🇵🇸 Free Palestine

I'm a penetration tester and AI red teamer who specializes in cloud security. I work across AWS infrastructure, APIs, and LLM systems, finding the failure modes that survive code review and security scans, and writing the reports engineers actually use to fix them. I lead development at Beruni, an AWS posture scanner built for startups.

Two years of hands-on engagement work, with stops at Positive Technologies in Moscow, Hackers Academy, and Thincscorp. B.S. Cybersecurity from FAST NUCES Islamabad, 2026. I care about repeatable methodology, clear reporting, and findings that survive the handoff to engineering.

Experience

2026 –
Present

Dev Lead

Beruni · Remote

Lead development of Beruni, a hosted AWS security-posture scanner built for startups. Design the cloud architecture and scanning pipeline, turning AWS configuration checks and compliance mapping (SOC 2 / PCI evidence) into a repeatable workflow. Beruni replaces the manual, screenshot-by-screenshot verification auditors used to spend weeks doing by hand with automated scans and a ready-made evidence trail.

Summer
2026

Metaverse Developer

UTeM · Melaka, Malaysia

Worked on metaverse technologies and developed an interactive virtual world on Mitoworld.io using diverse digital assets, including images, videos, and 3D models. Designed and developed a presentation of the festivals and cultural heritage of KPK, Pakistan, bringing the region's stories into an immersive virtual space. The team secured 2nd Place in the competition.

Jul – Sep
2025

AI Red Teamer

Hackers Academy · Remote

Adversarial testing of LLMs and autonomous agents: prompt injection, chain-of-thought leakage, tool-use abuse, and authorization bypass. Built deliberately vulnerable agents and Python fuzzing harnesses; documented each finding with reproducible PoCs, threat models, and developer-facing remediation.

Aug 2024

Junior Penetration Tester

Positive Technologies · Moscow

Full-scope web and internal network engagements. External and internal reconnaissance, privilege escalation, Active Directory exploitation, and post-exploitation. Tooling across Burp Suite, Metasploit, Nmap, Hydra, and Nessus. Delivered client-facing reports with CVSS-scored findings and prioritized remediation paths.

Apr – May
2024

Cyber Security Analyst

Thincscorp · Remote, UAE

OSINT and threat-intelligence work feeding incident response; investigation cycle time reduced ~30% through better tooling and triage playbooks. Maintained the organizational risk register and supported malware and digital-forensics investigations.

2022 – 2026

B.S. Cybersecurity

FAST NUCES · Islamabad

Coursework across cryptography, network security, secure SDLC, and applied AI. Capstone work fed directly into AutoCSPM and the prioritization prototype.

Projects

Virtual Pakistan on Mitoworld.io

2025

A collaborative virtual world built during the Project-Based Learning Summer Camp at UTeM, blending Pakistani cultural heritage with spatial design. The experience featured a custom KPK avatar, a Bab-e-Khyber gateway, and a traditional Hujra lounge with Persian rugs, prayer mats, and floor seating. When spatial barrier physics could not block the upper level, a playful "Police Cat" stop-sign wall became the improvised access control. The project secured 2nd Place in the competition.

Mitoworld.io metaverse spatial design IoT

AutoCSPM

2026

A dual-mode cloud security posture scanner: pre-deployment against infrastructure-as-code, and live against deployed AWS accounts. Maps findings to CIS Benchmarks and OWASP cloud guidance, and outputs evidence formatted for compliance review rather than a thousand-line CSV. MVP shipped; multi-cloud and policy-as-code on the roadmap.

AWS Python CSPM CIS · OWASP

A Spring Boot training lab that implements the OWASP API Top 10 as runnable vulnerabilities: BOLA, broken authentication, mass assignment, injection. Parallel vulnerable and fixed branches let teams diff each exploit against its patch, line by line.

Spring Boot JWT teaching lab

AI-Assisted Vulnerability Prioritization

2025

A prototype that ranks vulnerabilities by exploitability and environmental fit, pulling CVSS, EPSS, and CISA KEV signals with ML-generated remediation suggestions. Built for the “ten thousand highs” problem, where every finding is a P1 and triage collapses under its own volume.

