About
CEH v13-certified cybersecurity professional with hands-on experience in vulnerability assessment, network security, log analysis, and incident response across web, API, mobile, cloud (AWS), and container environments. Skilled in security monitoring and threat detection using Wazuh (SIEM/XDR), vulnerability scanning with Nessus and OpenVAS, and network traffic analysis with Wireshark. Strong understanding of TCP/IP, DNS, HTTP/HTTPS, VPNs, firewalls, and IDS/IPS. Applies a structured methodology — footprinting through reporting — to identify, investigate, and document security threats including malware, phishing, and insider threats. Builds Python-based automation for security operations and AI/LLM-driven security analysis tools. Currently pursuing OSCP; 50+ HackTheBox machines, 200+ TryHackMe rooms, and full PortSwigger Web Security Academy completion.
Skills & Expertise (45)
Work Experience
Content Creator
PentestByHP
Jan 2025 - Present
Produce cybersecurity and threat-analysis tutorials, documenting technical findings clearly for a growing learner community — reinforcing strong documentation and communication skills.
Penetration Tester
Independent Labs & Projects
Jan 2022 - Present
Investigated and exploited 50+ HackTheBox machines and 200+ TryHackMe rooms, documenting findings and remediation steps consistent with incident-reporting practices. Applied structured CEH methodology (footprinting through reporting) and OSCP-style testing on Proving Grounds to identify vulnerabilities and assess risk. Performed vulnerability assessments and analyzed network, application, and system logs to detect exploitable weaknesses and potential threats. Conducted network security testing (TCP/IP, DNS, VPN) and Active Directory security assessments; investigated API vulnerabilities (IDOR/BOLA, JWT, SSRF). Built Python automation for reconnaissance, log analysis, and exploit chaining, reducing manual investigation time. Evaluated cloud-native and container security (Docker, Kubernetes, Vault) from a threat-detection and hardening perspective.
Web Security Researcher
PortSwigger Web Security Academy
Jan 2025 - Jan 2026
Completed all PortSwigger Web Security Academy labs, including Expert-level chained exploitation scenarios, sharpening log-analysis and threat-identification skills. Mastered detection and analysis of SQLi, XSS, SSRF, XXE, CSRF, OAuth 2.0 flaws, and HTTP Request Smuggling using Burp Suite Professional.
Education
Bachelor of Computer Applications (B.C.A) - Amity University Online
- · Afghanistan
Certified Ethical Hacker Training - 3.0 University, Mumbai
- 2025 · Afghanistan
Certifications
Certified Ethical Hacker (CEH v13)
EC-Council · 2025
Junior Penetration Tester & Web Fundamentals
TryHackMe · 2024
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (45)
Click a skill to find developers with the same skill