VAPT Specialist (Vulnerability Assessment and Penetration Testing) | Web • Network • AD/Windows • Mobile • Cloud Security
🔐 Advanced vulnerability assessment & penetration testing across full attack surfaces. Focused on structured methodology, CVSS-aligned risk reporting, and secure remediation guidance. All testing conducted in authorized, isolated lab environments only.
🎓 TryHackMe: https://tryhackme.com/p/wajudev | 💼 LinkedIn: https://linkedin.com/in/olanrewaju-ayo
| Domain | Key Focus |
|---|---|
| Web App | OWASP Top 10/API Top 10, Auth bypass, IDOR, JWT, SSRF, Business Logic |
| Network | Service enumeration, CVE validation, Privilege escalation, Lateral movement |
| AD/Windows | Kerberoasting, BloodHound mapping, GPO abuse, Domain escalation paths |
| Mobile | APK reverse engineering, insecure storage, root bypass, API hooks |
| Cloud | IAM misconfig, S3 exposure, metadata SSRF, container escapes |
| Project | Description | Link |
|---|---|---|
| 🔍 AutoRecon-X | Modular recon pipeline: Nmap + Gobuster + Nuclei → structured JSON | View Repo |
| 📄 Web App Pentest Report | Professional engagement deliverable: 7 findings, CVSS v3.1, PoC, remediation | View Report |
| 🌐 VAPT Lab Portfolio | Isolated environment write-ups: AD escalation, Cloud IAM, Mobile hooks | View Labs |
- OWASP Testing Guide, PTES, NIST SP 800-115, MITRE ATT&CK
- CVSS v3.1 scoring, risk prioritization, remediation validation
- Executive + technical reporting, secure SDLC integration
📧 wajudev@gmail.com | 💼 LinkedIn | 🎓 TryHackMe
⚠️ Ethics Disclaimer: All code, reports, and demonstrations are for portfolio purposes only. Testing performed exclusively in isolated, authorized lab environments (OWASP Juice Shop, Metasploitable, TryHackMe). No production or unauthorized systems were targeted.