root access granted
Zaber Mahmud Asif
I am a

breaks systems before attackers do.

Cybersecurity researcher and penetration tester with 3+ years across offensive and defensive security — web, network & API pentesting, VAPT, bug bounty, digital forensics, incident response and blue-team operations. Finalist in 40+ global CTF competitions. Currently expanding into AI/ML for security and deepening SOC fundamentals.

3+
Years Experience
40+
Global CTFs
8
Certifications
recon.sh — bash
whoami

About

Illustrated placeholder avatar of Zaber Mahmud Asif

I'm a security researcher and penetration tester based in Dhaka, Bangladesh, with three-plus years of hands-on experience across offensive and defensive cybersecurity. My work spans web, network and API penetration testing, vulnerability assessment (VAPT), digital forensics and incident response — delivered against OWASP, NIST and PTES standards.

Outside of client engagements, I compete in capture-the-flag competitions and have reached the finals of 40+ global CTF events. As Vice President – Technical at the EWU Cyber Security Club, I lead technical operations for a 750+ member community, running CTFs, workshops and mentoring the next wave of ethical hackers.

Location
Dhaka, Bangladesh
Focus
Offensive Security & DFIR
Education
BSc CSE, East West University
Availability
Open to opportunities
Currently Learning
AI/ML for Security · SOC Operations
Endpoint Security
Kaspersky
cat skills.txt

Skills

Tooling and technique across the offensive/defensive spectrum, mapped to how I actually use them in engagements.

Offensive Security

01
Web PentestingNetwork PentestingAPI PentestingVAPTOWASP Top 10SQLiXSSCSRFSSRFIDOR

Defensive Security

02
Digital ForensicsIncident ResponseLog AnalysisThreat DetectionEndpoint Security

Red Team

03
ReconEnumerationExploitationBug BountyResponsible Disclosure

Tools

04
Burp SuiteMetasploitNmapWiresharkGhidraKali LinuxHackTheBox

Programming

05
PythonBashC / C++SQL

Standards & Frameworks

06
OWASPPTESNIST CSFCIS ControlsCVSS
cat services.txt

What I Do

Where I spend most of my time — from live engagements to training the next generation of hackers.

CTF Training

Coaching teammates and club members through CTF categories — web, crypto, forensics and pwn — from fundamentals to competition strategy.

Seminar

Hosting and speaking at seminars and workshops on offensive/defensive security topics for students and community members.

Pentesting

Web, network and API penetration testing engagements — from recon through exploitation to remediation-ready reporting.

Vulnerability Testing

Vulnerability assessments (VAPT) mapped against OWASP, NIST and PTES standards to surface and prioritise real risk.

Research

Independent security research — digging into new attack techniques, tooling and defensive countermeasures.

Core Strengths

Mentoring

Training

Leadership

Problem Solving

Quick Learner

Wanna collab, train or learn together?

Open to collaboration, training sessions or a learning partnership — let's connect.

Get In Touch
history | tail -6

Experience

Vice President – Technical
EWU Cyber Security Club (EWUCSC)
Mar 2026 – Present
Dhaka, BD
  • Lead technical operations for a 750+ member university cybersecurity club
  • Organise CTF events, pentesting workshops and security awareness programs
  • Mentor students in ethical hacking, exploit development and CTF strategies
CTF Event Co-Ordinator
EWU Cyber Security Club
Oct 2024 – Mar 2026
Dhaka, BD
  • Designed web, forensics, crypto and pwn CTF challenges
  • Successfully ran 5+ events end to end, from logistics to debriefs
Trainee Security Engineer
Smart Technologies (BD) Ltd
Sep 2025 – Dec 2025
Dhaka, BD
  • Deployed Kaspersky Endpoint Security; enforced malware, firewall, device and web control policies enterprise-wide via Security Center
  • Monitored threats, performed incident response and managed patch / signature updates
  • Significantly reduced endpoint vulnerability exposure across managed environments
Security Researcher
Hidden Investigations
Nov 2023 – Mar 2025
Dhaka, BD
  • Conducted full-scope web, network and API pentests using OWASP Top 10, PTES and CVSS
  • Discovered SQLi, XSS, CSRF, SSRF, IDOR and privilege escalation chains; delivered risk-rated reports with remediation roadmaps
  • Measurably reduced attack surface for multiple enterprise clients
  • Achieved 3rd place nationally; top finalist in 40+ global CTF events
Ethical Hacking & DFIR Intern
TechnoHacks EduTech
Dec 2023 – Feb 2024
  • Applied DFIR techniques: evidence acquisition, log analysis and malware triage
Cybersecurity Trainee & Campus Ambassador
Cyber Bangla / Hackviser
Oct 2023 – Present
Dhaka / Remote
  • Performed threat analysis, network monitoring and practical cyber defense training
  • Hosted security awareness sessions and promoted offensive security platforms
ls certificates/

