skip to content

Radwan Alrashdi · Oman

RONIN

Network security engineer with an offensive lean. I move between offense, defense and infrastructure — more of a DevOps guy, in a twisted way.

Whatever's in front of me gets built, fixed, or broken until it works.

浪人·rōnin — the masterless one

必殺·hissatsu — bringing certain death; a deadly, fatal blow

02/Section — Arsenal & Disciplines

Arsenal & Disciplines

Combat-ready tooling, offensive disciplines, and hard foundation. Curated to what I actually wield in the wild — zero fluff.

Primary Weapons · Quick GlanceCore Stack
[WEB SEC]

Burp Suite

Target inspection & web pentesting

[EXPLOIT]

Metasploit

Exploitation & payload delivery

[RECON]

Nmap

Network surface & port auditing

[IDENTITY]

Active Directory

Domain enumeration & priv-esc

[PACKETS]

Wireshark

Deep packet & traffic inspection

[AUTOMATION]

Python & Bash

Custom tooling & exploit scripts

01 // OFFENSEstrike capabilities & techniques

Offensive Operations

Targeted reconnaissance, web application exploitation, and enterprise privilege escalation.

  • Web Application Pentesting

    OWASP Top 10 · SQLi · IDOR · Auth bypass

  • Active Directory Exploitation

    Kerberoasting · BloodHound paths · Priv-esc

  • Network Exploitation

    Vulnerability validation · Metasploit · Lateral move

  • Attack Surface Mapping

    Nmap · Subdomain discovery · Service profiling

stack:Burp SuiteMetasploitNmapActive DirectoryBloodHound
02 // FOUNDATIONprotocols & internal mechanics

Systems & Foundation

Deep protocol mechanics, Linux internals, and custom security automation.

  • Network & Packet Analysis

    Wireshark · TCP/IP · DNS · HTTP/S wire level

  • Security Tooling & Automation

    Python & Bash custom exploit / audit scripts

  • Operating Systems & Hardening

    Kali Linux · Windows Server · Identity infra

  • Vulnerability Assessment

    Exposure triage · IOC analysis · Defensive posture

stack:WiresharkKali LinuxPythonBashTCP/IP
03 // PAPER TRAILcertifications & formal degree

Verified Credentials

Hands-on practical examinations and formal cybersecurity degree.

  • eJPTVERIFIED

    Junior Penetration Tester · INE Security

  • ICCAVERIFIED

    INE Certified Cloud Associate · INE Security

  • Network SecurityVERIFIED

    Cisco Networking Academy

  • BSc Cyber & Information SecurityDEGREE

    University of Technology and Applied Sciences

stack:INE-eJPTINE-ICCACisco-NetSecUTAS-BSc

03/Section — The Path

The Path

No fixed master, no fixed lane. Each stop added a discipline; none of them narrowed me.

  1. 01

    Co-founder

    UTAS IT Society

    Got students building things instead of only studying them — events, workshops, momentum.

  2. 02

    IT Technician Trainee

    UTAS Ibra

    Helpdesk, hardware, Windows reinstalls — including the ones I caused myself. Everything breaking was the real curriculum.

  3. 03

    Cybersecurity Intern

    Insight Information Security

    Offensive security as a job, not a hobby — breaking things with permission and paperwork.

  4. 04

    Freelance Cybersecurity Specialist

    Freelancecurrent

    Independent penetration testing, security assessments, and infrastructure hardening for clients. Operating solo in the wild — uncovering security blindspots and locking down systems without corporate red tape.

04/Section — The BOYS CAVE

The BOYS CAVE

My homelab — built and run for me and the boys. Privacy by default, independence from big tech, and a place to break things on my own terms. Below is the map of the real architecture; hover anything.

the outside

Twingateadmin
ZeroTiergaming mesh
Cloudflarepublic · zero trust
NetBirdtesting
Local LANhome
Tailscalebanned by the government

OPNsense

firewall · old machine

The second, older machine — reborn as the firewall. Everything answers to it first.

