Skip to content
View abdulhasyyb's full-sized avatar

Block or report abdulhasyyb

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
abdulhasyyb/README.md

About

Final-year Cybersecurity engineer pivoting from offensive exploitation into enterprise governance — I spend one half of my week finding the gap between what a system is supposed to do and what it actually lets you do, and the other half learning how to make sure that gap never opens in the first place.

  • Reported an API authorization flaw exposing 2.5M user records on a Pakistani federal government portal — acknowledged on PKCERT's national VDP dashboard.
  • Ran a structured AWS cloud penetration test end-to-end (IAM, S3, SSRF/IMDS, Active Directory attack-path mapping) as a VAPT intern at xLoop Digital.
  • Built a fully automated malware analysis pipeline — sandbox detonation, VirusTotal cross-checks, AI-generated triage reports.
  • Currently going deep on ISO 27001 / ISO 42001, GRC, and AI security governance — because knowing how to break a system is only half the problem; the rest is knowing how to govern it at scale.

Open to: Remote AppSec · Cloud Security · VAPT · Security Engineering · Contract Audits


Security Stack & Tooling

Languages

Offensive & Application Security

Cloud, Infrastructure & SecOps

GRC & Frameworks


Security Domain & Governance Expertise

Domain Proficiency Core Frameworks & Methodologies Technical Execution Details
Application Security / API Pentesting Advanced OWASP Top 10, OWASP API Security Top 10, PTES Auth/authz flaw discovery, business-logic abuse, SSTI, open redirect, IDOR chaining
Cloud Security (AWS) Advanced CIS AWS Benchmark, PTES IAM privilege escalation, S3 misconfiguration audits, SSRF/IMDS credential exposure
Active Directory / Internal Pentest Intermediate–Advanced MITRE ATT&CK BloodHound/SharpHound attack-path mapping, Kerberoasting, AS-REP roasting, Impacket lateral movement
Vulnerability Assessment Advanced CVSS v3.1, PTES Authenticated/unauthenticated scanning, cross-validation across scanners, manual severity scoring
Security Automation Intermediate n8n, custom Python tooling Malware sandboxing pipelines, VirusTotal enrichment, AI-generated reporting
GRC & Risk Management Growing / In Progress ISO 27001, ISO 42001, NIST CSF Risk registers, gap assessments, control mapping, policy drafting, mock internal audits
AI Security & Governance In Progress ISO 42001, emerging AI risk frameworks AI risk surface mapping, governance-vs-exploitation tradeoff analysis

Featured Security Projects & Research

Automated Malware Analysis Pipeline (MalScan Orchestrator)
Stack / Tools Scope Vulnerability Vectors / Threat Surface Governance & Remediation Impact Repository / Advisory
n8n, sandbox detonation, VirusTotal API, AI reporting Automated digital forensics workflow for malware triage Malicious binary submission, dynamic sandbox analysis, IOC extraction Reduces manual triage time, standardizes forensic evidence collection GitHub

Built an end-to-end orchestration layer that accepts a submitted sample, detonates it in a controlled sandbox, cross-references resulting hashes against VirusTotal, and generates an AI-assisted forensic report — built as a secure automation exercise in IOC extraction and forensic triage under controlled conditions.

Government Portal Auth Flow Vulnerability Research (PKCERT)
Stack / Tools Scope Vulnerability Vectors / Threat Surface Governance & Remediation Impact Repository / Advisory
Manual API testing, authorization analysis Federal government citizen-facing portal Broken object-level authorization on an internal API Coordinated disclosure to PKCERT; remediated shortly after report PKCERT VDP Acknowledgment

Identified an authorization control gap that allowed access to records outside the intended user scope. Reported through PKCERT's national Vulnerability Disclosure Program under responsible disclosure practices; the issue was remediated promptly after report.

AWS Cloud Infrastructure Penetration Testing (xLoop)
Stack / Tools Scope Vulnerability Vectors / Threat Surface Governance & Remediation Impact Repository / Advisory
AWS, Nessus, Nexpose, BloodHound/SharpHound, Impacket, Hashcat Controlled multi-host AWS lab environment IAM privilege escalation, S3 misconfiguration, SSRF/IMDS credential exposure, AD lateral movement CVSS v3.1-scored findings feeding a likelihood × impact risk-prioritization matrix Internal engagement — advisory available on request

Executed a full PTES-aligned cloud penetration test: pre-engagement, threat modeling, vulnerability analysis, exploitation, and reporting. Mapped Active Directory attack paths end-to-end, performed credential extraction with the Impacket suite, and ran Kerberoasting / AS-REP roasting attacks under senior supervision.

