Accredited Security Credentials
Rigorous Industry certifications demonstrating offensive competence
CRTO – Certified Red Team Operator
Zero-Point Security
Adversarial operations using Cobalt Strike, defense evasion, and host security boundary exploitation.
CURRENT ENGAGEMENT
CJWPT – Junior Web Pentester
Hack & Fix
OWASP Web top 10 payload injection, parameter pollution, and basic authorization checks.
Credential ID: 2091-5349-7151-6117
AI 100: Fundamentals
TCM Security
Security challenges and adversarial testing protocols targeting large language artificial intelligence engines.
Credential ID: cert_277wdj5j
Practical Help Desk
TCM Security
Focus on systems engineering, enterprise network communications, and administrative baseline security guides.
Credential ID: cert_bcqgb21v
Honors & Global Responsible Disclosures
Acknowledge contribution lists and institutional Synack recognitions
Federal Courts of the United States
Synack VDP · June 2026
Identified and reported vulnerabilities within judicial domains; patched and acknowledged in the official list of contributors.
U.S. Department of Education
Synack VDP · June 2026
Secured Federal Education nodes by identifying logical vulnerabilities via Synack coordination.
Slapfive Authorized Credentials
May 2026
Disclosed a vulnerability on auth.slapfive.com; assigned official tracker token SL-10462.
U.S. Dept of Health and Human Services (HHS)
Synack VDP · May 2026
Identified security misconfigurations within Federal public health portals; credited officially.
World Bank Group (VDP acknowledged)
April 2026
Disclosed critical domain broken link hijacks tracked officially under token index: VDP-2026-1027.
U.S. Department of Justice
Synack VDP · 2026
Disclosed critical vulnerabilities affecting the federal justice department portals, acknowledged officially by the VDP program.
Morgan Stanley
Responsible Disclosure · 2026
Acknowledged for discovering and reporting a critical security vulnerability within Morgan Stanley's infrastructure, ensuring proactive mitigation.
Hack Secure CTF WAR HOMELAB
April 2025
Awarded 1st place in the CTF championship assessing various exploitation pathways and domain penetration steps.
Community Speeches & Speaking Sessions
Advocating cyber awareness and teaching defensive red teaming models
Breaking & Building: A Practical Intro to Cybersecurity
April 2026 · Khulna University of Engineering & Technology
- Conducted KCSC's first physical session, bringing cybersecurity topics directly in-person to students.
- Delivered live demonstrations of web exploits in isolated environments to clarify testing frameworks.
- Emphasized the critical attacker mindset to build stronger defensive architectures.
Hack Your Career: Landing Jobs & Doing Real Work in Cybersecurity
May 3, 2026 · Career Roadmap Guidelines
- Detailed critical career paths spanning penetration testing, incident analysis, and Red Operations.
- Shared practical portfolio guidelines, interview expectations, and continuous certification pathways.
- Delivered a real Purple Team simulation displaying concurrent exploit and log-level capture.
Technical Blogs & Lab Writeups
Deep walks detailing offensive assessments, Linux vulnerabilities, and Active Directory tests
Breaking "Exception" — A Medium Linux Lab Writeup
Enumeration, automated scans, exploiting misconfigurations, and root escalations on Linux challenge frameworks.
How to Start Your Cybersecurity Journey as a Student
Getting past the static noise to build practical hands-on laboratories, CTF strategies, and solid peer mentoring paths.
When a Single Header Bypasses Your Access Control
Inside access loophole vectors where plain header variables can manipulate authorization filters.
CRTP Exam Preparation and My Experience
Timeline tracking, prep courses completed, key command structures, and domain strategy of our Altered Security test.
Advanced PowerShell Security: Bypasses & Defense
Analyzing AMSI bypass routines, script block metrics, logging capabilities, and Constrained Language boundaries.
Hack The Box — Querier Walkthrough Guide
MSSQL configuration loop analysis, xp_cmdshell triggers, credential theft, and total domain administrator elevation.
TryHackMe — Startup CTF Walkthrough Writeup
FTP server enumeration, anonymous uploads, setting reverse shell vectors, and standard Linux local escalations.