights.

🔗 Repository: github.com/ryuukhagetsu/subdomain-enumerator

Python Penetration Testing Reconnaissance Automation Information Gathering
Personal Project

Seccomp-CLI

Security Compliance Tool

2025 Sep - Present

Open Source • GitHub

seccomp-cli is a security compliance tool that performs static analysis on Android APKs and passive security checks on web applications. All findings are automatically mapped to ISO/IEC 27001:2022 controls with CVSS 4.0 scoring for compliance reporting.

  • Android Static Analysis: Manifest checks, cryptographic analysis, WebView security
  • Web Security Scanning: HTTP headers, TLS/SSL, CORS configuration
  • Import from External Tools: MobSF and Nuclei report normalization
  • CVSS 4.0 Scoring: Automatic vulnerability scoring per FIRST specification
  • ISO 27001 Mapping: Comprehensive mapping to 70+ Annex A controls
  • Risk Assessment: Severity scoring and compliance grading
  • Multiple Output Formats: JSON, CSV, Markdown, HTML

🔗 Repository: github.com/ryuukhagetsu/seccomp-cli

Python Security Compliance Android Security ISO 27001 CVSS
Personal Project

Shirai Education

Educational Platform

2024 - Present

Open Source • GitHub

Developed an educational platform designed to provide learning resources and interactive content for students and educators.

  • Built responsive web interface with modern UI/UX principles
  • Implemented interactive learning modules and content management
  • Designed user-friendly navigation and accessible layout

🔗 Repository: github.com/ryuukhagetsu/shirai_education

Web Development Education UI/UX
Personal Project

Akbar Photocopy

Business Management Application

2024 - Present

Open Source • GitHub

Developed a business management application for a photocopy shop, providing features for transaction tracking, inventory management, and sales reporting.

  • Implemented transaction management and point-of-sale functionality
  • Built inventory tracking and stock management system
  • Designed sales reporting and business analytics dashboard
  • Created user-friendly interface for daily business operations

🔗 Repository: github.com/ryuukhagetsu/akbar_photocopy

Web Development Business Application Inventory Management
Speaker

Universitas Pamulang

The Future of Cybersecurity: Emerging Trends and Predictions

November 2024

Universitas Pamulang, Jakarta

Delivered keynote presentation on emerging cybersecurity trends and future threat predictions at National Seminar, featuring live cyber attack demonstrations.

  • Presented cutting-edge cybersecurity trends and threat landscape analysis
  • Conducted live cyber attack demonstrations on prepared targets
  • Enhanced audience awareness of evolving cyber threats and countermeasures
  • Engaged with 200+ students and faculty members
Public Speaking Live Demonstrations Threat Analysis Education
Guest Speaker

Universitas Gunadarma

Cybersecurity Career Opportunities and Future Challenges

Oct 2024 - Nov 2024

Community Cybersecurity Universitas Gunadarma (CCUG)

Invited speaker for cybersecurity career webinar series, sharing insights on industry opportunities and challenges facing the next generation of cybersecurity professionals.

  • Discussed current cybersecurity career landscape and growth opportunities
  • Shared practical insights from bug bounty and penetration testing experience
  • Provided guidance on skill development and certification pathways
  • Mentored aspiring cybersecurity professionals during Q&A sessions
Career Guidance Industry Insights Mentoring Professional Development
Recognition

Government Recognition Programs

Multiple Certificate of Appreciation Awards

2021 - 2024

Indonesia • Various Locations

Received multiple certificates of appreciation from government agencies and prestigious institutions for contributions to cybersecurity awareness and vulnerability research.

  • Badan Siber dan Sandi Negara (BSSN) - National Cyber Security Agency
  • Kementerian Komunikasi dan Informatika (Kominfo) - Ministry of Communication
  • CSIRT Cimahi - Computer Security Incident Response Team
  • Transjakarta Hall of Fame - White Hacker Recognition
Government Recognition White Hat Hacking Public Service National Security
Academic Recognition

University Appreciation Programs

Multiple University Recognition Awards

2021 - Present

Indonesia • Academic Institutions

Honored by multiple prestigious universities for cybersecurity contributions and educational support through vulnerability research and responsible disclosure.

  • Universitas Brawijaya - Cybersecurity Research Contribution
  • Universitas Bina Sarana Informatika (BSI) - Multiple recognitions
  • Universitas Telkom - Bug Bounty Hall of Fame
  • Educational platform partnerships and mentoring programs
Academic Collaboration Research Contribution Educational Support Knowledge Transfer
Professional Development

Continuous Learning & Certification

Advanced Cybersecurity Certifications

2021 - Present

Global • Online & On-site

Continuously advancing professional expertise through industry-leading certifications and specialized training programs.

  • eLearnSecurity Junior Penetration Tester (eJPT)
  • EC-Council Certified Ethical Hacker (CEH V13)
  • CyberWarFare Labs Certified Red Team Analyst (CRTA)
  • The SecOps Group Certified AppSec Practitioner (CAP)
  • The SecOps Group Certified Network Security Practitioner (CNSP)
  • CyberWarFare Labs Certified Process Injection Analyst (CPIA)
  • Certified Computer Forensics Analyst (CCFA)
  • Cybersecurity Awareness Professional Certification (CAPC)
  • Scrum Foundation Professional Certification (SFPC)
CEH V13 Red Team Operations Digital Forensics Continuous Learning

Certifications & Achievements

Professional certifications, achievements, and recognition in cybersecurity field

Certificate

Latest Articles

Sharing knowledge through detailed write-ups and tutorials

Out-of-Band SQL Injection
07 Dec
SQL Injection OOB SQLi

Breaking Past 403: A Deep Dive into Out-of-Band SQL Injection Discovery

Discovered Out-of-Band SQL Injection on MSSQL server, bypassing 403 restrictions through directory fuzzing and payload crafting.

Read More
Broken Access Control
19 Jul
Broken Access Control SQL Injection

Abusing Broken Access Control and SQL Injection in the Wild

Discovered Broken Access Control exposing admin dashboard with full CRUD functionality, chained with SQL Injection vulnerability.

Read More
Web Security
18 Mar
Web Security Writeup

How Do I Get Root Access on a Linux Server

Critical authentication flaw in a university system's security. Responsibly disclosed, unexploited, and reported.

Read More