Summary
Overview
Work History
Education
Skills
Projects
Security Blog
Timeline
Generic

WAYNE KENNEY

Manchester,NH

Summary

Detail-oriented cybersecurity professional with a B.S. in Cybersecurity (Magna Cum Laude) and hands-on experience across web application penetration testing, network security, and threat analysis. Skilled in identifying and exploiting vulnerabilities including SQL injection, cross-site scripting (reflected, DOM, blind), broken access control, authentication flaws, and SSRF. Proficient with industry-standard tooling (Metasploit, Burp Suite, Nessus, Wireshark, Hashcat) and comfortable building custom Python-based scanning and assessment utilities. A former offensive-security practitioner now dedicated exclusively to defensive work - leveraging a deep attacker's perspective to help organizations understand, find, and remediate risk before adversaries do. Strong written communicator with an active security research blog documenting original tooling and methodology. Builder of Email Guardian (CyberGuard), an AI-driven inbox security engine featured in WMUR News 9 coverage for its mission to prevent the social engineering attacks the developer once perpetrated.

Overview

17
17
years of professional experience

Work History

Bookstore Clerk at various colleges from NCC-NHTI

Follett Higher Education Group
Concord, NH
02.2022 - Current

Cybersecurity Specialist

Freelancer - Development Frameworks
Manchester, Nh
01.2010 - 08.2026

Education

Bachelor of Science - Cybersecurity

Southern New Hampshire University (SNHU)

Skills

  • Web Application Testing
  • SQLi
  • XSS
  • Path Traversal
  • Broken Access Control
  • Broken Authentication
  • SSRF
  • Session Hijacking
  • Network Security & Monitoring
  • Packet analysis
  • Traffic inspection
  • Wireshark
  • Vulnerability Assessment
  • Nessus scanning
  • Triage
  • Remediation guidance
  • Exploitation Frameworks
  • Metasploit
  • Burp Suite
  • Wireless Testing
  • WEP/WPA2 assessment
  • Hashcat
  • Offensive Tool Development
  • Python security utilities
  • Custom scanners
  • AI-Assisted Security
  • Prompt engineering
  • AI-driven scanning workflows
  • LLM API integration
  • Operating Systems
  • Pop! OS
  • Kali Linux
  • Linux administration
  • Windows environments
  • Soft Skills
  • Technical writing
  • Threat communication
  • Continuous research

Projects

  • Email Guardian (CyberGuard) - AI Inbox Security Engine, https://cyb-sec.dev/post/Ai-inbox-scanning-tech, Designed and built an AI-powered email security platform that detects phishing, social engineering, and image-based threats by analyzing the semantic intent of inbound messages using large language models. Integrated LLM APIs (OpenRouter, Gemini, DeepSeek) to perform real-time semantic analysis of email content, identifying deceptive patterns that static signature-based filters miss. Implemented dual-provider inbox integration: Gmail (Gmail API, OAuth 2.0, read-only scope) and Microsoft 365 / Outlook (Microsoft Graph API, Entra ID app registration, Mail.Read permission). Built AI Vision-Powered Threat Decryption using Gemini Flash Vision to detect image-based phishing (fake login prompts, brand impersonation, urgency cues) beyond simple OCR - interpreting the deceptive intent of visual content in milliseconds. Developed a heuristic Sentinel Engine that analyzes attachment anatomy to detect Prototype Pollution and RCE chains in PDFs, images, and JSON. Engineered threaded parallel scanning for concurrent multi-message analysis, and .MBOX cold-storage ingestion for recursively scanning historical archives (Google Takeout). Migrated the platform to a Manifest V3 browser extension with local encrypted storage, eliminating the web-server middleman and reducing attack surface for sensitive API calls. Featured in WMUR News 9 investigative coverage (reporter Alanna Flood, 05/26) highlighting the tool's mission to prevent the kind of social engineering attacks the developer once perpetrated.
  • DORB (Discord Operated Remote Backdoor) - Security Research Project, https://cyb-sec.dev/post/dorb-backdoor, Designed and documented a command-and-control research tool that channels backdoor communication through Discord's legitimate API, demonstrating how trusted platforms can be abused to bypass perimeter controls. Published full methodology and defensive analysis on personal security blog to advance understanding of C2 evasion techniques among blue-team defenders. Built entirely for research and educational purposes; contributed findings to the broader security community to improve detection capability.
  • Custom Python Security Scanning Toolkit, Developed a suite of Python-based scanners for common web vulnerabilities, integrating AI-assisted analysis to accelerate triage and reduce false positives during assessment workflows.
  • Open-Source Security Tooling Contributions, Contributed to Ares, an open-source remote access tooling project, supporting ongoing security research into command-and-control architecture and detection.
  • Security Research Blog (cyb-sec.dev), Author original write-ups on offensive technique, tool development, and AI-assisted vulnerability research, with a focus on translating attacker methods into defensive insight.

