Available for red team engagements

RejuKole

$Cybersecurity Engineer

Six years of breaking into things that matter — and writing the report that closes the door behind me. Hall of Fame at NASA, SpaceX, Binance and three more.

Years in offensive security
0+

Years in offensive security

Global Hall of Fame entries
0

Global Hall of Fame entries

TryHackMe of 3M+ users
Top 0%

TryHackMe of 3M+ users

Rooms & labs completed
0+

Rooms & labs completed

Recognized by

NASASpaceXBinanceStarlinkTelstraLenovoHack The BoxTryHackMePortSwiggerCyberWarfare Labs
01 / About

I find the way in,
then I close it.

Cybersecurity engineer and ethical hacker with 6+ years of experience in red team operations, penetration testing, and exploit development. NASA Hall of Fame recipient and top 1% TryHackMe performer, specializing in advanced persistent threat simulation, malware research, and vulnerability discovery. Proven track record of identifying critical vulnerabilities in major organizations including NASA, SpaceX, Binance, Starlink, Telstra, and Lenovo.

reju@blackbox — zsh

~whoami

reju.kole — offensive security engineer

~cat ./focus.txt

red team ops · exploit dev · malware research

~uptime

6+ years, still hunting

~

02 / Recognition

Six Halls of Fame.
Zero exploited in the wild.

Critical vulnerabilities found and responsibly disclosed to some of the most security-sensitive organizations on the planet.

  • AerospaceHall of Fame

    NASA

    Official Letter of Recognition

    Discovered critical vulnerabilities in NASA's infrastructure, enhancing space mission security

    01
  • AerospaceHall of Fame

    SpaceX

    Security Vulnerability Disclosure

    Identified critical security vulnerabilities in SpaceX systems, contributing to the security of space exploration missions

    02
  • FintechHall of Fame

    Binance

    Cryptocurrency Exchange Security

    Discovered critical vulnerabilities in the world's largest cryptocurrency exchange, protecting millions of users' assets

    03
  • SatelliteHall of Fame

    Starlink

    Satellite Internet Security

    Enhanced the security of global satellite internet infrastructure through responsible vulnerability disclosure

    04
  • TelecomHall of Fame

    Telstra

    Telecommunications Security

    Improved the security posture of Australia's leading telecommunications infrastructure through vulnerability research

    05
  • EnterpriseHall of Fame

    Lenovo

    Enterprise Computing Security

    Contributed to the security of enterprise computing solutions used by millions of businesses worldwide

    06
03 / Disclosures

Published CVEs.
Both end in code execution.

Assigned identifiers for vulnerabilities I found, reported, and saw through to a fix. Both cards are encrypted — move your cursor across one to decrypt it.

  • 24 Jul 2026High · 8.6

    CVE-2026-65693

    Server-Side Template Injection to RCE

    Microweber CMS≤ 2.0.20·Microweber

    The mail template engine runs in an unsandboxed Twig environment with no security policy. An authenticated administrator can inject Twig expressions that break out of the template context and execute arbitrary commands on the host.

    Arbitrary OS command execution

    v4.0
    8.6
    v3.1
    7.2
    CWE
    94

    Improper Control of Generation of Code

    CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

    View advisory
    Disclosure 1
  • 6 Aug 2026High · 8.6

    CVE-2026-63725

    OS Command Injection in FileBackupService

    sysPass3.0.0 — 3.2.11·nuxsmin

    FileBackupService passes the backup directory path into a shell command without sanitization. An authenticated administrator can inject commands that run as the web server user — exposing the password manager's master password, encryption keys, and every stored credential.

    Full credential vault compromise

    v4.0
    8.6
    v3.1
    7.2
    CWE
    78

    Improper Neutralization of OS Command Elements

    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

    View advisory
    Disclosure 2
04 / Experience

Where the hours went

Independent research and client engagements, running in parallel since 2018.

  1. Cybersecurity Researcher & Bug Bounty Hunter

    2018 — Present
    IndependentRemote
    • Discovered critical vulnerabilities in major organizations including NASA, SpaceX, and Binance
    • Developed advanced red team tools and techniques for penetration testing
    • Achieved top 1% ranking on TryHackMe among over 3 million users globally
    • Completed multiple Hack The Box Pro Labs demonstrating advanced exploitation skills
  2. Penetration Testing Specialist

    2020 — Present
    FreelanceGlobal
    • Conducted comprehensive security assessments for enterprise clients
    • Specialized in web application and infrastructure penetration testing
    • Developed custom exploits and proof-of-concept demonstrations
    • Provided detailed remediation guidance and security recommendations
Hover me

Every system has a way in.
My job is to find it first.

Six years of red team operations across aerospace, fintech, telecom and satellite infrastructure.

05 / Work

Tools built to
simulate the real thing.

Offensive tooling and research, from kernel-adjacent evasion work to the automation that makes an engagement repeatable.

0195% success rate

Advanced C2 Malware Framework

  • Developed sophisticated command and control malware that successfully bypassed Windows Defender
  • Implemented advanced evasion techniques including process hollowing and DLL injection
  • Built encrypted communication channels for command and control operations
  • Demonstrated during red team engagements with 95% success rate
  • Featured in cybersecurity conferences as a case study for modern APT simulation

Stack

  • C++
  • Assembly
  • Windows API
  • Cryptography
  • Evasion Techniques

// engagement result

defender_bypass: true

success_rate: 0.95

conference_case_study: true

  • 02

    Automated Recon Toolkit

    • Built comprehensive reconnaissance automation framework integrating multiple OSINT tools and techniques
    • Streamlined vulnerability discovery process with custom reporting and threat intelligence correlation
    • Python
    • Bash
    • OSINT
    • Nmap
    • Custom APIs
  • 03

    Red Team Simulation Platform

    • Designed end-to-end red team engagement platform for simulating advanced persistent threats
    • Includes payload generation, lateral movement automation, and comprehensive attack chain documentation
    • Python
    • PowerShell
    • Metasploit
    • Cobalt Strike
    • MITRE ATT&CK
  • 04

    Vulnerability Research & Writeups

    • Published in-depth vulnerability research, exploit development tutorials, and cybersecurity writeups
    • Covering topics from web application security to advanced persistent threats
    • Research
    • Exploit Development
    • Technical Writing
    • CVE Analysis
06 / Credentials

Proof of work

Certifications, Pro Labs, and competition results — the receipts behind the résumé. Sweep the scanner across the badges.

Hack The Box

9 entries
  • Cyber Apocalypse CTF 2025Mar 2025
  • University CTF 2024 — Binary BadlandsDec 2024
  • P.O.O.Nov 2024
  • RPGNov 2024
  • DanteNov 2024
  • HadesNov 2024
  • FullHouseNov 2024
  • SolarOct 2024
  • Hack The Boo 2024 — CTF CompetitionOct 2024
07 / Arsenal

The kit, and
what it’s for.

Move your cursor across the list — the hex lattice charges where you touch it, and clicking detonates a shockwave.

Click to detonate

08 / Next

On the roadmap

What I'm training for, and where the research is heading.

09 / Services

How I work with teams

Engagements are scoped to your stack, run against real defenses, and land as findings your engineers can act on. Drag your cursor at a card's right edge to peel it back.

Open to work

Let’s find what your
scanners missed.

Red team operations, exploit development, and vulnerability research — for teams that would rather hear it from me than read it in a breach report.