Cybersecurity
Hi, I’m Samy-James Carnet, also known online as Kronos, a cybersecurity engineer from Paris, France. I graduated from ESIEA in 2024 with a “Diplôme d’ingénieur” (Master of Engineering degree) specializing in cybersecurity, after completing my final-year internship at Dassault Systèmes as an R&D Cybersecurity Engineer.
Since graduating, I have focused heavily on offensive security and vulnerability research, combining hands-on practice, personal labs, CTFs and advanced certifications. I am currently certified OSCP, OSEP and OffSec AI Red Teamer (OSAI), and I am preparing for OSWE.
My main areas of interest include penetration testing, Active Directory security, Web and API security, cloud security, security tooling and AI Red Teaming. I also spend significant time exploring the security of RAG pipelines, agentic systems, MCP integrations, prompt injection, tool abuse, data exfiltration and other emerging AI attack surfaces.
During my time at Dassault Systèmes, I worked on bug bounty triage, vulnerability reproduction, PoC validation, CVSS assessment and remediation follow-up with product teams. I also conducted an internal penetration test on a cloud component before production release.
I am currently looking for offensive security, penetration testing, AppSec, product security and AI security opportunities where I can keep developing technically while contributing to real-world security research and assessments.
Music
Beyond cybersecurity, I am also a signed composer and multi-platinum music producer working with Universal Music, with more than 100 million cumulative streams. Music gives me a very different creative outlet and is a good counterbalance to the long technical sessions that usually come with security research.
Why this blog?
I originally created this blog to document what I learn, and that is still its main purpose. I use it to publish CTF write-ups, technical notes and deeper dives into topics I find interesting, including offensive security, Red Teaming, vulnerability research, exploit development, AI security and other areas I explore over time.
If you would like to discuss cybersecurity, offensive security, AI Red Teaming, research, job opportunities or collaboration, feel free to reach out through LinkedIn or email.