Cybersecurity Innovation Builder

Design by Nontawatt Saraman
R0 Cyber · SRAN · QSense · ARAK

Welcome — a portfolio of the cybersecurity products I've designed and built, spanning process-level network visibility, log management, threat detection, and post-quantum readiness.
Click a screenshot to visit each product

ยินดีต้อนรับ — หน้านี้รวบรวมผลงานการออกแบบและพัฒนาผลิตภัณฑ์ด้าน ความมั่นคงปลอดภัยไซเบอร์ ตั้งแต่การมองเห็นเครือข่ายระดับ process, การจัดการ log, การตรวจจับภัยคุกคาม ไปจนถึงความพร้อมรับมือยุคควอนตัม
คลิกที่ภาพหน้าจอเพื่อเข้าชมแต่ละผลิตภัณฑ์

◆ ◆ ◆

Work · Productsผลงาน · ผลิตภัณฑ์ // 9 products

AGENTIC AI PENETRATION TESTINGR0 Cyber — Local AI for Pen-testing NEW
R0 Cyber — Agentic AI penetration testing harness

A sovereign, autonomous pen-testing harness — agentic AI that runs on your own infrastructure

Harness สำหรับทดสอบเจาะระบบแบบอัตโนมัติ — Agentic AI ที่รันในองค์กรคุณเอง

An agentic-AI penetration testing and vulnerability assessment harness that plans, chooses tools, exploits and interprets results like a professional tester — but runs entirely local and offline. Models, data and evidence stay in Thailand under your control. You set the scope and Rules of Engagement; every high-impact action needs human approval, with a kill switch and full audit log.

Harness ทดสอบเจาะระบบและประเมินความเสี่ยงด้วย Agentic AI ที่วางแผน เลือกเครื่องมือ โจมตี และตีความผลได้เหมือนผู้ทดสอบมืออาชีพ — แต่รันภายในองค์กรแบบ local/offline ทั้งหมด โมเดล ข้อมูล และหลักฐานอยู่ในประเทศไทยภายใต้การควบคุมขององค์กร คุณกำหนด Scope และ Rules of Engagement เอง ทุกการกระทำที่มีผลกระทบสูงต้องผ่าน Human Approval พร้อม Kill Switch และ Audit Log

  • Sovereign AI — models, data and results stay in-country, never sent to overseas cloud
  • Sovereign AI — โมเดล ข้อมูล และผลอยู่ในประเทศ ไม่ส่งออกไป cloud ต่างประเทศ
  • Autonomous operation — plans, selects tools and adapts within the authorized scope only
  • ทำงานอัตโนมัติ — วางแผน เลือกเครื่องมือ และปรับแผนได้เอง ภายในขอบเขตที่อนุญาตเท่านั้น
  • Reproducible evidence — PoC, artifacts and remediation you can verify and replay
  • หลักฐานทำซ้ำได้ — PoC หลักฐานประกอบ และข้อเสนอแนะที่ตรวจสอบและทำซ้ำได้
  • Human-controlled — kill switch, audit log and human approval on high-impact actions
  • ควบคุมโดยมนุษย์ — kill switch, audit log และ human approval สำหรับการกระทำผลกระทบสูง
  • Follows PTES and OWASP — AI handles the repeatable work, experts own the judgment calls
  • อ้างอิง PTES และ OWASP — AI รับงานที่ทำซ้ำได้ ส่วนการตัดสินใจสำคัญเป็นของผู้เชี่ยวชาญ
Agentic AI · Local / Offline · PTES · OWASP · Kill Switch · Audit Log
Visit r0cyber.com →เยี่ยมชม r0cyber.com →
CYBER FIRST AID & INCIDENT RESPONSELastSafe HelpBox NEW
LastSafe HelpBox — Cyber First Aid Kit

Cyber first aid for the critical first hour — before recovery begins

ชุดปฐมพยาบาลไซเบอร์สำหรับชั่วโมงแรก — ก่อนการกู้คืนจะเริ่ม

A cyber first-aid kit for the first hour after an incident. Open the box and you know what to do straight away: stop the damage, assess the symptoms, preserve evidence and hand over to the recovery team — step by step, ready to use even when no expert is on site.

