▸ /usr/bin/about
ahrixia
Senior Security Consultant at Swarmnetics, running comprehensive vulnerability assessments and penetration tests across web, network and cloud for 110+ clients. I own engagements end-to-end — scoping, testing, reporting and helping teams remediate real-world threats.
B.Sc. in Cyber Security from Edith Cowan University (Jan 2021). Committed to lifelong learning — certifications include OSCE3, OSCP+, OSWE, OSEP, CRTO, PNPT, KLCP, CNSP, eMAPT, PJPT, OSWP and more.
Currently serving as OffSec Ambassador for Singapore — public speaking, mentoring and technical knowledge sharing. Disclosed 15+ CVEs covering SQLi, XSS, CSRF and auth flaws in production software, helping vendors ship patches.
Part-time bug bounty hunter — reported high-severity issues in government platforms across Singapore, Malaysia and the wider region, including PII exposure and zero-click full account takeover. Off-hours you'll find me on Hack The Box / TryHackMe boot2roots and CTFs.
- 15+CVEs disclosed
- 110+clients secured
- 46+certifications
experience_
Senior Security Consultant
@ SwarmneticsPresent- ▹Delivered VAPT for 110+ clients across web, mobile, network, wireless, thick-client and cloud.
- ▹Run black-box and grey-box engagements — on-site, remote and hybrid across APAC.
- ▹Conduct firewall reviews and configuration audits to harden network posture.
- ▹Built automation for daily IT and security tasks — 40% efficiency gain.
- ▹Own client relationships end-to-end: scoping, reporting and remediation guidance.
OffSec Community Ambassador — Singapore
@ Offensive SecurityFeb 2025 — Present- ▹Represent OffSec in Singapore through public speaking and meetups.
- ▹Mentor aspiring pentesters and OSCP/OSWE candidates.
- ▹Publish technical write-ups and certification reviews.
B.Sc. Cybersecurity
@ Edith Cowan UniversityGraduated Jan 2021- ▹Bachelor's degree specializing in Cyber Security.
- ▹Goldman Sachs Engineering Virtual Program.
- ▹Cyber@ANZ Program.
▸ ./certs --verified
technical certifications
46 verified offensive-security & infrastructure certifications across web, network, mobile, cloud, AD, red team, AI/LLM and exploit dev.
- [Jun 2026]
Practical Offensive Industrial Security Essentials (POISE)
FOXGRID
- [Mar 2026]
Multi-Cloud Red Team Analyst (MCRTA)
CyberWarFare Labs
- [Mar 2026]
Certified Android Penetration Tester
MobileHackingLab
id: 664264ad43e160b89707912f
- [Feb 2026]
K8s Red Team Analyst (K8s-RTA)
CyberWarFare Labs
- [Dec 2025]
Certified API Red Team Analyst (API-RTA)
CyberWarFare Labs
- [Dec 2025]
Red Team Infra Dev (CRT-ID)
CyberWarFare Labs
- [Dec 2025]
HTB Certified Web Exploitation Specialist (CWES)
Hack The Box
- [Dec 2025]
HTB Certified Penetration Testing Specialist (CPTS)
Hack The Box
- [Nov 2025]
Web Red Team Analyst (Web-RTA)
CyberWarFare Labs
- [Sep 2025]
CVSS v4.0
FIRST
- [Aug 2025]
Certified Professional Penetration Tester (eCPPT)
INE
- [Aug 2025]
Certified Ethical White Hacker (CEWH)
CyberEd
- [Aug 2025]
Web Application Penetration Tester eXtreme (eWAPTX)
INE
- [Jul 2025]
Certified AI Security Professional (CAISP)
Practical DevSecOps
- [Jun 2025]
CVSS v3.1
FIRST
- [Feb 2025]
Certified Active Directory Pentesting eXpert (C-ADPenX)
The SecOps Group
- [Dec 2024]
Certified AppSec Pentesting eXpert (CAPenX)
The SecOps Group
- [Nov 2024]
CREST Registered Penetration Tester (CRT)
CREST
- [Nov 2024]
CREST Practitioner Security Analyst (CPSA)
CREST
- [Nov 2024]
OffSec Certified Professional+ (OSCP+)
OffSec
- [Oct 2024]
Certified Red Team Analyst (CRTA)
CyberWarFare Labs
- [Oct 2024]
Certified AppSec Pentester (CAPen)
The SecOps Group
- [Oct 2024]
Certified AppSec Practitioner (CAP)
The SecOps Group
- [Oct 2024]
OffSec Certified Expert 3 (OSCE3)
OffSec
- [Oct 2024]
OffSec Exploit Developer (OSED)
OffSec
- [Sep 2024]
Kali Linux Certified Professional (KLCP)
OffSec
- [Sep 2024]
OffSec Web Assessor (OSWA)
OffSec
- [Aug 2024]
OffSec Certified CyberCore (OSCC)
OffSec
- [May 2024]
Certified Network Security Practitioner (CNSP)
The SecOps Group
- [May 2024]
OffSec Experienced Penetration Tester (OSEP)
OffSec
id: 104062345
- [Feb 2024]
Certified Red Team Operator (CRTO)
Zero-Point Security
- [Jun 2023]
Practical Junior Penetration Tester (PJPT)
TCM Security
- [Jun 2023]
Practical Network Penetration Tester (PNPT)
TCM Security
- [May 2023]
Certified Penetration Testing Professional (CPENT)
EC-Council
id: ECC7962314850
- [Feb 2023]
Mobile Application Penetration Tester (eMAPT)
INE Security
id: 3574205
- [Nov 2022]
Offensive Security Web Expert (OSWE)
OffSec
- [Apr 2022]
Offensive Security Wireless Professional (OSWP)
OffSec
id: 49887955
- [Mar 2022]
Burp Suite Certified Practitioner (BSCP)
PortSwigger
id: 7991EF7CA8216513
- [Aug 2021]
Offensive Security Certified Professional (OSCP)
OffSec
id: 49887953
- [Nov 2021]
CREST Registered Penetration Tester (CRT)
CREST
- [Nov 2021]
CREST Practitioner Security Analyst (CPSA)
CREST
- [Feb 2021]
Junior Penetration Tester (eJPT)
INE Security
id: 7518729
- [Nov 2020]
Network+
CompTIA
- [Sep 2020]
Certified Ethical Hacker (CEH) Master ↗
EC-Council
- [Sep 2020]
Certified Ethical Hacker (CEH) Practical
EC-Council
id: ECC8296014735
- [Aug 2020]
Certified Ethical Hacker (CEH)
EC-Council
id: ECC6107584329
cve discoveries_
- 01CVE-2025-69689Improper privilege handling → Local Privilege Escalation
- 02CVE-2024-57430SQL Injection
- 03CVE-2024-57429CSRF → Privilege Escalation
- 04CVE-2024-57428Stored XSS
- 05CVE-2024-57427Reflected XSS
- 06CVE-2024-57426DLL Injection → Remote Code Execution
- 07CVE-2023-50072Stored XSS
- 08CVE-2023-45542Reflected XSS
- 09CVE-2023-44813Reflected XSS
- 10CVE-2023-44812Reflected XSS
- 11CVE-2023-44811CSRF
- 12CVE-2023-43326Reflected XSS
- 13CVE-2023-43325Reflected XSS
- 14CVE-2023-43323SSRF
- 15CVE-2023-30256Reflected XSS
▸ socket open
let's connect
Available for consultation, collaboration, or a chat about offensive security.