THE CORE

the server

The server. The cave everything else lives in — storage, compute, and 19 reasons to keep patching. What it actually runs is between me and it.

Wazuh SIEM

watching

Wazuh in a VM, watching the whole stack. Quiet. Taking notes.

nginx-proxy-manager

switchboard

The switchboard — internal traffic routes through here before it reaches anything.

inside the cave

MEDIA & STREAMING×2

jellyfinfladder

GAME WORLDS×3

palworldrunescapeterraria

THE FETCHERS×3

downloadermetubeqbittorrent

STORAGE & DOCS×2

cloudrevestirling-pdf

THE FORGE×2

giteagitea-act-runner

GATES & GUARD×4

adguard-homecloudflaredtwingatezerotier

VAULT & CONTROL×2

vaultwardenarcane

A hand-authored map of the real architecture — static data, no live status, nothing on this page talks to the cave.

05/Section — Field Record

Field Record

The work that proves the adjectives — what it is, my role in it, what it's built with, and the part that's genuinely impressive. No leadership theater; I'm consistently the hands-on builder.

R-01

SOC Lab

A free-tool SOC lab at my university, built so students learn real SOC work — live traffic, real alerts, zero license keys.

Sole builder and operator — hardware, isolated network, tooling, and an environment that fights back.

built withisolated networkspare hardwareFOSS security stack

Students get blue-team reps on something real — not slides.

R-02

Alts

My own diagram-automation tool for the server. The animated map in The BOYS CAVE is exactly the kind of artifact it keeps honest — infrastructure gets checked against the diagram, not memory.

Designer and builder. Actively being improved, never finished.

built withsolo projectshaped to my own infrastructure

I built the tool instead of maintaining the drawing by hand.

R-03

ibra-ctf

A student CTF competition, co-founded from nothing and run on gzCTF infrastructure. I keep the platform and the operations behind it running.

Co-founder, platform operator, workshop runner.

built withgzCTFcontainerized challenge infra

15+ workshops delivered. 300+ students brought through the gates.

brief mentions

CE-Nexus · reverse engineering

Game modding and RE work — making software do what it wasn't meant to.

06/Section — Trophies

Trophies

The record, kept clean. Entered some, hosted one — the numbers do the talking.

HackTheBox University CTF 2024

[entered]

21 of 49 challenges solved — web, binary exploitation, cryptography, forensics.

354th / 1,128Dec 2024

CYTHON 2024

[entered]

UTAS national final round.

11th nationally2024

ISACA Muscat Chapter

[entered]

Community Day Quiz.

1st placeOct 2024

ibra-ctf

[hosted]

The competition itself — full story in Field Record.

co-founder & operatorongoing

07/Section — Off Duty

Off Duty

The rest of the desk.

games

  • Titanfall 2
  • Bioshock
  • Persona series
  • The Witcher 3
  • Cyberpunk 2077
  • Wuthering Waves
  • Metaphor: ReFantazio
  • Assassin's Creed (through Syndicate)

…plus a standing weakness for indie games.

anime · manga

  • Shaman King
  • Re:Zero
  • Steins;Gate
  • Hunter × Hunter
  • Code Geass
  • 86
  • Yahari Ore no Seishun Love Comedy wa Machigatteiru
  • Mob Psycho 100
  • To Be Hero X
  • Lord of Mysteries

I regret nothing. I merely acknowledge what we lost.

08/Section — Dispatches

Dispatches

Writeups — CTF solutions, teardown notes, lab mishaps worth sharing. Every dispatch opens in its own window; read it without losing your place.

09/Section — Contact

Contact

If this is interesting to you, here's where to find me. No forms, no funnels.

gitgithub.com/RAD50

signed

必殺 — hissatsu — bringing certain death; the decisive blow. Every dispatch carries it.