Defending Applications.
Securing Digital Assets.
I am Md. Hasib Islam β a Cybersecurity Professional specializing in web & API penetration testing, network attack-surface mapping, security automation, and defensive AI integration.
Md. Hasib Islam
B.Sc. Computer Science (2024)
ihasib199@gmail.com
Turn security testing into a clear business decision.
Discover what is exposed, understand what matters most, and receive practical remediation guidance your team can act on.
Security Services for Your Business
Comprehensive security testing, vulnerability management, and defensive engineering tailored for companies, developers, and startups.
Web App Security Audit
Complete OWASP Top 10 penetration testing, business logic flaw identification, XSS/SQLi checks, and API authentication validation.
- β Vulnerability Proof-of-Concept
- β Remediation Steps for Devs
- β Re-testing Verification
Network Attack Surface Audit
External exposure mapping, open port identification, outdated service detection, and perimeter security hardening.
- β Subdomain & IP Enumeration
- β Misconfiguration Exposure
- β Executive Summary Report
Security Tooling & Automation
Development of custom Python scripts, automated vulnerability scanners, and continuous security check tools for CI/CD pipelines.
- β Custom Python & Bash Scripts
- β Continuous Monitoring Tools
- β API Integration Support
AI Threat Modeling & Consulting
Privacy-preserving AI integration, prompt injection vulnerability analysis, and local LLM security copilot implementation.
- β Local RAG Log Assistant
- β Prompt Injection Defense
- β AI Risk Assessment
A security process clients can understand.
A structured engagement from scope definition to remediation verification β with technical depth and business-friendly communication.
Define targets, authorization, objectives, constraints and testing depth.
Map the attack surface, technologies, endpoints, assets and exposed services.
Validate vulnerabilities, authentication, authorization, configuration and logic risks.
Translate technical findings into severity, impact, evidence and prioritized remediation.
Verify fixes and close the loop with evidence-based validation.
Reproducible findings
Clear technical evidence helps developers reproduce and understand security issues.
Risk-first remediation
Focus attention on issues with the strongest security and business impact.
Verification after fixes
Retesting confirms whether the intended remediation actually resolved the finding.
Estimate Your Security Scope
Select your project type and scope to calculate turn-around time and instantly generate an audit proposal.
Technical Arsenal.
Application Security
Penetration testing of web apps & APIs. Expertise in identifying Broken Access Control, IDOR, SQL Injection, XSS, and SSRF.
Network Security
Attack surface mapping, service enumeration, network protocol analysis, and Wi-Fi security assessments using Nmap & Wireshark.
Security Engineering
Automating vulnerability scanning, custom Python exploit proof-of-concepts, Bash workflow scripts, and secure dev integration.
AI-Assisted Defense
Building privacy-centric local RAG models for threat log analysis, synthetic media detection, and AI threat modeling.
Security Projects.
Assessment Workflow
Authorized Scope Definition
Establishing rules of engagement, target subdomains, NDA, and explicit testing parameters.
Reconnaissance & Surface Discovery
Passive & active enumeration of domain records, active services, ports, and exposed parameters.
Vulnerability Exploitation Validation
Controlled verification of potential security issues to eliminate false positives entirely.
Reporting & Remediation Support
Delivering executive summaries, detailed technical steps, code fixes, and follow-up retests.
Security Tech Stack
A defense-in-depth view of where each tool and discipline sits β outer layers are hit first, inner layers protect what matters most. Hover or tap a layer.
Indent + bar length = typical depth of engagement at that layer, not importance β every layer is treated as critical.
LANGUAGES & SCRIPTING
SECURITY TOOLSETS
Self-assessed proficiency, updated periodically as tooling and case work evolve.
All security audits, domain testing, and communications are strictly handled under Mutual NDA agreements. Zero client data or target endpoints are ever publicly disclosed.
Frequently Asked.
Do you sign an NDA before testing?
Yes. Every engagement is covered by a mutual NDA before any scope details, credentials, or targets are shared. Confidentiality is non-negotiable.
Will you test my live production system?
Only with written authorization and an agreed testing window. A staging or cloned environment is strongly preferred, and destructive tests are always confirmed with you first.
What do I actually receive at the end?
A written report with reproducible proof-of-concept steps for each finding, a severity rating, plain-language remediation guidance for your developers, and one free re-test once fixes are deployed.
How fast can you turn an audit around?
Usually 1β10 days depending on scope and depth. Use the Audit Estimator above for a real-time estimate based on your specific target.
Do you offer ongoing / retainer security support?
Yes β periodic re-audits, on-call incident triage, and continuous automated scanning can be arranged. Mention this in the message form below and it'll be scoped as a retainer rather than a one-off.
Let's Secure Your Systems.
Available for security consulting, web application audits, network threat assessments, and security engineering roles. Send a direct message to start the conversation.