GhostScan
PublicRed-team recon CLI: subdomain enumeration, HTTP security-header auditing and concurrent TCP port scanning, in a Rich terminal UI.
I'm a cybersecurity analyst with hands-on experience across threat intelligence, red-team adversary emulation, and SOC operations. At Kaiju Cybrsec I engineer an end-to-end threat-intelligence pipeline on OpenCTI, Wazuh and SIEM tooling, run red-team engagements for client cyber drills, and help build an in-house agentic-AI platform for automated vulnerability discovery.
Previously I worked as a SOC Analyst at CyberProof (Spain, remote) and a Cybersecurity Intern at Telekom Malaysia's Group Information Security. I hold multiple industry certifications and graduated on the Dean's List with a B.Sc. in Computer Science — Artificial Intelligence (Honours).
Kaiju Cybrsec Sdn Bhd · Kuala Lumpur, Malaysia
CyberProof · Spain (Remote)
Telekom Malaysia Berhad (TM) — Group Information Security · Cyberjaya, Malaysia
A broad cross-section — offensive tooling, SOC/IR resources, full-stack products and research. Public repositories link to code; private, client and employer work is described at a high level only.
Red-team recon CLI: subdomain enumeration, HTTP security-header auditing and concurrent TCP port scanning, in a Rich terminal UI.
Curated pentest command references: enumeration, Linux/Windows privilege escalation, Active Directory, web exploitation and post-exploitation.
Seven TryHackMe walkthroughs documenting a repeatable methodology across Linux and Windows boxes — enumeration, exploitation, privilege escalation.
Ten incident-response playbooks (ransomware, DDoS, APT, data theft, privilege escalation and more) structured on the NIST SP 800-61 lifecycle and mapped to MITRE ATT&CK.
Full-stack platform for running live cyber-incident tabletop exercises — scenario authoring, real-time injects, decision scoring and after-action reporting.
Game-master co-pilot for running Backdoors & Breaches IR tabletops — composes turn-by-turn narrative and automates the rules, with optional AI-generated prose. A personal learning tool built on BHIS / Antisyphon's game.
Experimental AI red-team assistant: an LLM agent that helps plan and organise offensive-security tooling across the MITRE ATT&CK lifecycle, to speed up authorised adversary-emulation work.
A modernised revision of an earlier computer-vision advertising project: estimates viewer age, gender and style (InsightFace, YOLO11, CLIP) to serve targeted ads — consent-first, with a hardened Flask API.
Automated daily equities engine on the Moomoo OpenAPI (paper trading) with a multi-layer risk engine, compliance screening, a news-sentiment gate and a SQLite audit journal, plus a walk-forward backtesting harness.
Zero-config TypeScript CLI that scans codebases for TODO / FIXME / HACK / NOTE comments across 15+ languages, with table, JSON and Markdown reports and CI-ready exit codes.
Research prototype designed to help bystanders find the nearest defibrillator and alert nearby trained rescuers during cardiac arrest (notification delivery in progress) — a 999/MERS companion, not a certified device. Row-level security on every table, with PostGIS spatial queries.
Multi-tenant SaaS that turns donations into a live play-together queue: webhook ingestion, row-level security, a streamer dashboard, OBS overlay and seat-metered billing. Co-built with a small team.
Mobile-first concept PWA where trusted helpers assist with digital tasks under task-scoped permissions, owner approval, risk-tiered actions, audit logging and step-up identity verification.
Co-developed real-time multiplayer card game for 2–8 players: RLS-protected hidden hands, race-safe SECURITY DEFINER RPCs with row locking, and anonymous auth.
Config-driven platform for digital wedding invitations with swappable themes, RSVP and a wishes wall, and token-gated host dashboards — a shared multi-tenant backend that keeps each event's data isolated behind controlled functions.
Bilingual React booking site for a live homestay business: an availability calendar and booking requests for guests, plus an auth-protected admin panel secured with row-level security.
Responsive marketing site for a cybersecurity services company (SOC, incident response, VAPT, forensics), built with the Next.js App Router, Framer Motion animations and dark/light theming.
Built a video authentication system to prevent unauthorised media access; hardened and optimised the code in collaboration with CyberSecurity Malaysia.
Real-time computer-vision system for age and gender detection using Python, OpenCV, Flask and PyTorch; deployed on edge devices for low-latency inference.
Full-stack inventory web application with secure user authentication, built with HTML, CSS, JavaScript, PHP and MySQL.
Universiti Kebangsaan Malaysia (UKM)
Dean's List — Semesters 1, 2, 5 & 7
Penang Matriculation College
Happy to connect about threat intelligence, red teaming and SOC / incident response. The fastest way to reach me is email.