Islamabad, Pakistan — Available for remote / hybrid

Abdul Moiz
breaks things so no one else can.

Third-year Cybersecurity student, Penetration Tester & Bug Bounty Researcher with hands-on experience in API security, OSINT, and authentication flaw discovery. I use Burp Suite, Nmap, Metasploit, and modern recon tooling to uncover business-logic and web application vulnerabilities.

15
Certifications
4
Internships
2024–
Active researcher
nmap -sV moiz.profile
01

$ whoami

I’m a third-year Cybersecurity student at the National University of Technology, Islamabad, with hands-on experience in penetration testing, API security, OSINT, and bug bounty research. I’m skilled in identifying and exploiting authentication and business-logic vulnerabilities using Burp Suite, Nmap, Metasploit, and modern vulnerability-scanning and OSINT tooling, with additional grounding in network security through my CCNA studies. I’m seeking a remote or hybrid internship or entry-level role in penetration testing, bug bounty research, or application security where I can apply practical offensive-security skills to real-world systems.

02

$ cat capabilities.json

Penetration Testing
  • Web & API testing
  • Authentication flaws
  • Business logic vulnerabilities
  • OWASP Top 10
OSINT & Recon
  • Footprinting & subdomain enumeration
  • Passive & active intelligence gathering
  • Digital forensics fundamentals
  • Password cracking
Network & Security
  • IPv4 / IPv6, LAN / WAN, TCP/IP
  • Segmentation, IDS / IPS, firewalls
  • ACLs, VLANs
  • Cloud networks
Tools & Frameworks
  • Burp Suite, Nmap, httpx
  • Wireshark, Metasploit, Nessus
  • Acunetix, Sn1per, OWASP ZAP
  • Gobuster, Subfinder, Recon-ng
Programming & Automation
  • Python, Bash, SQL
  • C++ scripting
  • Automation & exploit development
  • Kali Linux
03

$ tail -f engagement.log

[2024 — PRESENT]
Bug Bounty & Security Researcher
Freelance
  • Identify and report security vulnerabilities in web applications, APIs, and mobile platforms.
  • Specialize in API exploitation and authentication-flaw discovery across live targets.
  • Active Capture the Flag (CTF) competitor, applying offensive-security techniques under time pressure.
[JUL 2026 — SEP 2026]
VAPT Intern
Pakistan Cyber Emergency Response Team (PKCERT)
  • Performed reconnaissance and information gathering and ran vulnerability scans using Acunetix, Sn1per, and OWASP ZAP.
  • Conducted OSINT investigations and hands-on penetration testing engagements, followed by formal vulnerability reporting.
  • Competed in internal CTF challenges and participated in a cyber drill featuring cyberwarfare-themed CTF scenarios.
  • Applied Metasploit, Nmap, httpx, Subfinder, Shodan, Burp Suite, Recon-ng, Sherlock, Maigret, SpiderFoot, and theHarvester across engagements.
[AUG 2025 — SEP 2025]
Cybersecurity Intern
Cisco Networking Academy, UET Peshawar
  • Supported network defense simulations and conducted applied research on network security.
  • Gained hands-on exposure to firewalls, routers, and secure network design.
  • Assisted senior instructors in configuring training environments and documenting lab results.
[JUL 2025 — AUG 2025]
Cybersecurity Intern
Microsoft Learn Student Ambassadors (MLSA), UET Peshawar
  • Completed applied projects in ethical hacking fundamentals, network scanning, and information gathering.
  • Investigated session-security risks (cookies & cache), password cracking, and core system-security concepts.
  • Delivered project documentation and live demos showcasing practical problem-solving.
summary --total
Overall time active in field ~2.5 years (incl. freelance bug bounty & security research since 2024)
Formal internship experience ~5 months across 3 internships (2 completed, 1 active)
04

$ ls ./projects

Interceptor repo ↗

mitmproxy-based addon that captures and logs login requests, credentials, and session cookies for authorized security testing.

ns3cybermod repo ↗

Custom C++ module for the ns-3 network simulator adding plug-and-play attack/defense functions, built for an Information Security semester project.

ARP Spoofing Detector

Tool to detect ARP spoofing and poisoning attacks on local networks.

Wi-Fi Sensing Surveillance Grid repo ↗

Motion and presence sensing system using Channel State Information (CSI) on ESP32.

vibecoded-recon repo ↗

Read-only recon tool for common misconfigurations in AI-scaffolded (Next.js + Supabase + Vercel) web apps — checks for exposed Supabase RLS gaps, leaked API keys in JS bundles, open admin routes, wildcard CORS, and missing security headers.

05

$ cat education.md

BSc in Cybersecurity (3rd Year)
National University of Technology, Islamabad · Active member, University Cybersecurity Club
Coursework: Programming Fundamentals · Object-Oriented Programming · Computer Organization & Assembly Language · Information Assurance · Information Security · Network Security · Computer Networks · Database Systems · Vulnerability Assessment & Reverse Engineering · Malware Analysis · Penetration Testing · Artificial Intelligence · Cybersecurity
2024 — Present
06

$ ls -la ./Certificates

Let's find what others missed.

Open to remote or hybrid internships and entry-level roles in penetration testing, bug bounty research, and application security.