Back to Developers
Azam Moh

Azam Moh

Penetration Tester

Aurangabad, India 5+ yrs exp 95 · Outstanding

About

Certified Junior Penetration Tester (eJPTv2) and Certified Associate Penetration Tester (CAPT) with a Master of Science in Information Technology. Specialized expertise in network penetration testing, web application security, and vulnerability research. Demonstrated track record in identifying and responsibly disclosing security vulnerabilities through the HackerOne bug bounty platform. Proficient in the complete penetration testing lifecycle including information gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and professional reporting. Active contributor to the cybersecurity community with published technical write-ups, hands-on experience across Hack The Box and TryHackMe environments, and a strong foundation in OWASP Top 10 vulnerabilities. Passionate about advancing offensive security practices and continuously expanding knowledge in emerging attack vectors and defense evasion techniques.

Skills & Expertise (57)

Burp Suite Professional Advanced
8.0/10
3
Years Exp
OWASP Top 10 Advanced
8.0/10
3
Years Exp
Kali Linux Advanced
8.0/10
3
Years Exp
SQL Injection Advanced
7.5/10
3
Years Exp
Nmap Advanced
7.5/10
3
Years Exp
Active Directory Attacks Advanced
7.5/10
3
Years Exp
Risk Assessment Advanced
7.0/10
3
Years Exp
Python Advanced
7.0/10
3
Years Exp
Network Traffic Analysis Advanced
7.0/10
3
Years Exp
Metasploit Framework Advanced
7.0/10
3
Years Exp
Postman Aircrack-ng Bettercap Responder Tcpdump Amass ARP Spoofing Nuclei Ubuntu Linux Windows Server Windows 10/11 bash scripting WIRESHARK HTML CSS JavaScript Php MySql VMWARE VirtualBox OWASP Testing Guide PTES Remediation recommendations OWASP ZAP Payload crafting Recon-NG Gau Google Dorking DNS Enumeration Sublist3r SQLmap Nessus OpenVAS Nikto DALFOX Searchsploit Assetfinder Mimikatz BloodHound LinPEAS Winpeas CrackMapExec Lateral Movement persistence mechanisms Credential Harvesting Shodan Kerberoasting

Work Experience

Security Researcher and Technical Writer

Medium and Independent Platforms

Jan 2026 - Present

Published in-depth technical write-ups and tutorials documenting penetration testing techniques, tools usage, and proof-of-concept exploits for educational purposes. Authored comprehensive guides on advanced attack techniques including SMB Relay attacks, Windows and Linux privilege escalation vectors, Active Directory enumeration and exploitation, and network pivoting. Documented end-to-end penetration testing methodologies covering reconnaissance, vulnerability assessment, exploitation, post-exploitation, and professional reporting phases. Contributed to the global cybersecurity community by providing detailed explanations of CTF challenge solutions, tool comparisons, and defensive remediation strategies. Created educational content on OWASP Top 10 vulnerabilities, secure coding practices, and common misconfigurations in web applications and cloud environments.

Security Researcher and Lab Specialist

Hack The Box, TryHackMe, VulnHub

Jan 2022 - Present

Completed over 75 TryHackMe rooms and learning paths, including the complete Junior Penetration Tester pathway covering web hacking, network exploitation, and privilege escalation modules. Compromised 20+ Hack The Box machines across both Linux and Windows operating systems, employing techniques including service enumeration, exploit research, buffer overflow exploitation, and kernel privilege escalation. Designed and built a comprehensive VMware-based home penetration testing lab and successfully exploited 12+ deliberately vulnerable machines from VulnHub and PentesterLab. Practiced real-world attack scenarios including Active Directory exploitation, web application attacks, and lateral movement techniques in isolated lab environments. Developed proficiency in both automated scanning tools and manual exploitation methodologies across diverse target environments.

Independent Security Researcher

HackerOne Bug Bounty Platform

Oct 2024 - Mar 2025

Conducted a comprehensive five-month vulnerability research campaign, identifying and responsibly reporting six confirmed security vulnerabilities across multiple production platforms and applications. Discovered and documented critical and medium-severity findings including Self-XSS vulnerabilities, gRPC Reflection Exposure, and sensitive Information Disclosure issues affecting user data and system configurations. Produced detailed, professional vulnerability reports with clear proof-of-concept demonstrations, step-by-step reproduction instructions, impact assessments, and actionable remediation recommendations. Followed responsible disclosure practices and collaborated with security teams to verify findings and support remediation efforts. Performed in-depth manual testing of web applications, APIs, and server configurations using Burp Suite, Nmap, and custom reconnaissance scripts.

Education

Master of Science (M.Sc.) in Information Technology - Mahatma Gandhi Mission (MGM)

2021 - 2023 · Afghanistan

Bachelor of Science (B.Sc.) in Information Technology - Dr. Babasaheb Ambedkar Marathwada University (BAMU)

2018 - 2021 · Afghanistan

Certifications

Certified Junior Penetration Tester

INE Security · 2026

Certified Associate Penetration Tester

Hackvisor · 2025

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 15/15
💰 Rate 0/5
🏆 Certs 5/5
Verified 5/5
Total Score 95/100

Profile Overview

Member sinceSep 2026

Availability Details

Visa Status

Need Sponsorship

Relocation

Depends on Offer