Abdul Moiz
breaks things so no one else can.
Third-year Cybersecurity student, Penetration Tester & Bug Bounty Researcher with hands-on experience in API security, OSINT, and authentication flaw discovery. I use Burp Suite, Nmap, Metasploit, and modern recon tooling to uncover business-logic and web application vulnerabilities.
$ whoami
I’m a third-year Cybersecurity student at the National University of Technology, Islamabad, with hands-on experience in penetration testing, API security, OSINT, and bug bounty research. I’m skilled in identifying and exploiting authentication and business-logic vulnerabilities using Burp Suite, Nmap, Metasploit, and modern vulnerability-scanning and OSINT tooling, with additional grounding in network security through my CCNA studies. I’m seeking a remote or hybrid internship or entry-level role in penetration testing, bug bounty research, or application security where I can apply practical offensive-security skills to real-world systems.
$ cat capabilities.json
- Web & API testing
- Authentication flaws
- Business logic vulnerabilities
- OWASP Top 10
- Footprinting & subdomain enumeration
- Passive & active intelligence gathering
- Digital forensics fundamentals
- Password cracking
- IPv4 / IPv6, LAN / WAN, TCP/IP
- Segmentation, IDS / IPS, firewalls
- ACLs, VLANs
- Cloud networks
- Burp Suite, Nmap, httpx
- Wireshark, Metasploit, Nessus
- Acunetix, Sn1per, OWASP ZAP
- Gobuster, Subfinder, Recon-ng
- Python, Bash, SQL
- C++ scripting
- Automation & exploit development
- Kali Linux
$ tail -f engagement.log
- Identify and report security vulnerabilities in web applications, APIs, and mobile platforms.
- Specialize in API exploitation and authentication-flaw discovery across live targets.
- Active Capture the Flag (CTF) competitor, applying offensive-security techniques under time pressure.
- Performed reconnaissance and information gathering and ran vulnerability scans using Acunetix, Sn1per, and OWASP ZAP.
- Conducted OSINT investigations and hands-on penetration testing engagements, followed by formal vulnerability reporting.
- Competed in internal CTF challenges and participated in a cyber drill featuring cyberwarfare-themed CTF scenarios.
- Applied Metasploit, Nmap, httpx, Subfinder, Shodan, Burp Suite, Recon-ng, Sherlock, Maigret, SpiderFoot, and theHarvester across engagements.
- Supported network defense simulations and conducted applied research on network security.
- Gained hands-on exposure to firewalls, routers, and secure network design.
- Assisted senior instructors in configuring training environments and documenting lab results.
- Completed applied projects in ethical hacking fundamentals, network scanning, and information gathering.
- Investigated session-security risks (cookies & cache), password cracking, and core system-security concepts.
- Delivered project documentation and live demos showcasing practical problem-solving.
$ ls ./projects
mitmproxy-based addon that captures and logs login requests, credentials, and session cookies for authorized security testing.
Custom C++ module for the ns-3 network simulator adding plug-and-play attack/defense functions, built for an Information Security semester project.
Tool to detect ARP spoofing and poisoning attacks on local networks.
Motion and presence sensing system using Channel State Information (CSI) on ESP32.
Read-only recon tool for common misconfigurations in AI-scaffolded (Next.js + Supabase + Vercel) web apps — checks for exposed Supabase RLS gaps, leaked API keys in JS bundles, open admin routes, wildcard CORS, and missing security headers.
$ cat education.md
$ ls -la ./Certificates
Let's find what others missed.
Open to remote or hybrid internships and entry-level roles in penetration testing, bug bounty research, and application security.