Security Blog

  • Email Guardian (CyberGuard) - AI Inbox Security Engine, https://cyb-sec.dev/post/Ai-inbox-scanning-tech, Designed and built an AI-powered email security platform that detects phishing, social engineering, and image-based threats by analyzing the semantic intent of inbound messages using large language models. Integrated LLM APIs (OpenRouter, Gemini, DeepSeek) to perform real-time semantic analysis of email content, identifying deceptive patterns that static signature-based filters miss. Implemented dual-provider inbox integration: Gmail (Gmail API, OAuth 2.0, read-only scope) and Microsoft 365 / Outlook (Microsoft Graph API, Entra ID app registration, Mail.Read permission). Built AI Vision-Powered Threat Decryption using Gemini Flash Vision to detect image-based phishing (fake login prompts, brand impersonation, urgency cues) beyond simple OCR - interpreting the deceptive intent of visual content in milliseconds. Developed a heuristic Sentinel Engine that analyzes attachment anatomy to detect Prototype Pollution and RCE chains in PDFs, images, and JSON. Engineered threaded parallel scanning for concurrent multi-message analysis, and .MBOX cold-storage ingestion for recursively scanning historical archives (Google Takeout). Migrated the platform to a Manifest V3 browser extension with local encrypted storage, eliminating the web-server middleman and reducing attack surface for sensitive API calls. Featured in WMUR News 9 investigative coverage (reporter Alanna Flood, 05/26) highlighting the tool's mission to prevent the kind of social engineering attacks the developer once perpetrated.
  • DORB (Discord Operated Remote Backdoor) - Security Research Project, https://cyb-sec.dev/post/dorb-backdoor, Designed and documented a command-and-control research tool that channels backdoor communication through Discord's legitimate API, demonstrating how trusted platforms can be abused to bypass perimeter controls. Published full methodology and defensive analysis on personal security blog to advance understanding of C2 evasion techniques among blue-team defenders. Built entirely for research and educational purposes; contributed findings to the broader security community to improve detection capability.
  • Custom Python Security Scanning Toolkit, Developed a suite of Python-based scanners for common web vulnerabilities, integrating AI-assisted analysis to accelerate triage and reduce false positives during assessment workflows.
  • Open-Source Security Tooling Contributions, Contributed to Ares, an open-source remote access tooling project, supporting ongoing security research into command-and-control architecture and detection.
  • Security Research Blog (cyb-sec.dev), Author original write-ups on offensive technique, tool development, and AI-assisted vulnerability research, with a focus on translating attacker methods into defensive insight.

Timeline

Bookstore Clerk at various colleges from NCC-NHTI

Follett Higher Education Group
02.2022 - Current

Cybersecurity Specialist

Freelancer - Development Frameworks
01.2010 - 08.2026

Bachelor of Science - Cybersecurity

Southern New Hampshire University (SNHU)
WAYNE KENNEY