Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View Shehzadcyber's full-sized avatar
  • Pakistan

Block or report Shehzadcyber

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
shehzadcyber/README.md
 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
 β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β•β•β•
 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘
 β•šβ•β•β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β•šβ•β•β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•  β–ˆβ–ˆβ•‘
 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
 β•šβ•β•β•β•β•β•β•β•šβ•β•  β•šβ•β•β•šβ•β•β•β•β•β•β•β•šβ•β•  β•šβ•β•β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•β• β•šβ•β•β•β•β•β•
Typing SVG

Red Team Pentesting Blue Team SOC Purple Team CVE


LinkedIn HackerOne TryHackMe Gmail Profile Views


$ whoami

β”Œβ”€β”€(ShehSecγ‰Ώkali)-[~/]
└─$ cat identity.json

{
  "name"       : "Shehzad Ali",
  "alias"      : "ShehSec",
  "role"       : "Cybersecurity Engineer",
  "teams"      : ["πŸ”΄ Red", "πŸ”΅ Blue", "🟣 Purple"],
  "location"   : "πŸ‡΅πŸ‡° Pakistan",
  "experience" : "4+ yrs offensive | 2+ yrs industry",
  "education"  : "BS CS β€” Hazara University (3.54 GPA)",
  "cve"        : "CVE-2025-24966 β€” reNgine Project",
  "bounties"   : "HackerOne β€” Active Researcher",
  "status"     : "[+] Always Hacking... ethically."
}


$ cat /etc/attack_surface

πŸ”΄ RED TEAM

Offensive Security

[+] Web App Pentesting
    OWASP Top 10
    SQLi Β· XSS Β· SSRF Β· RCE
    Business Logic Flaws

[+] API Security
    REST Β· GraphQL
    JWT Β· OAuth Β· IDOR
    Mass Assignment

[+] Mobile Security
    Android & iOS RE
    Runtime Analysis

[+] Active Directory
    Kerberos Attacks
    Lateral Movement
    Privilege Escalation

[+] Desktop App Security
    Binary Exploitation
    Reverse Engineering

πŸ”΅ BLUE TEAM

Defensive Security

[+] SOC Operations
    SIEM Fundamentals
    Log Analysis & Triage

[+] DFIR
    Digital Forensics
    Incident Response

[+] Threat Hunting
    Detection Engineering
    Behavioral Analysis

[+] Vuln Management
    Secure Coding
    Compliance Hardening

[+] Govt Infrastructure
    KPITB β€” Secured
    Gov Digital Assets

🟣 PURPLE TEAM

Hybrid & Research

[+] Cloud Security
    AWS Β· Azure
    IAM Abuse
    Misconfigurations

[+] AI/LLM Security
    Prompt Injection
    Data Leakage
    Model Exploitation

[+] Red Team Simulations
    Full Attack Chains
    Detection Testing

[!] Researching
    IoT Security
    Web3 / Blockchain
    Post-Quantum Crypto

$ ls ~/tools/ --color

Burp Suite Metasploit BloodHound Impacket Acunetix Wireshark Nessus OWASP ZAP Ghidra IDA Free JADX Nmap Python Bash JavaScript C/C++ Assembly


$ cat experience.log

[2024 β†’ NOW ]  πŸ”΄ Cybersecurity Researcher | Penetration Tester
               Secure Purple Β· Islamabad, Pakistan
               β†’ Assessments: Web Β· Mobile Β· API Β· Cloud Β· AI/LLM Β· Desktop
               β†’ Manual pentesting + emerging threat research

[2024 β†’ 2025]  πŸ”΅ Security Engineer Intern
               KPITB β€” Khyber Pakhtunkhwa IT Board Β· Peshawar
               β†’ VAPT for government digital infrastructure
               β†’ System hardening + compliance security improvements

[2023 β†’ NOW ]  🟣 Penetration Tester (Contract)
               OffensioX Β· Islamabad
               β†’ VAPT & Red Team engagements
               β†’ Attack simulation + detection/response evaluation