Enterprise API Security Audit (2.5M Record Authorization Flaw)
Stack / Tools Scope Vulnerability Vectors / Threat Surface Governance & Remediation Impact Repository / Advisory
Manual API auth testing Public-sector API surface handling citizen records Missing function-level access control on a high-privilege endpoint ~2.5M records brought back into scope; disclosure recognized nationally PKCERT VDP Acknowledgment

The root cause was a missing authorization check rather than a missing authentication check — a reminder that the two are often conflated in production systems. Full technical writeup published on Medium.


Experience

VAPT Intern — Cloud Penetration Testing · xLoop Digital Jul 2026 – Present

  • Executed a structured cloud penetration testing engagement against AWS environments, following PTES methodology under senior supervision
  • Performed IAM privilege escalation testing and S3 misconfiguration assessment across a controlled AWS attack surface
  • Tested SSRF and IMDS abuse vectors for credential exposure
  • Ran authenticated/unauthenticated vulnerability assessments with Nessus, cross-validated against Nexpose, manually scored with CVSS v3.1
  • Mapped Active Directory attack paths with BloodHound/SharpHound; performed lateral movement with the Impacket suite
  • Conducted Kerberoasting and AS-REP roasting attacks with Hashcat; built a risk-prioritization matrix for findings triage

AWS PTES IAM Active Directory Vulnerability Management Risk Prioritization


Achievements & Advisories

Entity / Platform Finding / Achievement Impact / Status
PKCERT (National CERT — Pakistan) API authorization flaw exposing 2.5M user records Acknowledged on national VDP dashboard · Remediated
Bugcrowd Active bug bounty hunter Ongoing
Hack Smarter Labs Casino Lab — captive portal pivot to Jinja2 SSTI → full RCE Completed · Writeup published
APIsec University API Penetration Testing (12 hrs) Certified

Certifications & Frameworks

Cloud & Infrastructure

Governance & AI Security

Offensive Security & Web/API


Security Profiles & Research Outlets


GitHub Analytics


GitHub Trophies


Contribution Activity


Contribution Snake


Current Focus

Learning: AI Governance (ISO 42001), Advanced Cloud Threat Hunting
Building: Custom Automated Exploitation & Triage Modules
Exploring: LLM Vulnerabilities & Red Teaming AI Pipelines
Open To: Remote AppSec, VAPT, Cloud Security, Contract Audits

Connect


"Knowing how to break a system is only half the problem; you actually have to know how to govern it."

Pinned Loading

  1. Malscan_orchestrator-Digital-Forensics Malscan_orchestrator-Digital-Forensics Public

    MalScan Orchestrator is a digital forensics automation workflow built using n8n to orchestrate malware analysis, enrichment, and reporting in a controlled and repeatable manner.

  2. GDPR-Compliant-Hospital-management-system GDPR-Compliant-Hospital-management-system Public

    A secure hospital management dashboard designed with GDPR privacy principles, role-based access control, audit logging, and optional reversible anonymization using Fernet encryption. Built with Str…

    Python

  3. keylogger keylogger Public

    A basic keylogger written in Python to simulate malware behavior for ethical hacking labs. It is delivered and executed using SSH captures keystrokes in the background and sends them to a remote HT…

    Python

  4. n8n-workflows n8n-workflows Public

    My n8n workflows

  5. Web-Crawler-for-Data-Extraction-Computer-Networks-Project- Web-Crawler-for-Data-Extraction-Computer-Networks-Project- Public

    Academic project developed as part of the Computer Networks course, focusing on automated web crawling and data extraction using HTTP requests and HTML parsing.

    Python

  6. -ai-pdf-chatbot -ai-pdf-chatbot Public

    A simple Streamlit app that lets you upload any PDF and ask natural language questions about its content — powered by **Gemini** and **LangChain**.

    Python