Hack The Box — Global Rank #6
Reached Top 10 (#6) in Hack The Box's All-Time Hall of Fame among 100K+ hackers worldwide during the 2018–2019 period.
I am a Penetration Tester, Red Team Operator (CRTO), and Security Engineer focused on practical attack-path validation across web applications, APIs, Active Directory, internal networks, and cloud environments. My career started in vulnerability research and bug bounty hunting and evolved into enterprise VAPT, adversary simulation, and remediation-focused security engineering.
My work sits at the intersection of offensive security, engineering, and risk reduction: discover realistic attack paths, validate exploitability, communicate business impact, and support practical remediation.
I have worked across enterprise web applications, Active Directory environments, internal networks, cloud platforms, private bug-bounty programmes, and adversary-simulation exercises. In current and recent roles, I have translated technical findings into actionable remediation for engineering and infrastructure teams.
Reached Top 10 (#6) in Hack The Box's All-Time Hall of Fame among 100K+ hackers worldwide during the 2018–2019 period.
Our team achieved 3rd rank at the AWS Summit Dubai 2026 Agentic AI Hackathon, held at Dubai World Trade Centre.
CRTO credential from Zero-Point Security, complementing practical work in Active Directory, adversary simulation, lateral movement, and evasion.
Recognized in Yahoo's Hall of Fame following responsible disclosure of Stored XSS, Reflected XSS, and logic vulnerabilities.
Freelance Red Team Member from March 2021 to March 2023, performing black-box penetration testing and adversary emulation on enterprise targets.
Identified and responsibly disclosed a critical BitForex Exchange vulnerability through HackenProof with proof-of-concept details.
Publishes practical security write-ups and has delivered web-application-security teaching with hands-on labs and OWASP-focused material.
Conduct internal network and web-application VAPT; execute adversary simulations and Active Directory assessments; identify lateral-movement and privilege-escalation paths; and translate findings into actionable remediation aligned with UAE IA (NESA/ISR).
Designed and delivered web-application-security curriculum focused on OWASP Top 10 and secure coding, supported by hands-on labs that simulated practical VAPT scenarios.
Performed advanced offensive-security work across private bug-bounty programmes and enterprise web applications, including business-logic testing, high-severity vulnerability research, reporting, and red-team simulations.
Executed black-box penetration testing and adversary emulation against global enterprise targets, with proof-of-concept reporting and remediation guidance for engineering teams.
Started with independent vulnerability research, including Yahoo findings that led to Hall of Fame recognition and a critical BitForex Exchange disclosure through HackenProof.
My research background is rooted in hands-on exploitation. I document practical techniques and lessons from security testing, with published work covering Yahoo XSS, Python Pickle Deserialization, CouchDB exploitation, and Windows/Linux privilege escalation.
For security-engineering roles, offensive-security engagements, red-team collaboration, technical security projects, or cybersecurity education, connect through the channels below.