Available for VAPT / Penetration Testing roles

ABUL KALAM AZAD

Junior Penetration Tester Web & Network VAPT

eJPTv2-, CRTA- and MCRTA-certified final-year B.Tech student who turns full-scope engagements into evidence — validated findings, CVSS v3.1 scoring, and remediation roadmaps that hold up under retest.

azad@sec: ~/profile

whoami

Junior penetration tester — web application & network VAPT.

B.Tech Electronics & Computer Science, KIIT Bhubaneswar · 2023–2027.

cat ./certifications

eJPTv2 · CRTA · MCRTA · ICCA · ISC2 CC

Validated findings
19full-scope VAPT
TryHackMe
Top 2%global · AIR 12
Certifications
5offensive & cloud
Security tools
3open source
01

About

~/about

I am a final-year B.Tech (Electronics & Computer Science) student at KIIT Bhubaneswar and a junior penetration tester focused on web application and network VAPT. My work is methodology-driven — PTES and OWASP WSTG v4.2 for execution, CVSS v3.1 and CWE for scoring and classification, and structured reporting that a remediation team can actually act on.

Most recently I ran a complete grey-box engagement end to end against four in-scope assets: 19 validated findings including 2 Critical and 7 High, a 97-page report with business impact analysis and a prioritised remediation roadmap, and a full retest cycle verifying what was actually fixed. Of the 18 automated scanner findings, I rejected 39% as non-actionable and found 8 issues no scanner reported — 5 of them High severity.

Alongside that I build small offensive-security tools in Python, mentor 20–25 students in my college's cyber security society, and compete on TryHackMe (Top 2% global) and Hack The Box. I am looking for a VAPT / penetration testing role where I can keep doing hands-on assessment work and writing the reports that go with it.

02

Skills & Tools

~/skills

Web & Application Security

  • Burp Suite
  • Repeater
  • Intruder
  • Proxy
  • HTTP/S interception
  • OWASP Top 10
  • SQL Injection
  • XSS
  • IDOR
  • Authentication testing

Network Security

  • Nmap
  • Wireshark
  • Netcat
  • Port scanning
  • Service enumeration
  • Packet analysis
  • Network pentesting

Exploitation & Assessment

  • Metasploit
  • Nessus
  • Nikto
  • Nuclei
  • Privilege escalation
  • Vulnerability assessment
  • MITM / ARP spoofing

Red Team & Active Directory

  • MITRE ATT&CK TTPs
  • Kerberos attacks (patched AD)
  • Lateral movement
  • Stealth pivoting
  • Adversary simulation
  • Internal / external recon

Scripting & Tooling

  • Python
  • Scapy
  • Bash
  • Git / GitHub
  • Linux (Kali)
  • Tool development

Reporting & Standards

  • VAPT reporting
  • CVSS v3.1
  • CWE mapping
  • OWASP WSTG v4.2
  • PTES
  • NIST SP 800-115
  • Remediation guidance

Cloud Security

  • AWS
  • Azure
  • GCP red team techniques
  • IAM & RBAC
  • Compute & storage security
  • Cloud asset recon
  • MITRE Cloud ATT&CK
03

Certifications

~/certifications
offensiveAug 2026

CRTA

Certified Red Team Analyst

CyberWarFare Labs

Verify
cloud · offensiveAug 2026

MCRTA

Certified Multi-Cloud Red Team Analyst

CyberWarFare Labs

Verify
offensiveFeb 2026

eJPTv2

Junior Penetration Tester

INE Security

Verify
cloudFeb 2026

ICCA

INE Certified Cloud Associate

foundational

CC

Certified in Cybersecurity

ISC2

courseAug 2026

Azure Red Teaming

Introduction to Azure Red Teaming — course completion

Altered Security

Verify

TryHackMe learning paths completed

04

Security Projects

~/projects

featured engagement

Full-Scope VAPT — Web & Network Assessment

Grey-box assessment of four in-scope assets: two Windows hosts, two web applications.

Repository

scope Isolated lab environment · authorised engagement · findings reproduced under defined rules of engagement.

  • 2Critical
  • 7High
  • 19Validated total
  • 97Page report
  • Executed an end-to-end grey-box VAPT following PTES and OWASP WSTG v4.2, identifying 19 validated vulnerabilities — each scored with CVSS v3.1 and mapped to CWE.
  • Manually validated all 18 automated scanner findings and rejected 39% as non-actionable; identified 8 additional vulnerabilities — 42% of the total, including 5 of 7 High-severity issues — that no scanner reported.
  • Achieved SYSTEM-level compromise via MS17-010 (EternalBlue) and extracted the full local credential database, demonstrating real-world impact beyond scanner output.
  • Delivered a 97-page report with executive summary, business impact analysis and a prioritised remediation roadmap; retested all 19 findings — 6 resolved, 4 partially resolved, 9 unresolved.
  • PTES
  • OWASP WSTG v4.2
  • CVSS v3.1
  • CWE
  • Burp Suite
  • Nessus
  • Metasploit
  • Nmap
  • Windows

