Resume

Auth Level: Verified // RESUME_DATA_02

Identity

Narasimha Tiruveedula

Status

Active @ UMD Cybersecurity

Clearance

OSEP / CRTE / OSWE

GPA Accuracy

3.9 / 4.0

Generate Hard Copy

Nodes Online Live

OffSecVerified
HackTheBoxVerified
Red Team OpsVerified
Maldev AcademyVerified
TryHackMeVerified

Operational Trace

Solution Delivery Analyst

Nov 2023 – May 2024

Deloitte USI | Red Team & Application Security

  • # Ran full-scope red team and application security engagements across 5+ enterprise networks, surfacing 15+ critical and high-severity findings spanning web and API applications, Active Directory environments, and internal infrastructure.
  • # Designed and executed MITRE ATT&CK-aligned adversary simulations spanning initial access, execution, persistence, privilege escalation, defense evasion, credential access, lateral movement, and command and control, emulating realistic threat actor behavior across the attack lifecycle.
  • # Traced untrusted input from source to sink and chained multiple web and API vulnerabilities into reliable end-to-end exploits, bypassing authentication through flaws such as JWT abuse, IDOR, stored XSS, and SQL injection, and reaching remote code execution via command injection, insecure deserialization, file upload, and SSTI.
  • # Compromised Active Directory environments end to end using Kerberoasting, AS-REP Roasting, delegation and DACL abuse, credential dumping, cross-domain trust abuse, and Golden/Silver ticket forgery for persistence.
  • # Defeated layered endpoint defenses (PowerShell CLM, AppLocker, WDAC, JEA, LAPS, 2FA) and delivered in-memory payloads that evaded enterprise EDR via process injection, process hollowing, and direct syscalls.
  • # Developed custom Python and PowerShell offensive tooling to automate enumeration, privilege escalation, credential extraction, and post-exploitation, improving exploit reliability by ~50% and cutting manual effort by ~40%.
  • # Authored client-ready reports mapping complete attack chains to detection gaps and prioritized remediation, supporting client remediation and detection improvements for both technical and executive stakeholders.

Risk Advisory Intern

Jun 2022 – Jul 2022

Deloitte USI

  • # Executed end-to-end penetration testing on 2 enterprise applications, uncovering and reporting 4 critical vulnerabilities impacting system Confidentiality, Integrity, and Availability.
  • # Combined SAST (Fortify SCA), DAST (WebInspect, HCL AppScan), and manual testing (Burp Suite Pro), achieving ~30% more coverage than automated scanning alone.
  • # Tested 10+ high-value REST API endpoints with Burp Suite Pro and Postman, uncovering authentication, authorization, and input-validation flaws.
  • # Scripted repeatable vulnerability-detection workflows that cut manual effort by ~20% and standardized assessments across the team.

Tactical Stacks

Offensive Ops

Active DirectoryADCS AttacksEDR/AV EvasionProcess InjectionLateral Movement

Systems & Programming

Win32 APIsDirect SyscallsPythonPowerShellC#Bash

Arsenal

Burp SuiteCobalt StrikeMetasploitBloodHoundGhidraIDA Pro

Defense Infrastructure

DockerAnsiblePKIAES/HashingSIEM Engineering