Offensive Security Researcher focused on web application and API security, with hands-on experience identifying and validating real-world vulnerabilities through authorized penetration testing and responsible disclosure. Specializing in high-impact security issues such as authentication bypasses, broken access control, and sensitive data exposure across enterprise, open-source, and academic systems.
Critical vulnerabilities identified and ethically disclosed to enterprise platforms and academic institutions
Research-grade offensive security frameworks for vulnerability validation
Research-grade authorization testing framework designed to detect and validate real access control vulnerabilities in web applications. Focuses on identifying issues like broken access control, IDOR, and privilege escalation with high-confidence results.
$ wafstrike --target https://target-app.com --mode auth-validation
[*] Initializing WAFStrike Authorization Testing Framework
[*] Target: https://target-app.com
[*] Mode: Authorization Validation
---
[+] Analyzing WAF filtering rules...
[+] Mapping backend enforcement logic...
[!] Inconsistency detected: /api/admin/users
[β] Vulnerability confirmed: Broken Access Control (CVSS 8.2)
[*] Generating proof-of-concept...
[β] Report generated: wafstrike_report_20260516.pdf
Full-scope penetration testing and security research projects
Led a black-box penetration test of a production WordPress web application protected by Wordfence WAF. Discovered critical vulnerabilities in the WPBakery plugin, including authenticated Stored XSS and Local File Inclusion (LFI).
Conducted responsible security research across major Pakistani academic institutions, identifying critical vulnerabilities in admission systems, authentication mechanisms, and administrative interfaces.
Technical whitepapers and offensive security research
May 16, 2026
Published an offensive security whitepaper focused on identifying exposed origin infrastructure behind reverse proxies and CDN environments during authorized penetration tests. The research covers reverse proxy trust validation, backend timeout analysis, SSRF-based origin validation, and infrastructure fingerprint correlation techniques used in real-world security assessments.
Professional certifications and specialized training programs
European Union Agency for Cybersecurity (ENISA)
Issued: January 2026
EU4Digital Facility, European Union
Issued: December 2025 | Expires: October 2028
Qualys
Issued: September 2024
The SecOps Group
Issued: November 2024 | ID: 10233311
The SecOps Group
Issued: October 2024 | ID: 8787025
Cybrary
Issued: June 2023
Harvard University
Issued: January 2023
Stanford Online
Issued: March 2022
SkillFront
Verification ID: 92068255735788
Simplilearn SkillUp
Verification ID: 10186837
Reach out for security research collaboration or vulnerability disclosure