// open-source tooling

ARP Spoofer

Python MITM tool · Scapy

  • ARP cache-poisoning tool performing a man-in-the-middle attack between a target host and gateway by forging Layer-2 Ethernet/ARP frames with Scapy.
  • Resolves MAC addresses once to prevent ARP cache flapping and automatically restores original ARP tables on exit for clean, non-disruptive teardown.
  • Tested in an isolated VMware lab (Kali attacker, Windows 10 target); documented detection and defences — Dynamic ARP Inspection, static ARP entries, arpwatch.
  • Python
  • Scapy
  • Layer 2
  • MITM
github.com/Abulkalam1524/arp-spoofer

Network Scanner

ARP-based host discovery · Python, Scapy

  • Lightweight ARP-based scanner that discovers live hosts across a /24 subnet and maps their IP and MAC addresses using Scapy srp() — no external scanning tools required.
  • Python
  • Scapy
  • Recon
github.com/Abulkalam1524/network-scanner

MAC Address Changer

Linux network utility · Python

  • Linux MAC-spoofing tool that changes and verifies a network interface's MAC address, including root-privilege checks and post-change validation.
  • Python
  • Linux
  • Networking
github.com/Abulkalam1524/mac-address-changer
05

CTF & Hands-on Labs

~/ctf

TryHackMe

Top 2% global

AIR 12All India Rank · October 2024 Wall of Fame

Penetration testing, web exploitation, privilege escalation and network security rooms. Completed the Jr Penetration Tester, Cyber Security 101 and Complete Beginner paths.

tryhackme.com/p/G00dM4nGr1t

D3 Fest 2025 — CTF

3rd place

IIIT Bhubaneswar · November 2025

Competed as Team 7h3_UnKnw0n, placing third in the capture-the-flag competition.

Hack The Box

Ongoing hands-on machine and challenge practice, plus collaborative vulnerability research and guided lab sessions run for the KIIT cyber security society.

Competition circuit

Competed in the following CTF events:

  • BSides
  • DEADFACE
  • Pentathon
  • H7CTF
06

Security Write-ups

~/writeups

TryHackMePenetration testing write-up

Mr. Robot — Walkthrough

A detailed penetration-testing walkthrough covering enumeration, web exploitation and privilege escalation — demonstrating end-to-end methodology and clear technical reporting.

  • Enumeration
  • Web exploitation
  • Privilege escalation

Medium

All published write-ups

Full archive of my technical write-ups and methodology notes, published on Medium.

// new write-ups published regularly

07

Experience & Education

~/experience
  1. Cyber Security Mentor

    Aug 2024 — Present

    IoT Lab (Cyber Security Society), KIIT

    • Mentor and train 20–25 students in the college cyber security society, delivering hands-on sessions on network security, penetration testing and CTF techniques.
    • Design and host OSINT-based CTF challenges for lab events, building challenges across recon, research and web exploitation.
    • Lead collaborative vulnerability research and guided practice labs on TryHackMe and Hack The Box.
  2. Cybersecurity Intern

    Nov 2024 — Dec 2024

    The Red Users

    • Conducted network penetration testing across assigned targets to identify vulnerabilities and assess overall security posture.
    • Used Burp Suite to intercept, analyse and modify HTTP/S requests, surfacing injection and authentication flaws in web applications.
    • Documented findings with actionable remediation recommendations in structured security reports.
  3. B.Tech, Electronics & Computer Science Engineering

    Jul 2023 — Jul 2027

    KIIT, Bhubaneswar

    Relevant coursework Computer Networks · Operating Systems · Network Security · Cybersecurity Fundamentals · Cryptography

08

Achievements & Recognition

~/achievements
National level · Government of India July 2026

OS Bug Bounty Challenge 2026 — C-DAC / MeitY

C-DAC Kolkata · Ministry of Electronics & Information Technology

A 36-hour security assessment of BOSS OS covering static and dynamic analysis, fuzzing, reverse engineering, proof-of-concept development and CVSS-scored vulnerability reporting under a defined Rules of Engagement.

  • Static analysis
  • Dynamic analysis
  • Fuzzing
  • Reverse engineering
  • PoC development
  • CVSS reporting
3rd place

Capture The Flag — D3 Fest 2025

IIIT Bhubaneswar · November 2025 · Team 7h3_UnKnw0n

Top 2% global

TryHackMe — All India Rank 12

October 2024 Wall of Fame · pentesting, web exploitation, privilege escalation, network security

Competitor

CTF competition circuit

BSides · DEADFACE · Pentathon · H7CTF

09

Contact

~/contact

Open to VAPT & penetration testing roles

I am actively looking for penetration testing and security-assessment opportunities — internships or full-time. If you would like the full 97-page VAPT report, a walkthrough of my methodology, or just want to talk security, the fastest way to reach me is email.