Hello, I'm

Vladimir Cuc

OSCP+ & Security+ Certified

Security Engineer & Penetration Tester

I'm passionate about cybersecurity, from offensive security and penetration testing to security operations and cloud infrastructure. I focus on Active Directory attack paths, SIEM-driven detection, and building tooling that strengthens organizational defenses.

Latest Security Insights

Explore my OSCP-style walkthroughs covering enumeration, exploitation, lateral movement, and privilege escalation with clear methodology.

Read Blog Posts

About Me

My path into cybersecurity started with a simple curiosity about how systems break, and how attackers think. That curiosity turned into an obsession with offensive security: grinding labs late into the night, chaining exploits, and learning to move through a network the way a real adversary would. It led me to the OSCP, which I passed on my first attempt, and it still shapes how I approach every engagement.

I live in the attacker's mindset, enumerating aggressively, hunting misconfigurations, and mapping Active Directory attack paths from initial foothold to full domain compromise. I focus on privilege escalation, lateral movement, and pivoting, and I write my own tooling to make recon and exploitation faster and cleaner. When I'm not in a lab, I'm documenting walkthroughs and sharpening the tradecraft that turns a single weak point into complete control.

terminal
$sudo apt install caffeine
error: package already at latest version

Contact Information

(863) 338-7723
vladimircuc007@gmail.com
St. Louis, MO

Education

Bachelor of Science in Computer Science

Florida Southern College

2022 - 2025 • GPA: 3.8

Certifications

OSCP+ CertificationSecurity+ CertificationGoogle Cybersecurity CertificateMicrosoft Security, Compliance, and Identity FundamentalsMicrosoft Azure Fundamentals

Skills & Technologies

Offensive security, security operations, and cloud

Offensive Security

Active Directory Attacks
Privilege Escalation (Linux/Windows)
Lateral Movement
Web Application Testing
Pivoting / Tunneling

Offensive Tooling & Tradecraft

BloodHound / SharpHound
Impacket / NetExec
Burp Suite
Nmap / RustScan
Metasploit / Sliver C2

Cloud, Identity & AppSec

Identity & Access Management
OAuth & Web App Security
Conditional Access
Azure (AZ-900)
Secrets Management

Programming & Tooling

Python
Bash
PowerShell
JavaScript / TypeScript
SQL

Professional Experience

Offensive security and engineering experience in one place

Web Systems & Automation Engineer

Posted Social

February 2026 – Present
  • Build and secure a multi-tenant client portal for 50+ clients and 100+ users.
  • Enforce tenant isolation with Postgres RLS, least-privilege RBAC, and passwordless auth.
  • Harden OAuth flows with signed state and PKCE, and add a server-side SSRF guard.
  • Build 30+ automation workflows across 20 client environments with Python API integrations.

Help Desk Support Technician

Florida Southern College

October 2022 – December 2025
  • Tier-1 support for identity and access issues, resolving account lockouts and MFA problems for 100+ users.
  • Maintained Conditional Access assignments under supervision and supported MFA and password recovery.
  • Troubleshot Windows endpoints, RDP connectivity, and school applications.
  • Communicated technical steps clearly to support safe campus access.

Cybersecurity Intern

Publix Supermarkets Corporate

May 2025 – July 2025
  • Enhanced PowerShell domain-monitoring tool, increasing fraudulent domain detection by 50%.
  • Assisted red-team engineers with AD enumeration and privilege-escalation testing.
  • Triaged 200+ alerts in Microsoft Defender using Splunk queries to identify detection gaps.
  • Performed forensic E01 imaging and tuned SIEM thresholds for better detection accuracy.

Software Engineer Intern

Vertical Digital (Eleco Group)

May 2024 – Aug 2024
  • Designed secure RESTful APIs, improving data-flow efficiency by 40%.
  • Optimized MongoDB operations, reducing query response times by 35%.
  • Developed payment-processing engine, simulating 10,000+ transactions.
  • Worked in Linux environments, supporting offensive-security tooling automation.

Projects

A production secure-portal demo, open-source security tools, and hands-on labs

RaptorRecon

RaptorRecon

Bash framework for fast OSCP-style recon across multiple targets.

View on GitHub
DragonMap

DragonMap

Bash script for credentialed Active Directory enumeration in assumed-breach scenarios.

View on GitHub
Relay secure analytics portal with encryption and security overlays

Relay

A real, working multi-tenant client analytics portal, security-hardened and built end to end with Claude Code.

Malware analysis lab dashboard analyzing an AsyncRAT sample

Malware Analysis Lab, AsyncRAT

Isolated FLARE VM and REMnux lab where I analyzed a real AsyncRAT sample end to end.

Read the Writeups

Security & AI

AI is part of how I build and how I defend. I use it to move fast, then put the security boundaries around it that teams often skip, and I bring an attacker's eye to AI systems themselves.

Featured Blog Posts

Penetration testing walkthroughs and security write-ups

Let's Connect

Whether it's penetration testing, security engineering, cloud infrastructure, or building security tooling, I'm always open to interesting problems and collaborations.

(863) 338-7723
phish-terminal
vlad@lab:~/attachments

Phishing Check: Which one is safe to open?