Resume
Auth Level: Verified // RESUME_DATA_02
Identity
Narasimha Tiruveedula
Status
Active @ UMD Cybersecurity
Clearance
OSEP / CRTE / OSWE
GPA Accuracy
3.9 / 4.0
Nodes Online Live
OffSecVerified
HackTheBoxVerified
Red Team OpsVerified
Maldev AcademyVerified
TryHackMeVerified
Operational Trace
Solution Delivery Analyst
Nov 2023 – May 2024Deloitte USI | Red Team & Application Security
- # Ran full-scope red team and application security engagements across 5+ enterprise networks, surfacing 15+ critical and high-severity findings spanning web and API applications, Active Directory environments, and internal infrastructure.
- # Designed and executed MITRE ATT&CK-aligned adversary simulations spanning initial access, execution, persistence, privilege escalation, defense evasion, credential access, lateral movement, and command and control, emulating realistic threat actor behavior across the attack lifecycle.
- # Traced untrusted input from source to sink and chained multiple web and API vulnerabilities into reliable end-to-end exploits, bypassing authentication through flaws such as JWT abuse, IDOR, stored XSS, and SQL injection, and reaching remote code execution via command injection, insecure deserialization, file upload, and SSTI.
- # Compromised Active Directory environments end to end using Kerberoasting, AS-REP Roasting, delegation and DACL abuse, credential dumping, cross-domain trust abuse, and Golden/Silver ticket forgery for persistence.
- # Defeated layered endpoint defenses (PowerShell CLM, AppLocker, WDAC, JEA, LAPS, 2FA) and delivered in-memory payloads that evaded enterprise EDR via process injection, process hollowing, and direct syscalls.
- # Developed custom Python and PowerShell offensive tooling to automate enumeration, privilege escalation, credential extraction, and post-exploitation, improving exploit reliability by ~50% and cutting manual effort by ~40%.
- # Authored client-ready reports mapping complete attack chains to detection gaps and prioritized remediation, supporting client remediation and detection improvements for both technical and executive stakeholders.
Risk Advisory Intern
Jun 2022 – Jul 2022Deloitte USI
- # Executed end-to-end penetration testing on 2 enterprise applications, uncovering and reporting 4 critical vulnerabilities impacting system Confidentiality, Integrity, and Availability.
- # Combined SAST (Fortify SCA), DAST (WebInspect, HCL AppScan), and manual testing (Burp Suite Pro), achieving ~30% more coverage than automated scanning alone.
- # Tested 10+ high-value REST API endpoints with Burp Suite Pro and Postman, uncovering authentication, authorization, and input-validation flaws.
- # Scripted repeatable vulnerability-detection workflows that cut manual effort by ~20% and standardized assessments across the team.
Tactical Stacks
Offensive Ops
Active DirectoryADCS AttacksEDR/AV EvasionProcess InjectionLateral Movement
Systems & Programming
Win32 APIsDirect SyscallsPythonPowerShellC#Bash
Arsenal
Burp SuiteCobalt StrikeMetasploitBloodHoundGhidraIDA Pro
Defense Infrastructure
DockerAnsiblePKIAES/HashingSIEM Engineering