ชุดปฐมพยาบาลไซเบอร์สำหรับชั่วโมงแรกหลังเกิดเหตุ เปิดกล่องแล้วรู้ทันทีว่าต้องทำอะไร: หยุดความเสียหาย ประเมินอาการ เก็บหลักฐาน และส่งต่อทีมกู้ระบบอย่างเป็นขั้นตอน พร้อมใช้ได้ทันที แม้ไม่มีผู้เชี่ยวชาญอยู่หน้างาน

  • Four steps of cyber first aid: Stop the damage · Assess · Stabilize · Hand over
  • สี่ขั้นตอนปฐมพยาบาลไซเบอร์: หยุดความเสียหาย · ประเมินอาการ · คงสภาพ · ส่งต่อ
  • Guided playbook — open it and know where to start, no incident-response expertise required
  • คู่มือนำทาง — เปิดมาแล้วรู้ว่าเริ่มตรงไหน ไม่ต้องเป็นผู้เชี่ยวชาญ IR
  • Vital-signs monitor, first-aid assistant and a case file ready to hand to the recovery team
  • เครื่องวัดสัญญาณชีพระบบ ผู้ช่วยปฐมพยาบาล และแฟ้มเหตุการณ์พร้อมส่งต่อทีมกู้ระบบ
  • Read-only by design — preserves evidence and changes nothing on the original system
  • ทำงานแบบ read-only — รักษาหลักฐานและไม่เปลี่ยนแปลงระบบต้นฉบับ
Incident Response · Read-only · Evidence · Triage · Playbook
Visit lastsafe.net →เยี่ยมชม lastsafe.net →
QUANTUM-SAFE TLS GATEWAYQSense Gate NEW
QSense Gate architecture

Quantum-safe TLS Gateway

เกตเวย์ TLS ที่ปลอดภัยจากควอนตัม วางหน้าระบบเดิม — แค่ชี้ DNS มา

A gateway that puts post-quantum encryption (hybrid ML-KEM) in front of websites, IoT/OT devices, databases and remote access — blunting “Harvest Now, Decrypt Later” attacks without changing a line on the origin servers. Certificate lifecycle and a web application firewall come with it.

เกตเวย์ที่เพิ่มการเข้ารหัสยุคหลังควอนตัม (hybrid ML-KEM) ให้เว็บไซต์ อุปกรณ์ IoT/OT ฐานข้อมูล และการเข้าถึงระยะไกล — ลดความเสี่ยง “Harvest Now, Decrypt Later” โดยไม่ต้องแก้ไขเซิร์ฟเวอร์ต้นทางเลย พร้อมระบบจัดการใบรับรองและ web application firewall ในตัว

  • PQC Edge: hybrid X25519MLKEM768 over TLS 1.3, with fallback for legacy browsers
  • PQC Edge: hybrid X25519MLKEM768 บน TLS 1.3 พร้อม fallback สำหรับเบราว์เซอร์รุ่นเก่า
  • Protects existing systems as-is — secure forwarding to the origin, nothing to install
  • ปกป้องระบบเดิมได้ทันที — ส่งต่อไปยังต้นทางอย่างปลอดภัย ไม่ต้องติดตั้งอะไรเพิ่ม
  • Beyond the web: MQTT, Modbus/TCP, OPC-UA, drone C2, databases, and SSH/RDP/VNC with mTLS
  • ไม่ใช่แค่เว็บ: MQTT, Modbus/TCP, OPC-UA, ระบบสั่งการโดรน, ฐานข้อมูล และ SSH/RDP/VNC ด้วย mTLS
  • WAF on OWASP Top 10, rate limiting and GeoIP blocking · automatic certificate issue and renewal
  • WAF ตาม OWASP Top 10, rate limiting และ GeoIP blocking · ออกและต่ออายุใบรับรองอัตโนมัติ
  • Live dashboard with a 3D globe and PQC status · runs on cloud, dedicated instance or on-premises
  • แดชบอร์ดเรียลไทม์ ลูกโลก 3 มิติ และสถานะ PQC · ใช้ได้ทั้ง cloud, dedicated instance และ on-premises
FIPS 203 · X25519MLKEM768 · TLS 1.3 · OpenSSL 3.5 · OWASP
Visit gate.qsenselab.com →เยี่ยมชม gate.qsenselab.com →
MFA & IDENTITY SECURITYMFAwall NEW
MFAwall — CIPAT × QSense MFA initiative

An MFA checkpoint in front of any login — no code changes

เพิ่มด่าน MFA หน้าเว็บเดิม — ไม่ต้องแก้โค้ดแม้แต่บรรทัดเดียว

A CIPAT × QSense initiative that puts Multi-Factor Authentication in front of existing websites through QSense Gate — guarding admin pages and critical paths with TOTP and Passkey so a leaked password alone is never enough. One gateway, one policy, live in about 5 minutes with zero changes to the origin system.