[2021 β†’ NOW ]  🟒 Security Researcher β€” Bug Bounty
               HackerOne Β· Remote / USA
               β†’ Critical vulnerability disclosure for global orgs
               β†’ Logic flaws Β· Misconfigs Β· Novel exploitation vectors

$ ls -la certifications/

πŸŽ–οΈ Cert Full Name Status
🎯 CEH Certified Ethical Hacker β€” EC-Council βœ…
πŸ”“ eCPPTv3 Certified Professional Penetration Tester βœ…
🌐 eWPTXv3 Web App Penetration Tester eXtreme βœ…
πŸ”Œ ASCP API Security Certified Professional βœ…
πŸ“± CAPen Certified AppSec Pentester βœ…
πŸ”‘ CASA Certified API Security Analyst βœ…
πŸ›‘οΈ Google Cybersecurity Professional βœ…

$ ./projects --verbose

projects = {
    "XSS-Finder": {
        "type": "πŸ”΄ Offensive Tool",
        "desc": "CLI β€” automated XSS detection for bug bounty hunting",
        "tech": ["Python", "Requests", "Payload Testing"],
    },
    "Blind-XSS-Headers": {
        "type": "πŸ”΄ Offensive Tool",
        "desc": "Blind XSS via HTTP header payload injection automation",
        "tech": ["Python", "HTTP Manipulation"],
    },
    "Vuln-Assessment-Tool": {
        "type": "🟣 Research / FYP-2024",
        "desc": "Python scanner β€” SQLi, XSS & misconfiguration detection",
        "tech": ["Python", "SQLi", "XSS", "Remediation Suggestions"],
    },
}

$ cat achievements.txt

πŸ† [2024] Finalist ── BlackHat MEA Cybersecurity CTF ── Riyadh, Saudi Arabia
πŸ† [2024] Finalist ── Digital Pakistan Cyber Security Hackathon
πŸ† [2023] Finalist ── NCCS Hackathon
πŸ† [2023] Finalist ── Ignite Cyber Security Hackathon
πŸ’€ [2025] CVE Contributor ── CVE-2025-24966 (reNgine Project)

CVE-2025-24966 β€” Responsible disclosure in reNgine open-source recon framework. Real research, real impact. 🎯


$ neofetch --stats


$ ping ShehSec

PING ShehSec ([email protected])
64 bytes: icmp_seq=1 β€” Open to pentesting gigs, red team collabs & bug bounty. 🀝

Email LinkedIn HackerOne TryHackMe


╔══════════════════════════════════════════════════════════════════╗
β•‘   πŸ”΄ Attack.   πŸ”΅ Defend.   🟣 Dominate.  β€” The ShehSec Way.   β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

⚑ All activities are authorized & ethical Β· Built with β˜• & terminal sessions

Popular repositories Loading

  1. CVE-2017-7529 CVE-2017-7529 Public

    Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggere…

    Python 11 1

  2. Bug-Bounty-Script Bug-Bounty-Script Public

    Forked from shubham-rooter/Bug-Bounty-Script

    Bug-hunting Automation

    Shell 2 1

  3. XSS-Finder XSS-Finder Public

    The XSS-Finder, I created for my bug bounty hunting process. It helps me quickly find Cross-Site Scripting (XSS) vulnerabilities by trying different inputs with a variety of XSS attack codes. It ha…

    Python 2 2

  4. web-eng-project web-eng-project Public

    This is for Web Engineering Project

    JavaScript 1

  5. MyScript-for-BugBounty-Tools-installation MyScript-for-BugBounty-Tools-installation Public

    A simple repo used for installation of go based tools when you setup a new machine.

    Shell 1 1

  6. NPM-Dependency-Confusion-Attack-RCE-Payload NPM-Dependency-Confusion-Attack-RCE-Payload Public

    RCE Payload for NPM Dependency Confusion Attack

    JavaScript 1 1