Certificates

Hover or click any certificate to inspect it in full view.

certificate.svg
ls ctf_certificates/

CTF Certificates

Certificates of participation and achievement from Capture The Flag competitions. Hover or click any certificate to inspect it in full view.

ls -la projects/

Projects

A sample of the engagements and builds behind the experience above.

CTF infrastructure

EWUCSC Challenge Suite

Designed and deployed 5+ CTF events spanning web, forensics, crypto and pwn categories for a 750+ member club, including challenge authoring, scoring infra and post-event write-ups.

Challenge DesignDFIREvent Ops
Blue team

Enterprise Endpoint Hardening

Rolled out Kaspersky Endpoint Security across an enterprise fleet, tuning malware, firewall, device and web-control policies and cutting endpoint vulnerability exposure through active monitoring.

KasperskyIncident ResponsePatch Mgmt
CTF tooling

CTF Recon Toolkit

Built a set of Python recon and automation tools for CTF competitions, speeding up enumeration and challenge-solving workflows across web, network and forensics categories.

PythonAutomationRecon
Security tooling

PC Login Activity Monitor

Developed a Python-based monitoring tool that logs and tracks login events on a personal machine, giving visibility into access attempts and usage patterns.

PythonMonitoringLogging
Blue team

Hands-On Experience: Kaspersky Deployment

Hands-on deployment and administration of Kaspersky Endpoint Security across an enterprise fleet via Security Center — configuring malware, firewall, device-control and web-control policies, and managing patch / signature rollouts.

KasperskyEndpoint SecuritySecurity Center
ls -la corporate/

Corporate Experience

Placeholder demo cards — replace with real corporate engagement details.

Demo

Software Solution Team [Intern]

Deployed and managed Kaspersky Endpoint Security policies, monitored threats and incidents, maintained updates, and reduced endpoint security risks across enterprise environments.

CertificatePlaceholder
Demo

Corporate Engagement Two

Placeholder description for a corporate engagement. Replace this text with the client, scope and outcome of the work.

DemoPlaceholder
Demo

Corporate Engagement Three

Placeholder description for a corporate engagement. Replace this text with the client, scope and outcome of the work.

DemoPlaceholder
cat achievements.log

Achievements

Hover or click any achievement to inspect it in full view.

history --workshops

Workshops & Training

Sessions I've hosted as organiser, and sessions where I've joined as a guest.

Hosted & Organised

Organised

Digital Forensics: Uncovering the Hidden Truth

Dhaka, Bangladesh

Hands-on sessions on Web, Osint and Network Basics for club members.

Organised

CTF Events — 5+ Editions

Dhaka, Bangladesh

End-to-end design and delivery of web, forensics, crypto and pwn challenges.

Organised

Security Awareness Sessions

Dhaka, Bangladesh

Practical Cyber Security Pathway For New Comers.

As a Guest

Guest Speaker

Digital Forensics: Uncovering the Hidden Truth

Remote / Online

Applied session on current offensive security practices.

whoami --platforms

Problem Solving

Platforms where I sharpen offensive and defensive skills outside of client engagements.

nc -lvp contact

Get In Touch

Open to security research, pentesting engagements and collaboration. Reach out directly.