✦ The Wizard's Chronicle ✦

About the Sorcerer

Ratthapong Sommanus · @sabastiaz

🦅
The Wizard's Identity
Who I Am
Ratthapong Sommanus receiving the Tenable Outstanding Technical Impact Award

I am Ratthapong Sommanus, known as Sabastiaz Founder of Wowza Group, a cybersecurity community focused on both Red Team and Blue Team development, and a Cybersecurity Assessment Specialist at Bigfish Enterprise Limited.

My work centers on Penetration Testing, Red Teaming, and Vulnerability Management across web applications, enterprise networks, and Active Directory environments. I specialize in identifying realistic attack paths, demonstrating tangible impact, and translating complex technical findings into clear, business-aligned recommendations.

I collaborate closely with technical teams and executive stakeholders to strengthen security posture, enhance governance frameworks, and reduce operational risk through structured assessments and threat-informed methodologies.

🏛️
Community Founder
Wowza Group Red & Blue Team Community
🏢
Current Role
Cybersecurity Assessment Specialist · Bigfish Enterprise
🎯
Primary Discipline
Penetration Testing / Red Teaming / Vuln Management
🌐
Scope
Web Apps · Enterprise Networks · Active Directory
📜
Published On
Medium — @sabastiaz
Quick Connect
Offensive Disciplines
Offensive Focus

Specializing in chaining misconfigurations inside enterprise networks to simulate realistic attack paths.

Active Directory Compromise & Abuse
Privilege Escalation & Lateral Movement
Kerberos Attacks — Kerberoasting / DCSync
BloodHound Attack Path Analysis
Enterprise Vulnerability Exploitation
The Ritual Lifecycle
Attack Methodology
I
Initial Access
II
Enumeration & Attack Surface Mapping
III
Credential Extraction
IV
Privilege Escalation
V
Lateral Movement
VI
Domain Compromise
VII
Impact Analysis & Executive Reporting
The Mastery Compendium
Areas of Expertise
Active Directory Security Network & Infrastructure Security Vulnerability Management Certifications Tenable Platform Expertise Burp Suite Expertise Security Baseline & CIS Benchmark Cybersecurity Awareness Phishing Simulation Incident Response Community Building & Personal Brand (Wowza) EDR Bypass Techniques
Ancient Orders & Seals
Certifications
OffSec Experienced Penetration Tester (OSEP)
OffSec Certified Professional (OSCP)
HTB Certified Penetration Testing Specialist (CPTS)
Red Team Operator (CRTO)
HTB Certified Active Directory Pentesting Expert (CAPE)
Certified Active Directory Pentesting eXpert (C-ADPenX)
Certified Red Team Analyst (CRTA)
Tenable.VM Specialist Certification
Certified Ethical Hacker (CEH)
The Dark Archives
Case Study Highlight
Enterprise Assessment
Active Directory Internal Assessment
Foothold DACL Privilege Escalation Domain Admin

Structured attack-chain documentation with executive-ready reporting, demonstrating full domain compromise from initial foothold.

🦉
Engagement

For enterprise red team simulations, Active Directory security assessments, or technical collaboration — dispatch your owl to the Owlery.

Send Owl Post →