$ tail -f activity.log

Activity log

What I’ve done and made — newest first.

  1. Build

    I built a Windows app, “PasteDrawer”

    A clipboard history tool you pull out from the screen edge and paste from by drag and drop. The product site is now up.

    View details
  2. Build

    Released the game “Security Pachi-Slot”

    Released a Juggler-style browser slot parodying “security pachinko,” the meme for AI-driven vulnerability research.

  3. Build

    Released the game “Cheat Shogi”

    Released a shogi game where cheat cards bend the rules — play the CPU or a friend online with a room ID.

    View details
  4. Build

    Published the msfvenom one-liner generator

    Added a browser tool that generates msfvenom commands and listeners from a dropdown.

    View details
  5. Build

    Published the Web CheatSheet

    Added a pentest / CTF command and technique cheatsheet to the site.

    View details
  6. Build

    Relaunched yunolay.com

    Moved the blog to blog.yunolay.com and rebuilt this site as a home for my activity log and works.

    View details
  7. Career

    Moved to Fore-Z as Executive Officer

    Transferred from Executive Officer at Fore-co.ltd to Executive Officer at Fore-Z.

  8. Talk

    Spoke at OffSecLab Meetup in Shibuya

    Gave a talk “OSEE受験記 (OSEE exam write-up)” as Yunolay, introducing OSEE and my exam experience.

    View details
  9. Cert

    OffSec Exploitation Expert (OSEE)

    Earned by passing the EXP-401 (Advanced Windows Exploitation) exam — advanced exploit development including the Windows kernel.

    View details
  10. Career

    Started writing on note

    Published my first article — a self-introduction — on May 17, 2026, and have been posting on note since.

  11. Training

    Attended “Practical iOS Reverse Engineering” at OffensiveCon 2026

    Took Jiska Classen’s training on reverse engineering iOS apps, kernel and firmware.

    View details
  12. Training

    Attended “Windows Internals for Security Engineers” at OffensiveCon 2025

    Took Yarden Shafir’s training on Windows 11 kernel internals and security mechanisms.

    View details
  13. Cert

    HTB Certified Web Exploitation Expert (CWEE)

    Hack The Box’s advanced web exploitation certification.

    View details
  14. Career

    Executive Officer, Fore-co.ltd

    Executive management and security strategy.

  15. Talk

    Ran a workshop at RWPL in SECCON 13

    Ran my self-made challenge “RWPL Flowers” hands-on, walking through source-code leakage via LFI and RCE.

    View details
  16. Career

    Joined the Synack Red Team (SRT)

    Vulnerability research and red teaming.

    View details
  17. Cert

    HTB Certified Penetration Testing Specialist (CPTS)

    Hack The Box’s penetration testing certification.

    View details
  18. Career

    Security Engineer, Poruto-inc

    Vulnerability assessment and penetration testing.

  19. Career

    Started freelancing

    Independent security consulting and research.

  20. Cert

    Completed TryHackMe Advent of Cyber 2023

  21. Cert

    HTB Certified Web Exploitation Specialist (CWES, formerly CBBH)

    Hack The Box’s web exploitation certification, earned under its former name CBBH.

    View details
  22. Career

    Left GMO Cybersecurity by Ierae

    About two years and nine months of web/API assessments and mobile game anti-cheat analysis.

  23. Cert

    OffSec Certified Expert 3 (OSCE3)

    Awarded for holding all three of OSWE, OSEP and OSED.

    View details
  24. Cert

    OffSec Exploit Developer (OSED)

    Windows user-mode exploit development.

    View details
  25. Cert

    OffSec Experienced Penetration Tester (OSEP)

    Advanced penetration testing including evasion and Active Directory.

    View details
  26. Cert

    OffSec Web Expert (OSWE)

    White-box web application exploitation and exploit automation.

    View details
  27. Career

    Joined GMO Cybersecurity by Ierae

    Assessed PHP, REST API, GraphQL, gRPC and Cloud Firestore targets.

  28. Cert

    eLearnSecurity eWPTXv2

    Web Application Penetration Tester eXtreme.

    View details
  29. Cert

    eLearnSecurity eCPPTv2

    Certified Professional Penetration Tester.

    View details
  30. Cert

    OffSec Certified Professional (OSCP)

    The 24-hour hands-on penetration testing exam.

    View details
  31. Career

    Left LAC Co., Ltd.

    Operated IPS, IDS, WAF and sandboxes in the SOC (FireEye, Palo Alto, Cisco, Juniper).

  32. Career

    Joined LAC Co., Ltd. (SOC)

    Started my career in a security operations center.

Awards & rankings

  • Hack The Box global rank — peak #8

  • MBSD Cybersecurity Challenge — 2nd place

  • Hack The Box Open Beta Seasons III, IV, V, VI — Holo rank

  • picoCTF 10k+ points (General Skills 100%)

  • Member of CTF team 7h3B14ckKn1gh75 (Knights)