Cyber Threat Intelligence Analyst. I started out breaking web apps in CTF arenas just to understand how they fail, and ended up tracking, dissecting, and disarming the people doing it for real. Here's that journey, in order.
I enrolled in , though the lessons that actually stuck came from CTF arenas, not lecture halls. Web exploitation became the obsession. Every broken authentication flow and injection point was a puzzle I couldn't put down, and that itch to understand why a system fails is still what drives everything I do.
Picked up
Web Exploitation Burp Suite pwntools Nmap
2023 · Foundations
From the arena to the enterprise
Picked as a top-50 Viettel Digital Talent, I spent my intern months buried in NIST CSF and CIS Controls, my first real taste of security at organizational scale. That opened the door to Viettel Group Headquarters, where I authored the group-level information security regulation and ran audits across every business unit in Vietnam and its overseas subsidiaries. I learned that finding a flaw is only half the work. The other half is turning it into policy people will actually follow.
As a , I moved from writing the rules to living inside the incidents. I hunted advanced threats and persistence across group-wide infrastructure, drove investigations through deep log analysis from first alert to root cause, and owned the response end to end, from containment through the findings that kept it from happening twice.
Picked up
Threat Hunting Log Investigation Sysmon Wireshark Incident Response
2026 · Impact
The hunt
Today, as a Cyber Threat Intelligence Analyst at Alice (formerly ActiveFence), I track phishing campaigns end to end, from static kits piping credentials to Telegram bots, to Browser-in-the-Browser popups and WebSocket kits validating stolen logins in real time. I reverse malicious browser extensions, tear infostealers apart from cookie theft to C2, and map adversary infrastructure into client-facing reports built on MITRE ATT&CK. The curiosity that started in a CTF box is still what protects platforms at scale today.
On the team at Alice (formerly ActiveFence).
Picked up
MITRE ATT&CK Malware Analysis C2 Mapping Phishing Kit Analysis IOC Extraction
All along · The arena
// The Arena
The competition never let go
Through every job, CTF kept me sharp: web exploitation, misc, and challenge-patch, on stages across the region.
Top 5 · Student
Third Prize
Second Prize
Top 5 (Student Division) at ASEAN Cyber Shield 2025, Busan, Korea. A CTFd Docker plugin I built.
Still curious. Still breaking things to understand them.
Credentials
Education
Sept 2021 – Jul 2025
Hanoi University of Science and Technology
Bachelor of Science in Cyber Security
GPA: 3.3/4.00
Classification:
Very Good
Coursework: Computer Architecture, Network Defense, Malware Analysis, Digital Forensics