กิจกรรมโดยสมาคมส่งเสริมนวัตกรรมเทคโนโลยี (CIPAT) ร่วมกับ QSense เพิ่มการยืนยันตัวตนแบบหลายปัจจัย (MFA) หน้าเว็บไซต์เดิมผ่าน QSense Gate — ปกป้องหน้า Admin และเส้นทางสำคัญด้วย TOTP และ Passkey แม้รหัสผ่านรั่วก็ยังเข้าไม่ได้ นโยบายรวมที่เกตเวย์เดียว เริ่มได้ใน ~5 นาที โดยไม่แก้ระบบต้นทาง

  • Verify: TOTP authenticator and Passkey before login, admin or any critical path (path policy)
  • Verify: ยืนยันด้วยแอป Authenticator (TOTP) และ Passkey ก่อนถึงหน้า login, admin หรือ path สำคัญ
  • Defend: OWASP filtering (SQLi/XSS), bot control, rate limiting and GeoIP blocking
  • Defend: กรองภัยตาม OWASP (SQLi/XSS), จัดการ bot, rate limiting และบล็อกตามประเทศ (GeoIP)
  • Future: hybrid ML-KEM key exchange over TLS — blunts “Harvest Now, Decrypt Later”
  • Future: แลกกุญแจแบบ hybrid ML-KEM บน TLS — ลดความเสี่ยง “Harvest Now, Decrypt Later”
  • Zero-code deployment — existing website and passwords keep working; every auth event is logged
  • ติดตั้งแบบ zero-code — เว็บและรหัสผ่านเดิมใช้ต่อได้ พร้อมบันทึกเหตุการณ์ยืนยันตัวตนเพื่อการตรวจสอบ
TOTP · Passkey · OWASP · ML-KEM · Zero-code
Visit mfawall.cipat.or.th →เยี่ยมชม mfawall.cipat.or.th →
NETWORK DETECTION & RESPONSESRAN NetApprove
SRAN NetApprove screen

Self-learning network defense — no signatures, no noise

ป้องกันเครือข่ายที่เรียนรู้ได้เอง — ไม่ใช้ signature ไม่มี noise

Detects threats and responds automatically with AI, without relying on signatures — cutting false positives and containing threats fast: from detection to containment in under 5 seconds.

ตรวจจับภัยคุกคามและตอบสนองอัตโนมัติด้วย AI โดยไม่พึ่ง signature ลด false positive และกักกันภัยได้รวดเร็ว — ตรวจพบจนถึงกักกันภายในไม่ถึง 5 วินาที

  • AI anomaly detection via a 7-layer ML ensemble, signature-free
  • AI anomaly detection แบบ 7-layer ML ensemble ปราศจาก signature
  • LLM-assisted incident triage in plain language
  • LLM ช่วย triage เหตุการณ์เป็นภาษาคนอ่านเข้าใจ
  • Automated response via SOAR adapters (firewall, switch, RADIUS, EDR)
  • ตอบสนองอัตโนมัติผ่าน SOAR adapter (firewall, switch, RADIUS, EDR)
  • Compliance dashboards: NIST CSF, ISO 27001, PCI-DSS
  • แดชบอร์ด compliance: NIST CSF, ISO 27001, PCI-DSS
ML Ensemble · SOAR · DPI · Kill-chain
Visit netapprove.sran.net →เยี่ยมชม netapprove.sran.net →
LOG MANAGEMENTSRAN Metalog
SRAN Metalog screen

Centralize every log from every device — intelligently

รวบรวมทุก log จากทุกอุปกรณ์อย่างชาญฉลาด

A log management platform for operations, security and compliance teams — consolidating logs from many sources into one place, searchable in milliseconds, and built to meet Thailand's Computer Crime Act §26.

