ENGAGEMENT REPORT // REF: YM-2026-OPS // ACTIVE

Yamashita Moleya

I identify the paths an adversary would take before they get the chance to walk them — mapping attack surfaces, chaining misconfigurations, and turning findings into fixes.
Offense in service of defense.

Findings Summary
0
Certifications
0
Projects Delivered
0
Years in the Field
Scroll to Declassify

Who Am I

The discipline of the sword, applied to the shell

Yamashita Moleya, penetration tester profile photo
CLEARANCE OPERATOR

Security First

Always Learning

Like a samurai perfecting the art of the sword, I've dedicated myself to mastering the discipline of penetration testing and offensive security.

My work is finding the vulnerabilities an adversary would find first, and closing them before that happens. Every engagement gets the same treatment: rigorous reconnaissance, disciplined exploitation, and reporting that a defender can actually act on.

Cybersecurity rewards the people who never stop training. Through hands-on labs, real engagements, and continuous certification, I've built coverage across the domains that matter most to modern organizations.

Technical Excellence

Proficient in Python, Bash, and modern security tooling

Strategic Mindset

Reasoning from both the attacker's and defender's side of the wire

Certified Professional

PNPT, PJPT, CRTA, AD-RTS, MCRTA, WEB-RTA, API-RTA, CNSP, Google Cybersecurity, CRTOM, CCEP, CCPP

Arsenal of Skills

Tools and tradecraft for modern offensive security

Network Penetration Testing

Advanced network reconnaissance, exploitation, and post-exploitation techniques

NmapMetasploitNetExec

Web Application Security

OWASP Top 10 and beyond — comprehensive web app vulnerability assessment

Burp SuiteOWASP ZAPSQLMap

Active Directory

AD enumeration, privilege escalation, lateral movement, and domain compromise

BloodHoundImpacketRubeus

API Security Testing

REST and GraphQL API vulnerability identification and exploitation

PostmanGraphQLJWT

Scripting & Automation

Custom tool development, exploit scripting, and automation frameworks

PythonBashPowerShell

Cloud Security

AWS, Azure, and GCP security assessment and exploitation

AWSAzureGCP

Social Engineering

Human factor security assessment and phishing campaign execution

PhishingOSINTPretexting

Reporting & Documentation

Professional technical and executive reporting with remediation guidance

TechnicalExecutiveCVSS

Professional Certifications

Validated expertise, engagement by engagement

PNPT Certification badge

PNPT

Practical Network Penetration Tester

TCM Security
PJPT Certification badge

PJPT

Practical Junior Penetration Tester

TCM Security
Certified Red Team Analyst badge

CRTA

Certified Red Team Analyst

Cyberwarfare Labs
Active Directory Red Team Specialist badge

AD-RTS

Certified Active Directory Red Team Specialist

Cyberwarfare Labs
Multi-Cloud Red Team Analyst badge

MCRTA

Certified Multi-Cloud Red Team Analyst

Cyberwarfare Labs
Web Red Team Analyst badge

WEB-RTA

Certified Web Red Team Analyst

Cyberwarfare Labs
API Red Team Analyst badge

API-RTA

Certified API Red Team Analyst

Cyberwarfare Labs
CNSP Certification badge

CNSP

Certified Network Security Practitioner

The SecOps Group
Google Cybersecurity Professional badge

Google Cybersecurity

Cybersecurity Professional Certificate

Google
Certified Red Team Management badge

CRTOM

Certified Red Team Management

RedTeamLeaders
Certified Cybersecurity Educator Professional badge

CCEP

Certified Cybersecurity Educator Professional

RedTeamLeaders
Certified C++ Practitioner badge

CCPP

Certified C++ Practitioner

RedTeamLeaders

Featured Engagements

Campaigns and outcomes from the digital battlefield

Critical

Web Application Strike

Completed

Conducted comprehensive black-box testing on a complex e-commerce platform. Identified critical SQLi, XSS, and broken access control vulnerabilities.

Web SecuritySQLiXSSOWASP
Critical

Network Fortress

Completed

Led an internal network penetration test for an enterprise organization. Uncovered misconfigured services and lateral movement vectors through AD.

Network SecurityActive DirectoryLateral MovementPrivEsc
Open Source

ReconQuest Framework

Open Source

Automated reconnaissance tool with intelligent filtering for directory and subdomain scanning, reducing false positives during engagements.

PythonAutomationOSINTRecon
Critical

Cloud Security Assessment

Completed

Comprehensive cloud penetration testing covering AWS, Azure, and GCP. Identified misconfigurations and privilege escalation paths.

AWSAzureGCPCloud Security
Open Source

Net-Mapper

Open Source

A professional network topology visualization platform for security teams, network engineers, and penetration testers — interactive infrastructure mapping, subnet segmentation, route analysis, and offline documentation.

NetworkingCybersecurityVisualizationTopology Mapping

Let's Connect

Ready to discuss a security challenge or an engagement?

secure_channel.sh
$ ./initiate_contact.sh
[*] Initializing secure connection...
[+] Handshake complete
[+] Ready to receive transmission
$ _