Suphawith Phusanbai

A self-taught penetration tester who likes to hunt bugs alone!

Hunting vulnerabilities in Fortune 500 companies and gaming softwares.

About Me

I focus on desktop application security, Windows vulnerability research, and reverse engineering. I usually perform penetration testing for Tier 1 banks in Thailand, with additional hands-on experience in AI and agentic penetration testing. I also enjoy adversary simulation and developing custom malware for red team operations! I also enjoy weight lifting!

Curiosity drives everything I do. I usually start with questioning the issue, making an assumption, finding the root cause, articulating attack possibilities, and then exploiting it. The least favorite thing for me is doing repetitive tasks such as compliance pentesting checklists.

Penetration TestingCVE ResearchBug BountyOpen Source

Working Experience

  1. PwC

    Current

    Cyber Security Associate — Penetration Tester

    Present

    • Conduct penetration testing across application, network, Wi-Fi, Azure, and AI/LLM environments for banking and enterprise clients.
    • Identified high-impact vulnerabilities, including an authentication bypass exposing customer PII and a critical cloud security misconfiguration. Credited with PwC Thailand's first RCE discovery.
    • Developed custom adversary-simulation tooling capable of evading enterprise AV/EDR controls and delivered secure code review training to banking developers.
    • AppSec
    • Network
    • Wi-Fi
    • Azure
    • AI / LLM
    • Red Teaming

    Full-timeBangkok, Thailand · Hybrid

  2. Siam Thanat Hack Co., Ltd.

    Penetration Tester

    • Conducted web and mobile application penetration testing across client environments.
    • Worked across malware analysis, incident response, and offensive-security challenge development.
    • Web Security
    • Mobile Security
    • Malware Analysis
    • Incident Response
    • CTF Development

    Full-timeThailand · Hybrid

GitBook Blog

Read My Security Research Blog

From vulnerability discovery to exploitation — practical write-ups based on real-world targets.

Corporation & Government

These are globally recognized vendors to whom I reported vulnerabilities and coordinated responsible disclosure.

Open Source Software

These are OSS maintainers I reported vulnerabilities to and communicated with through GitHub issues and email.

Popular CMS/CRM

Public Advisories & Exploits

Achievements

Women Thailand Cyber Top Talent 2024 Creator

Web App Category (Junior & Open Challenge Labs)

Lab Creator