ghostwirez / arvin rafael legaspi
contact
public copy · shareable Quezon City, Philippines

Arvin Rafael
Legaspi

Offensive Security Engineer at Secuna. I get paid to find the path from a single foothold to everything that matters, then write it down clearly enough to fix.

Web applications, internal networks, Active Directory. Off the clock: threat intelligence, on-chain malware tracking, and running a community for people trying to break into this field.

Document metadata
Operator ghostwirez
Role Offensive Security Engineer
Secuna · Nov 2024 – present
Also Founder, CyberwireZ
HTB Philippines Ambassador
Engagements ████████ ██████ ███████████ █████
Disclosure Techniques public. Client findings, never.

What I actually do

The surface I work across, and the shape these engagements usually take. Findings belong to the client, so none appear here — the techniques are the part I can talk about.

WEB Web application penetration testing primary

Authentication, authorization, and everything the server takes on trust

Full assessments against production web applications and APIs: mapping the real attack surface, then working the places where server-side checks are missing rather than the places a scanner points at. Most of what matters lives in authorization logic — object references, tenant boundaries, role assignment, session lifetime.

Every engagement ends in a report a developer can act on, and a retest that proves the fix actually held.

Burp SuiteffufsqlmapOWASP WSTGmanual review
How it goes
ScopeRules of engagement, targets, credentials, blast radius agreed in writing
MapContent discovery, roles, tenancy model, trust boundaries
AttackAuthz gaps, injection, SSRF, file handling, session and token logic
DeliverReproduction steps, impact, remediation, then retest
NET Internal network · Active Directory primary

From one authenticated foothold to the objects that actually matter

Internal assessments where the question isn't whether a host is vulnerable, but how far a single set of valid credentials gets you. Directory misconfiguration beats missing patches nearly every time: delegation settings, certificate templates, signing requirements, ACLs nobody has audited since the domain was built.

CRTO and CRTA back this track, and the reporting is where it earns its keep — a graph of who can reach what, not a list of CVEs.

BloodHoundImpacketNetExecCertipyRubeusCobalt Strike
How it goes
FootholdAssumed-breach credentials or a service reachable from the user VLAN
EnumerateDomain objects, ACLs, delegation, ADCS templates, signing posture
EscalateKerberos abuse, coercion and relay paths, certificate misconfiguration
DeliverThe shortest path drawn end to end, with the one change that breaks it
MOB Android application security lab · published

Exported components, and secrets that were only ever hidden

Static and dynamic analysis of Android apps, worked through the Mobile Hacking Lab challenges and written up in full. Exported activities and receivers that accept input from any installed app, values that reach a shell unquoted, and keys that obfuscation only made harder to read, not harder to extract.

Writeups for the IoT Connect, Cyclic Scanner and Strings labs are linked in the next section.

FridafridumpjadxadbBurp + pinning bypass
How it goes
UnpackManifest, exported components, decompiled sources
RigWritable system image, frida-server on boot, TLS interceptionadb root · frida-server · Burp CA
ProbeIntent fuzzing, injection into command sinks, runtime hooking
ExtractKeys and plaintext pulled from memory rather than from the APK
INTEL Threat intelligence · malware research

Following a live campaign until the infrastructure runs out

Independent tracking of an active ClickFix operation that stores its loader in smart contract storage. There is no host to seize and no domain to sinkhole, and rotating the payload costs the operator one transaction — so the analysis moves on-chain instead.

Decoding setter transactions rebuilds the command-and-control rotation history in order, which is the part a takedown request can't touch. Published in full; the macOS variant is still open.

on-chain analysissandboxingstatic triagepassive DNSOSINT
How it goes
LureFake prompt talks the user into running the command themselves
FetchStage reads its next instruction from contract storageeth_call → payload
StageDelivery through trusted CDN and WebDAV over HTTPS
TraceSetter transactions decoded into a C2 rotation timeline

Published writeups

Threat intelligence, mobile labs and certification notes, under the ghostwirez handle.

Threat intel Medium

Chasing a ClickFix campaign down the blockchain

From a compromised law firm site to a loader that abuses trusted infrastructure — payload logic held in contract storage, staged through a CDN and WebDAV over HTTPS, ending in a trojanized installer.

ClickFixEtherHidingWebDAVloader analysis
Android lab Medium

MobileHackingLab: IoT Connect

Working an exported component that trusts input from any app on the device, from manifest review through to a working proof of concept.

exported componentsintentsadb
Android lab Medium

MobileHackingLab: Cyclic Scanner

A filename that reaches a shell unquoted, which makes naming the file the exploit. Command execution in the app's own context.

command injectionFridajadx
Android lab Medium

MobileHackingLab: Strings

Recovering encryption keys from a running process with Frida and fridump, after the static route turned out to be the long way round.

fridumpmemory analysisAES
Certification Medium

CRTO review: what the exam actually asks for

An honest account of preparing for and passing Certified Red Team Operator — what the lab time is worth, and what I'd study differently.

CRTOred teamexam prep
Notes GitBook

Working notes and rigs

The longer-form notebook: lab setups, tooling that earned a place in the workflow, and the research that isn't finished enough to publish yet.

notestoolingin progress

Credentials

Red team heavy, all hands-on exams. The hatched ones are the current reading list, not a wish list.

CRTO ↗ Certified Red Team Operator · review published
CRTACertified Red Team Analyst
CPTSCertified Penetration Testing Specialist
CWESCertified Web Exploitation Specialist
CAPTCertified Android Penetration Tester · in progress
CDSACertified Defensive Security Analyst · in progress
SC-900Security, Compliance & Identity Fundamentals · in progress
Held
In progress

Record

Secuna now Nov 2024 – present

Offensive Security Engineer

Web application and internal network penetration testing, end to end: scoping, exploitation, the report, and the retest that proves the fix held.

OpenText Jul 2023 – Nov 2024

Software Engineer

Built software before breaking it for a living. Reading a codebase the way its maintainer does is still the shortest route to a finding.

ROC.PH Jun 2022 – Jul 2022

Lead Network & Security Engineer · internship

First time on the defensive side of a live network, which is still where a lot of my instincts about what actually gets noticed come from.

University of the East 2019 – 2023

BS Computer Engineering, Caloocan · magna cum laude

CyberwireZ

I started CyberwireZ because the fastest way to get good at this is in a room with other people trying to get good at it.

As Hack The Box Philippines Ambassador I run meetups, hands-on workshops and campus sessions — mostly for people making a first serious attempt at offensive security, which is where I was not that long ago. Organising something and need a speaker or a lab track? Ask.

Meetups

Regular CyberwireZ and HTB Philippines gatherings

Workshops

Hands-on sessions, including Linux fundamentals on campus

Conferences

CyberwireZ turns up — BSides Manila and friends

Speakers

Booking talks and village sessions with the local scene