แพลตฟอร์มจัดการ log สำหรับทีม operations, security และ compliance รวม log จากหลายแหล่ง เข้าสู่ที่เดียว ค้นหาได้ในระดับมิลลิวินาที ออกแบบมาให้รองรับ พ.ร.บ. คอมพิวเตอร์ มาตรา 26 ของไทย

  • Ingests 20+ log formats + cloud APIs (CloudTrail, M365, Workspace, Okta)
  • รับ log 20+ รูปแบบ + cloud API (CloudTrail, M365, Workspace, Okta)
  • ~90% Zstandard compression · millisecond search via DuckDB
  • บีบอัด Zstandard ~90% · ค้นหาผ่าน DuckDB ระดับมิลลิวินาที
  • AI Log Analysis + alerting mapped to MITRE ATT&CK
  • AI Log Analysis + แจ้งเตือนแบบ map กับ MITRE ATT&CK
  • SHA-256 tamper-evident logs and post-quantum log forwarding
  • SHA-256 tamper-evident และ post-quantum log forwarding
DuckDB · Zstandard · MITRE ATT&CK · ML-KEM-768
Visit metalog.sran.net →เยี่ยมชม metalog.sran.net →
HONEYPOT & THREAT INTELHackrAlert
HackrAlert screen

Trap Every Threat — proactive defense that catches them all

Trap Every Threat — ดักจับทุกภัยด้วยการป้องกันเชิงรุก

An enterprise honeypot platform that detects, captures and alerts on attacks in real time — so you see threats before an attack succeeds. Deploys in under 10 minutes.

แพลตฟอร์ม honeypot ระดับองค์กรที่ตรวจจับ จับภาพ และแจ้งเตือนการโจมตีแบบเรียลไทม์ ให้เห็นภัยคุกคามก่อนที่การโจมตีจะสำเร็จ ติดตั้งได้ใน 10 นาที

  • Real-time alerts via LINE and email + global attack map
  • แจ้งเตือนเรียลไทม์ผ่าน LINE และอีเมล + แผนที่โจมตีทั่วโลก
  • Captures SSH/RDP/Telnet, malware, port scans and web attacks (SQLi/XSS/LFI)
  • จับ SSH/RDP/Telnet, malware, port scan และ web attack (SQLi/XSS/LFI)
  • Emulates ICS/SCADA (Modbus, S7comm, BACnet) and IoT/OT
  • จำลอง ICS/SCADA (Modbus, S7comm, BACnet) และ IoT/OT
  • Detects medical-device reconnaissance (DICOM, HL7, PACS)
  • ตรวจจับการสำรวจอุปกรณ์การแพทย์ (DICOM, HL7, PACS)
Honeypot · ICS/SCADA · LINE Alert · Threat Intel
Visit hackralert.com →เยี่ยมชม hackralert.com →
POST-QUANTUM READINESSQSense
QSense screen

Enterprise PQC · Quantum-Safe · CRQC Readiness

Helps organizations prepare for the quantum-computing threat, measuring “Harvest Now, Decrypt Later” and “Trust Now, Forge Later” risk by automatically discovering cryptography across the network — agentless.

ช่วยองค์กรเตรียมพร้อมรับภัยจากคอมพิวเตอร์ควอนตัม วัดความเสี่ยง “Harvest Now, Decrypt Later” และ “Trust Now, Forge Later” ด้วยการค้นพบการเข้ารหัสทั่วทั้งเครือข่ายแบบอัตโนมัติ ไม่ต้องลง agent

  • Automated Cryptographic Discovery, zero-touch (no agent)
  • Automated Cryptographic Discovery แบบ zero-touch (no agent)
  • Real-time cryptographic bill of materials (CBOM) + Crypto Maturity Score
  • บัญชีรหัสลับ (CBOM) เรียลไทม์ + Crypto Maturity Score
  • Classifies assets as Classical / Hybrid / PQC with a supply-chain graph
  • จำแนกสินทรัพย์เป็น Classical / Hybrid / PQC พร้อมกราฟ supply chain
  • Supports NIST FIPS 203/204/205 and CNSA 2.0 — a Find → Rate → Ready cycle
  • รองรับ NIST FIPS 203/204/205 และ CNSA 2.0 — วัฏจักร Find → Rate → Ready
FIPS 203/204/205 · CBOM · CNSA 2.0 · Zero-touch
Visit qsenselab.com →เยี่ยมชม qsenselab.com →
QUANTUM-SAFE CONNECTIVITYIronPath NEW
IronPath logo
EDITION 1 Hardware Appliance
Site A IronPath QKD + PQC Hybrid Tunnel IronPath Site B

A hardware box placed end-to-end between two sites — wrapping all traffic in a PQC tunnel automatically, nothing to install on endpoints.

