Skip to main content
root@phirun:~$ initializing portfolio...
[+] Loading modules: VAPT, Red Team, OSCP
[+] Connecting to HackTheBox... OK
[+] Connecting to TryHackMe... OK
[+] System ready. Welcome back, Phirun.

$ whoami

Leng Phirun

Assistant Lead (Adversary) & Penetration Tester

An enthusiastic cybersecurity professional with hands-on experience in vulnerability assessment, penetration testing, and red teaming. Passionate about uncovering vulnerabilities and strengthening security measures.

# About Me

I am an Assistant Lead (Adversary) at Veilron Technologies with over 3 years of hands-on experience in the cybersecurity field. My work focuses on vulnerability assessment, penetration testing, and red teaming across networks, web applications, mobile apps, Active Directory, and APIs.

I'm passionate about uncovering vulnerabilities and strengthening security measures, with a keen interest in staying updated with the latest industry trends. Known for a proactive attitude, attention to detail, and the ability to collaborate effectively with teams.

Outside of work, I enjoy participating in CTF competitions, researching new tools and techniques, and continuously growing within the cybersecurity landscape.

role Asst. Lead (Adversary)
company Veilron Technologies
education B.Sc. Computer Science
university RUPP
location Phnom Penh, Cambodia
interests CTFs, Red Teaming

# Skills

// VAPT & Red Teaming

Network Pentesting Web App Testing Mobile App Testing API Security Active Directory Red Teaming Configuration Review

// Security Operations

Vulnerability Assessment SIEM PAM Asset Management IT Policy

// Key Competencies

Project Management Team Management Critical Thinking Report Writing Client Presentations

// Methodologies

OWASP Top 10 MITRE ATT&CK PTES NIST Kill Chain

# Certifications

🛡

OSCP

OffSec

Certified
🎯

CRTA

CyberWarFare Labs

Nov 2025
🔍

CREST CRT

CREST

Aug 2025
🔍

CREST CPSA

CREST

Aug 2025
💻

PT1 Certificate

TryHackMe

Jun 2025
🌐

API Pentesting

APIsec University

Oct 2024
🔒

CC

ISC2

Certified
🎓

B.Sc. Computer Science

Royal University of Phnom Penh

Graduated

# Experience

Mar 2025 - Present

Assistant Lead (Adversary)

Veilron Technologies // Hybrid, Phnom Penh

Leading adversary simulation engagements, overseeing VAPT operations, red teaming assessments, and mentoring team members. Coordinating internal and external team efforts on security projects.

Red Team VAPT Leadership AD API
Dec 2022 - Mar 2025

Information Security Engineer

Veilron Technologies // Hybrid, Phnom Penh

Vulnerability Assessment and Penetration Testing across Network, Web, Mobile, Active Directory, and API. Red Teaming assessments, configuration reviews, reporting, and project management.

VAPT Red Team Config Review Reporting
Apr 2022 - Nov 2022

IT Security

Foreign Trade Bank of Cambodia // Full-time, Onsite

Security training awareness, SIEM administration, vulnerability assessments, privilege access control (PAM), and asset management.

VA SIEM PAM Asset Mgmt
Aug 2021 - Nov 2021

IT Support Technician

Women's Media Centre of Cambodia // Full-time, Onsite

Provided general IT support, maintained reliable network connections, managed mail systems, and assisted with IT policy implementation.

IT Support Networking IT Policy

# Projects & Writeups

Tool

Internal Network Pentest Toolkit

Custom scripts and automation tools developed for internal network penetration testing engagements, including AD enumeration, lateral movement helpers, and post-exploitation utilities.

Python PowerShell Active Directory Red Team
View on GitHub →
Writeup

HackTheBox Machine Writeups

Detailed writeups covering exploitation methodology, privilege escalation techniques, and lessons learned from various HackTheBox machines across different difficulty levels.

OSCP Prep Linux Windows Pivoting
View Profile →
Research

Web Application Security Research

Ongoing research into modern web application vulnerabilities including authentication bypasses, API security flaws, and emerging attack vectors against cloud-native applications.

OWASP API Security Bug Bounty Cloud
View on GitHub →

# CTF & Security Labs

📦

HackTheBox

app.hackthebox.com

Active member on HackTheBox, tackling machines and challenges across various difficulty levels. Practicing real-world offensive techniques in a controlled lab environment.

View Profile →
🚩

TryHackMe

tryhackme.com

Completed learning paths and challenges on TryHackMe, earning the PT1 Certificate. Focused on penetration testing, privilege escalation, and web exploitation techniques.

View Profile →
🏆

CTF Competitions

Capture The Flag

Regular CTF participant with experience in web exploitation, reverse engineering, cryptography, and binary exploitation challenges. Continuously sharpening offensive skills through competition.

GitHub →

# Contact

Interested in working together or have a security concern? Feel free to reach out. I'm always open to discussing new opportunities, collaborations, or security challenges.