System design & web development

Full-stack architecture and development — clean code, scalable design, performance first. Built WorldLanguagesTH end to end: UI/UX design, development, and production deployment for a Thai client.
I design systems and secure them.
Founder of CoreFlareSec — system design, web development, and offensive security. ICS/OT, red team, and the tools in between.
I design and build systems, then attack them before anyone else does. CoreFlareSec is small on purpose — penetration testing for SME and startups across web applications, networks, and ICS/OT, plus custom CTF and security labs and platforms built on Cloudflare. Every engagement ends with a report your team can act on, not a scanner dump. Creator of ICSforge and modpao, open-source ICS/SCADA pentest tooling.
A working record of what I actually do — the platforms I ship, the tools I write, the labs I clear, and the credentials behind them. No filler.
Available for projects. Based in Bangkok, working across Southeast Asia.
Start a conversation
Full-stack architecture and development — clean code, scalable design, performance first. Built WorldLanguagesTH end to end: UI/UX design, development, and production deployment for a Thai client.

ISC2 CC, Jr Penetration Tester (PT1), and kWAPTA certified. Web application pentesting — XSS, IDOR, authentication flaws — plus network scanning, privilege escalation, and vulnerability reporting teams can actually act on.
__ __ ___ ___ ___ ___ ___ | \/ |/ _ \| \| _ \/ _ \ / _ \ m o d p a o | |\/| | (_) | |) | _/ (_) | (_) | modbus pentest console |_| |_|\___/|___/|_| \___/ \___/ multi-session . resume . tab authorized testing only type help
An interactive console for authorized assessment of Modbus TCP devices — PLCs, RTUs, and ICS/SCADA infrastructure. Built out of what the Alchemy Pro Lab actually demanded: read and decode coils, discrete inputs, and registers (f32, ASCII, hex, int, time); profile devices and sweep the full 0–65535 range with auto-chunking and early stop; write through FC05/06/15/16 and FC23; build raw Modbus-RTU frames offline; discover hosts across IP ranges and CIDR blocks; and keep multi-session autosave, audit trails, and register tagging so the engagement stays documented.
A full red team simulation against a hardened Active Directory estate — phishing for the initial foothold, evading endpoint protections, then persisting and moving laterally all the way to domain compromise.
A multi-network penetration test built around chaining web application flaws into footholds, then developing exploits and escalating across the estate one host at a time.
An Active Directory–heavy lab centred on relay attacks, password cracking, and crossing forest trust boundaries — pivoting deeper into the network with every set of credentials recovered.
An IT-to-OT attack path: breach the corporate network, tunnel into the industrial segment, then work directly against the process layer — Modbus traffic analysis, Structured Text PLC code review, and dynamic analysis of ladder logic.
Offered by Thailand's National Cyber Security Agency (NCSA) through the Cisco Networking Academy program — the full ethical hacking lifecycle from reconnaissance and scanning through exploitation, post-exploitation, and reporting.

Hands-on web application pentesting certification from Knight Squad Academy — reconnaissance and application discovery, HTTP fundamentals, client-side injection (XSS), authorization flaws (IDOR), authentication weaknesses, and file/path handling. Passed with Merit.

Practical penetration testing certification from TryHackMe — passing an exam that tests the knowledge and practical skills required to work as a junior penetration tester: web application security, network pentesting, privilege escalation, Active Directory attacks, and professional report writing.

Awarded by the ISC2 Board of Directors after meeting the certification requirements, adopting the ISC2 Code of Ethics, and passing the competency examination — covering security principles, access controls, network security, and security operations.