Security Practitioner & Continuous Learner
I'm Nobex Wahengbam — a PJPT-certified penetration tester specialising in
offensive security and Active Directory exploitation. My background in enterprise
IT gives me a real-world understanding of the environments I attack — the same
AD structures, GPOs, and remote access configurations found in corporate networks.
My Active Directory home lab (BATMAN.local) is a fully virtualized
Windows domain environment where I've executed 17 distinct attack techniques —
from LLMNR poisoning and SMB relay through Kerberoasting, credential dumping,
Golden Ticket persistence, and critical CVE exploitation — every step mapped
to MITRE ATT&CK.
I've also built a comprehensive web application VAPT lab documenting 32 vulnerability findings
across OWASP Top 10, covering SQL injection, XSS, authentication bypasses, and API security —
tested against DVWA and PortSwigger Web Security Academy with full Burp Suite evidence and CVSS scoring.
Beyond these labs, I sharpen offensive skills through machine walkthroughs on
HackTheBox and TCM Security platforms and CTF competitions, documenting each
with full methodology, exploitation steps, and vulnerability analysis.