whoami

I'll be graduating from the University of Maryland, College Park in May 2026, currently finishing my Master’s in Cybersecurity along with a Graduate Certificate in Cloud Engineering.

I'm actively looking for a full-time role in Security Engineering, IR/SOC Analyst, or AppSec roles, and I am open to relocating.

I focus more on builing and automating security Systems. A large part of my work involves automation and AI/LLM-assisted security workflows, especially for log analysis, threat modeling, and incident triaging.

I do write a lot of Blogs, building and contributing to open-source security tools, experimenting new AI/LLM, and work on projects that simulate real-world attacks and defensive response.

Let's stay in touch :)


Featured Projects

SOAR EDR Emulation

Emulating adversary techniques and automating D&R with LimaCharlie, Tines and Slack

Automation LimaCharlie Tines

burplabs

Automated python package for portswigger labs

python burplabs portswigger

Automated DevSecOps pipeline: Secure CI/CD Deployment

An automated vulnerability scanning pipeline which involves Cloud, AI and Security Integration.

Jenkins Docker OWASP

Obsidian sync from windows

PowerShell-based automation sets up your Obsidian vault to sync with a private GitHub repo

Powershell Automation Obsidian

CVEs

| CVE-2025-46203

  • Unifiedtransform v2.0 suffers from Broken Access Control, allowing students/teachers to access /students/edit/{id} and modify student records. Affects all v2.0 builds

| CVE-2025-46204

  • Unifiedtransform v2.0 suffers from Broken Access Control, allowing students/teachers to access /course/edit/{id} and modify course data. Affects all v2.0 builds

Certifications

GFACT
GFACT
Feb 2026
BSCP
BSCP
July 2025
AWS
SAA
April 2025
CDSA
CDSA
March 2025
OSCP
OSCP
July 2024
Google
Google Cert
Sept 2023
eJPT
eJPTv2
May 2023
CEH
CEH
Feb 2023

Latest from Medium

React2Shell — CVE-2025–55182: Practical Exploitation of the Vulnerability

Exploiting Northport Ledger application with RSC component In a previous post, we explored React2Shell as a concept and how insecure deserialization …

Read More →

React2Shell — CVE-2025–55182: Critical Vulnerability in React Server

Vuln with easy chain and CVSS:10 After so long i have been writing blog and I have been researching on this vuln. I know time has passed on this but …

Read More →

The Tunnel Without Walls Report — HTB Holmes

The Tunnel Without Walls Report — HTB Holmes Scenario: A memory dump from a connected Linux machine reveals covert network connections, fake …

Read More →