Python CVSS · EPSS ML

Writing

The 10 Most Common AWS Misconfigurations We Found Scanning Beta Accounts

Beruni · 2026 · 06

Written for the Beruni blog: the ten AWS misconfigurations that show up most across IAM, S3, EC2, VPC, and RDS in real beta-account scans, each paired with a CLI remediation that doesn't need downtime.

cloud aws posture

The Leetspeak Loophole: Unmasking LLM System Prompts and Its Business Impact

2026 · 05

A technical analysis of how leetspeak encoding can be used to extract system prompts from LLMs, discussing the underlying mechanisms and significant business implications for AI security.

ai red team llm security vulnerability research

Beyond Leetspeak: Advanced System Audit Extraction from Gemini and Its Red Team Implications

2026 · 05

An indepth guide on how to imply advanced techniques that involves Authority Framing, Continuation Bootstrapping and much more techniques that helps in Understanding the core funcionality of LLMs and how they can be taken Advantage of to bypass the security of the system.

ai red team llm security vulnerability research

Prompt-injection severity in agentic systems — a working framework

draft

Notes from recent red-team work: a severity model that accounts for tool use, blast radius, and authorization context, not just whether the model can be made to swear.

ai red team methodology

BOLA in the wild — three patterns I keep finding in REST APIs

draft

The three shapes of broken object-level authorization I see in nearly every engagement, what they share, and the test cases that catch them without false positives.

web api owasp

Building AutoCSPM: turning AWS misconfigurations into actionable findings

Confidential

A walkthrough of the scanner architecture, the CIS rule engine, and why “compliance evidence” is the only output that ever changes behaviour in mid-sized orgs.

cloud aws tooling

More posts as engagements close and material becomes shareable. Most of my output lives in client reports rather than public writing.

Recommends

The most efficient path to getting good at web security. Free, methodically structured, and the labs are built on real vulnerability classes, not toy examples.
First stop when I need a technique for a target type I haven't touched in a while. Comprehensive, current, and searchable.
Reference repo for payloads, bypass tricks, and methodology notes across every vuln class. Permanently bookmarked.
If you do API work, offensive or defensive, read it twice. It's where my teaching lab anchors and where most API findings in the wild trace back.
The closest thing to an offensive cloud playbook that's publicly available. Real AWS, GCP, and Azure attack chains with actual IAM exploitation paths, not conceptual overviews.
The taxonomy I reach for when threat-modelling an agentic system. Prompt injection, insecure output handling, training data poisoning; the definitions are precise enough to actually be useful.
Andrej Karpathy building transformers from scratch on a whiteboard. Necessary context for AI security work; you attack what you understand.
ATT&CK for ML systems. The clearest adversarial AI taxonomy available and the framework my red team reports align to.
Deliberately vulnerable AWS environment for practising cloud attack paths hands-on. IAM privilege escalation, S3 exposure, Lambda abuse; set it up and break it.

Skills

Offensive
Web, API, and Active Directory testing across the full kill chain. Burp Suite Pro, OWASP ZAP, Metasploit, Nmap, SQLmap, Hydra, Nessus.
AI / LLM
Prompt injection, agent and tool-use exploits, chain-of-thought leakage, Python fuzzing harnesses, threat modeling for agentic systems. MITRE ATLAS-aligned reporting.
Cloud
AWS configuration review, IaC scanning, CIS Benchmarks, OWASP cloud guidance. Compliance evidence for SOC 2 and ISO-aligned engagements.
Languages
Python, C/C++, Bash, SQL, PowerShell, JavaScript.

Contact

Email is the fastest channel; I reply within a working day. Currently open to remote pentest and AI red team roles, and selective freelance engagements.

Email · GitHub · LinkedIn

CV available on contact.

What I Do Everyday

poetry philosophy politics religion

By default, I don't know. Someday it's one of these, someday it's all of them at once, someday it's none. In short: trying to navigate life alongside its metaphysical realities.

Want to Try Something Cool?

Press M then I then K — anywhere on this page. No mouse needed.

M·I·K

A full-screen navigation shortcut hidden inside the site. Old-school keyboard ritual. Type the initials.