Atipong Kankang

I design systems and secure them.

Founder of CoreFlareSec — system design, web development, and offensive security. ICS/OT, red team, and the tools in between.

ISC2 CC · PT1 · kWAPTA · Ethical Hacker — plus four HTB Pro Labs cleared in July 2026.

4 certs · 4× HTB Pro Labs

See my work
Secure
by design

I design and build systems, then attack them before anyone else does. CoreFlareSec is small on purpose — penetration testing for SME and startups across web applications, networks, and ICS/OT, plus custom CTF and security labs and platforms built on Cloudflare. Every engagement ends with a report your team can act on, not a scanner dump. Creator of ICSforge and modpao, open-source ICS/SCADA pentest tooling.

Everything here I built, broke, or earned

A working record of what I actually do — the platforms I ship, the tools I write, the labs I clear, and the credentials behind them. No filler.

Open source
HTB Pro Labs
Certifications

Available for projects. Based in Bangkok, working across Southeast Asia.

Start a conversation

System design & web development

WorldLanguagesTH platform

Full-stack architecture and development — clean code, scalable design, performance first. Built WorldLanguagesTH end to end: UI/UX design, development, and production deployment for a Thai client.

HTML/CSS/JSPythonCloudflare WorkersD1 · KV · R2

Cybersecurity & pentest

Security tooling

ISC2 CC, Jr Penetration Tester (PT1), and kWAPTA certified. Web application pentesting — XSS, IDOR, authentication flaws — plus network scanning, privilege escalation, and vulnerability reporting teams can actually act on.

XSSIDORReconActive DirectoryReporting

modpao — Modbus / OT pentest console

python3 modpao.py
   __  __  ___  ___  ___  ___   ___
  |  \/  |/ _ \|   \| _ \/ _ \ / _ \   m o d p a o
  | |\/| | (_) | |) |  _/ (_) | (_) |  modbus pentest console
  |_|  |_|\___/|___/|_|  \___/ \___/   multi-session . resume . tab
   authorized testing only   type help

An interactive console for authorized assessment of Modbus TCP devices — PLCs, RTUs, and ICS/SCADA infrastructure. Built out of what the Alchemy Pro Lab actually demanded: read and decode coils, discrete inputs, and registers (f32, ASCII, hex, int, time); profile devices and sweep the full 0–65535 range with auto-chunking and early stop; write through FC05/06/15/16 and FC23; build raw Modbus-RTU frames offline; discover hosts across IP ranges and CIDR blocks; and keep multi-session autosave, audit trails, and register tagging so the engagement stays documented.

Language: Python 3.8+
License: MIT
Protocol: Modbus TCP · RTU frames
View on GitHub →
Interactive consoleRegister scan & decodeFull-range sweepFC05/06/15/16/23Auth schemesLive monitoring & alertsRTU frame builderNetwork discoverySession autosave & audit

HTB Pro Labs: Rastalabs

Hack The BoxHTBCERT-7CB0275136
Pro Labs
RASTALABS
Certificate of Completion
27 Jul 202640 hours · 40 CPE

A full red team simulation against a hardened Active Directory estate — phishing for the initial foothold, evading endpoint protections, then persisting and moving laterally all the way to domain compromise.

Issuer: Hack The Box
Lab Master: Daniel Duggan
Completed: 27 Jul 2026
AD enumeration & exploitationEvading endpoint protectionsExploit developmentLateral movementLocal privilege escalationPersistencePhishingSituational awareness

HTB Pro Labs: Dante

Hack The BoxHTBCERT-BC9BBEA59F
Pro Labs
DANTE
Certificate of Completion
22 Jul 202640 hours · 40 CPE

A multi-network penetration test built around chaining web application flaws into footholds, then developing exploits and escalating across the estate one host at a time.

Issuer: Hack The Box
Lab Master: Shaun Whorton
Completed: 22 Jul 2026
EnumerationExploit developmentLateral movementLocal privilege escalationSituational awarenessWeb application attacks

HTB Pro Labs: Zephyr

Hack The BoxHTBCERT-E55F835D36
Pro Labs
ZEPHYR
Certificate of Completion
19 Jul 202640 hours · 40 CPE

An Active Directory–heavy lab centred on relay attacks, password cracking, and crossing forest trust boundaries — pivoting deeper into the network with every set of credentials recovered.

Issuer: Hack The Box
Lab Masters: Daniel Morris, Matthew Bach
Completed: 19 Jul 2026
Relay attacksPivotingSQL attacksPassword crackingPrivilege escalationWeb application attacksAD flawsCrossing trust boundaries

HTB Pro Labs: Alchemy

Hack The BoxHTBCERT-E23F9C5D00
Pro Labs
ALCHEMY
Certificate of Completion
09 Jul 202640 hours · 40 CPE

An IT-to-OT attack path: breach the corporate network, tunnel into the industrial segment, then work directly against the process layer — Modbus traffic analysis, Structured Text PLC code review, and dynamic analysis of ladder logic.

Issuer: Hack The Box
Lab Masters: Konstantinos S. Mokos, Ayush Sahay
Completed: 09 Jul 2026
IT & OT enumerationTunneling and pivotingModbus protocolModbus network analysisStructured Text PLC reviewLadder logic analysisWeb application attacks

Ethical Hacker

Cisco Networking AcademyNCSA · THNCA
Certificate of Completion
ETHICAL HACKER
National Cyber Security Agency
24 May 2026Atipong Kankang

Offered by Thailand's National Cyber Security Agency (NCSA) through the Cisco Networking Academy program — the full ethical hacking lifecycle from reconnaissance and scanning through exploitation, post-exploitation, and reporting.

Issuer: NCSA · Cisco Networking Academy
Instructor: AVM. Amorn Chomchoey
Completed: 24 May 2026
ReconnaissanceScanning & enumerationExploitationPost-exploitationReporting

Certified Web App Penetration Testing Apprentice (kWAPTA)

kWAPTA Badge

Hands-on web application pentesting certification from Knight Squad Academy — reconnaissance and application discovery, HTTP fundamentals, client-side injection (XSS), authorization flaws (IDOR), authentication weaknesses, and file/path handling. Passed with Merit.

Issuer: Knight Squad Academy
Issued: 21 Apr 2026
Exam version: 1.0
Credential ID: KSA-YGSRTEMF2104
Verify credential →
Passed with MeritReconHTTP fundamentalsXSSIDORAuth weaknessesFile/path handling

Jr Penetration Tester (PT1)

Jr Penetration Tester Badge

Practical penetration testing certification from TryHackMe — passing an exam that tests the knowledge and practical skills required to work as a junior penetration tester: web application security, network pentesting, privilege escalation, Active Directory attacks, and professional report writing.

Issuer: TryHackMe
Issued: 16 Apr 2026
Holder: Atipong Kankang
Verify on Credly →
Web app securityNetwork pentestPrivilege escalationActive DirectoryReporting

Certified in Cybersecurity (CC)

ISC2 CC Badge

Awarded by the ISC2 Board of Directors after meeting the certification requirements, adopting the ISC2 Code of Ethics, and passing the competency examination — covering security principles, access controls, network security, and security operations.

Issuer: ISC2
Certification no.: 1931070
Certified since: 2024
Cycle: 1 Mar 2024 – 28 Feb 2027
Verify on Credly →
ANAB accreditedSecurity principlesAccess controlsNetwork securitySecurity operations