Hello, I'm
Vladimir Cuc
OSCP+ & Security+ Certified
Security Engineer & Penetration Tester
I'm passionate about cybersecurity, from offensive security and penetration testing to security operations and cloud infrastructure. I focus on Active Directory attack paths, SIEM-driven detection, and building tooling that strengthens organizational defenses.
Latest Security Insights
Explore my OSCP-style walkthroughs covering enumeration, exploitation, lateral movement, and privilege escalation with clear methodology.
Read Blog Posts
About Me
My path into cybersecurity started with a simple curiosity about how systems break, and how attackers think. That curiosity turned into an obsession with offensive security: grinding labs late into the night, chaining exploits, and learning to move through a network the way a real adversary would. It led me to the OSCP, which I passed on my first attempt, and it still shapes how I approach every engagement.
I live in the attacker's mindset, enumerating aggressively, hunting misconfigurations, and mapping Active Directory attack paths from initial foothold to full domain compromise. I focus on privilege escalation, lateral movement, and pivoting, and I write my own tooling to make recon and exploitation faster and cleaner. When I'm not in a lab, I'm documenting walkthroughs and sharpening the tradecraft that turns a single weak point into complete control.
Contact Information
Education
Bachelor of Science in Computer Science
Florida Southern College
2022 - 2025 • GPA: 3.8
Skills & Technologies
Offensive security, security operations, and cloudA snapshot of the technologies I use across penetration testing, security operations, cloud infrastructure, and automation
Offensive Security
Offensive Tooling & Tradecraft
Cloud, Identity & AppSec
Programming & Tooling
For full skill list download the resume
Professional Experience
A timeline shaped by security, engineering, and real-world problem-solvingOffensive security and engineering experience in one place
Web Systems & Automation Engineer
Posted Social
Key Responsibilities
- ▸Build and secure a multi-tenant client portal for 50+ clients and 100+ users.Build and secure a multi-tenant client portal in Next.js and TypeScript on Supabase and Vercel, serving 50+ clients and 100+ users, owning the full technical and security side.
- ▸Enforce tenant isolation with Postgres RLS, least-privilege RBAC, and passwordless auth.Enforce tenant isolation with Postgres Row-Level Security and a tiered least-privilege access model, with passwordless authentication (Google OAuth and magic links) scoped per client.
- ▸Harden OAuth flows with signed state and PKCE, and add a server-side SSRF guard.Harden the social-account OAuth flows against forgery with server-signed state and PKCE, add a server-side SSRF egress guard, and keep secrets server-side with Supabase Vault and scoped API credentials.
- ▸Build 30+ automation workflows across 20 client environments with Python API integrations.Build 30+ automation workflows across 20 client environments, with Python integrations to Meta and platform APIs for event tracking and conversion attribution.
Help Desk Support Technician
Florida Southern College
Key Responsibilities
- ▸Tier-1 support for identity and access issues, resolving account lockouts and MFA problems for 100+ users.Provided Tier-1 support for identity and access issues, resolving account lockouts, MFA problems, and password resets for 100+ students and faculty.
- ▸Maintained Conditional Access assignments under supervision and supported MFA and password recovery.Maintained Conditional Access user assignments under senior engineering supervision, handled password resets and MFA enrollment support, and routed privileged-access requests through the campus ticketing workflow.
- ▸Troubleshot Windows endpoints, RDP connectivity, and school applications.Troubleshot Windows endpoints, RDP connectivity, school applications, and license management, developing a methodical and security-minded approach to problem solving.
- ▸Communicated technical steps clearly to support safe campus access.Communicated complex technical steps in a clear, user-friendly way, strengthening team efficiency and supporting safe access across campus systems.
Cybersecurity Intern
Publix Supermarkets Corporate
Key Responsibilities
- ▸Enhanced PowerShell domain-monitoring tool, increasing fraudulent domain detection by 50%.Enhanced a PowerShell-based domain-monitoring tool with SSL/WHOIS fingerprint analysis, increasing detection of fraudulent Publix domains by 50%.
- ▸Assisted red-team engineers with AD enumeration and privilege-escalation testing.Assisted senior red-team engineers with Active Directory enumeration, Kerberoasting validation, and Windows privilege-escalation testing during internal assessments.
- ▸Triaged 200+ alerts in Microsoft Defender using Splunk queries to identify detection gaps.Triaged and investigated 200+ alerts in Microsoft Defender and ServiceNow, using focused Splunk queries to reduce noise, speed up triage, and identify detection gaps.
- ▸Performed forensic E01 imaging and tuned SIEM thresholds for better detection accuracy.Performed forensic E01 endpoint imaging and tuned SIEM alert thresholds to sharpen detection accuracy and support both SOC workflows and offensive test coverage.
Software Engineer Intern
Vertical Digital (Eleco Group)
- ▸Designed secure RESTful APIs, improving data-flow efficiency by 40%.Designed and implemented secure, scalable RESTful APIs, improving data-flow efficiency by 40% and reinforcing backend reliability against misuse.
- ▸Optimized MongoDB operations, reducing query response times by 35%.Optimized large-dataset operations in MongoDB, reducing query response times by 35% and strengthening system performance under load.
- ▸Developed payment-processing engine, simulating 10,000+ transactions.Developed and rigorously tested a custom payment-processing engine, simulating 10,000+ transactions to validate data integrity and uncover edge-case failures.
- ▸Worked in Linux environments, supporting offensive-security tooling automation.Worked daily in Linux environments, leveraging scripting and debugging skills that later supported my offensive-security work and tooling automation.
Projects
A production secure-portal demo, open-source security tools, and hands-on labs

RaptorRecon
Bash framework for fast OSCP-style recon across multiple targets.Bash framework for fast OSCP-style recon across multiple targets. Orchestrates RustScan, Nmap, web enum, SMB/FTP/RPC probes, and drops everything into clean, timestamped per-host folders.
View on GitHub
DragonMap
Bash script for credentialed Active Directory enumeration in assumed-breach scenarios.Bash script for credentialed Active Directory enumeration in assumed-breach scenarios. Performs high-signal SMB/RPC/LDAP/DNS recon using valid creds and saves organized, timestamped output for each target.
View on GitHub
Relay
A real, working multi-tenant client analytics portal, security-hardened and built end to end with Claude Code.A real, working multi-tenant client analytics portal, the open-source twin of a product I run in production. Security-hardened and built end to end with Claude Code, with a public Security Lab of live attack and defense demos.

Malware Analysis Lab, AsyncRAT
Isolated FLARE VM and REMnux lab where I analyzed a real AsyncRAT sample end to end.Isolated FLARE VM and REMnux lab where I reversed a real AsyncRAT sample. Static analysis with dnSpy and Detect It Easy, then dynamic analysis with Process Monitor and Wireshark to surface process injection, C2, and registry persistence.
Read the WriteupsSecurity & AI
AI is part of how I build and how I defend. I use it to move fast, then put the security boundaries around it that teams often skip, and I bring an attacker's eye to AI systems themselves.
Featured Blog Posts
Walkthroughs, notes, and lessons learned from penetration testing, security research, and hands-on labsPenetration testing walkthroughs and security write-ups
Let's Connect
Whether it's penetration testing, security engineering, cloud infrastructure, or building security tooling, I'm always open to interesting problems and collaborations.