Quantum can’t decrypt it — a quantum-safe tunnel

“Quantum can’t decrypt it” — อุโมงค์เชื่อมต่อที่ปลอดภัยจากควอนตัม

Defends against “Harvest Now, Decrypt Later” (HNDL) attacks — a one-click VPN tunnel that blends classical and post-quantum cryptography, so traffic captured today cannot be decrypted by tomorrow’s quantum computers.

ป้องกันการโจมตีแบบ “Harvest Now, Decrypt Later” (HNDL) — อุโมงค์ VPN แบบคลิกเดียว ที่ผสานการเข้ารหัสแบบคลาสสิกกับ post-quantum ทำให้ข้อมูลที่ถูกดักวันนี้ ไม่สามารถถอดรหัสได้ด้วยคอมพิวเตอร์ควอนตัมในอนาคต

  • Hybrid PQC tunnel: X25519 + ML-KEM + Classic McEliece (WireGuard / rosenpass)
  • อุโมงค์ PQC แบบไฮบริด: X25519 + ML-KEM + Classic McEliece (WireGuard / rosenpass)
  • Automatic pre-shared key rotation every ~2 minutes for forward secrecy
  • หมุนเปลี่ยน pre-shared key อัตโนมัติทุก ~2 นาที เพื่อ forward secrecy
  • One-click secure connection — no terminal or manual config
  • เชื่อมต่อปลอดภัยด้วยคลิกเดียว — ไม่ต้องตั้งค่าผ่าน terminal
  • Hardware appliance or Windows/WSL software, with a built-in secure browser
  • มีทั้งแบบ hardware appliance และซอฟต์แวร์ Windows/WSL พร้อมเบราว์เซอร์ปลอดภัยในตัว
FIPS 203 · ML-KEM · Classic McEliece · WireGuard
Read more →อ่านเพิ่มเติม →

Aboutเกี่ยวกับ // about me

Nontawatt Saraman
Nontawatt Saraman
Cybersecurity Product Designer
20+ years of experienceประสบการณ์กว่า 20 ปี

A designer and builder of cybersecurity products who believes good defense starts with seeing — seeing what is happening on the network, understanding what it means, and only then acting with confidence. Everything is designed to run on your own infrastructure; sensitive data never has to leave.

ผู้ออกแบบและสร้างผลิตภัณฑ์ด้านความมั่นคงปลอดภัยไซเบอร์ ที่เชื่อว่าการป้องกันที่ดีเริ่มต้นจากการ “มองเห็น” — เห็นว่าอะไรกำลังเกิดขึ้นในเครือข่าย เข้าใจความหมายของมัน แล้วจึงลงมือป้องกันได้อย่างมั่นใจ ผลงานทั้งหมดออกแบบให้ทำงานบนระบบขององค์กรเอง ข้อมูลสำคัญไม่ต้องออกไปไหน

Roles & committeesบทบาทและคณะกรรมการ
  • Board member, Digital Council of Thailand (DCT)
  • กรรมการสภาดิจิทัลเพื่อเศรษฐกิจและสังคมแห่งประเทศไทย (DCT)
  • Honorary President, Cyber Innovation Technology Promotion Association (CIPAT)
  • นายกกิตติมศักดิ์ สมาคมส่งเสริมนวัตกรรมเทคโนโลยีไซเบอร์ (CIPAT)
  • Co-founder, Digital Operations & Research Center for a Sustainable Future
  • ผู้ร่วมก่อตั้งศูนย์ปฏิบัติการและวิจัยดิจิทัลเพื่ออนาคตที่ยั่งยืน
Founderผู้ก่อตั้ง
  • Co-founder, SRAN Technology
  • ผู้ร่วมก่อตั้ง SRAN Technology
  • Founder, QSense — PQC Readiness Platform
  • ผู้ก่อตั้ง QSense — PQC Readiness Platform
  • Founder, ARAK Software
  • ผู้ก่อตั้ง ARAK Software
◆ ◆ ◆

Contactติดต่อ // contact

Interested in working together or talking products? Reach me at สนใจร่วมงานหรือพูดคุยเรื่องผลิตภัณฑ์ ติดต่อได้ที่

Metalog NetApprove HackrAlert QSense

EN | TH