Profile.

An experienced Red Teamer whose focus has always been simple: find the vulnerability — then fix it.

who I am

Security, from the attacker's seat

I am a Red Teamer based in Dhaka, Bangladesh. My work sits at the sharp end of cyber defense: I attack systems the way an adversary would — carefully, methodically, with a clear objective — so organizations can protect their digital assets before real attackers strike. My background is rooted in penetration testing, and every engagement is driven by the same commitment: help organizations identify their vulnerabilities and provide practical solutions.

An engagement never ends at a finding. I push until I know what an attacker can genuinely reach, then translate that into remediation strategies that teams can actually act on. Across web applications, mobile apps, APIs, network devices and Active Directory, the output is always the same: verified findings, prioritized risk, and a clear path to a stronger security posture.

The threat landscape shifts constantly — and so do the tactics, techniques and procedures used to test against it. I stay attuned to emerging threats and continuously refine my methodology and tooling, so the organizations I work with are defended against what's real today, not what was real last year.

operating doctrine

How I operate

Principles that shape every assessment, report and recommendation.

Practical, not theoretical

Every finding lands with a fix. Vulnerability assessments, penetration tests and security reviews all close with actionable remediation strategies, not vague recommendations.

Verified before reported

Nothing goes into a report that hasn't been validated by simulating real attacker tactics, techniques and procedures. Findings are proven, prioritized and reproducible.

Current, or nothing

Security evolves daily. I track emerging threats and continuously improve testing methodologies and tooling, keeping the organizations I defend ahead of what's live in the wild.

Collaborative defense

Security is a team sport. I work across cross-functional teams to design and implement security measures, aligning security objectives with organizational goals at every layer.

Risk in context

Not every weakness matters equally. I assess and prioritize potential risks and vulnerabilities against what the organization actually holds and exposes.

Evidence-driven documentation

Findings are documented clearly so teams can act — and so the organization's overall security posture measurably improves with every cycle.

next stop

See the tools behind the trade