RED TEAM
/ HOME · INDEX
— · — · — v 4.2 · MMXXVI
OFFENSIVE SECURITY ENGINEER · DHAKA

I FIND THE flaws BEFORE THEY FIND YOU.

Comprehensive penetration testing across web, Android, IoT, and access-control hardware. Custom payloads, EDR/DLP bypass, and reproducible PoCs with strategic remediation — the kind of report your security team can act on.

Latest Writeup
2026 · 05 · 06 · 21 MIN READ
iOS jailbreak detection bypass — a Frida + Objection field guide
Read post №09 →
Currently
roleOff. Sec. Engineer · Shorborno · GP MSSP
studyM.Sc. Info Systems Security · BUP
field200+ Web · Android pentests
Shell
$whoami
ashfaq@dhaka:~
$uptime
5y · 2 CVEs · 100+ HOF
$
// 01 — Services

Built to break & defend

Four practice areas grounded in five years of red-team and pentesting work. Every engagement ships with a reproducible PoC and a strategic remediation plan.
All services →
[01] / OFFENSIVE

Red Team & APT Sim

Multi-stage Red Team engagements, realistic APT simulations, custom payload development, EDR & AV evasion.

View →
[02] / WEB

Web App Pentest

OWASP-aligned testing — SQLi, SSRF, SSTI, XSS, broken auth/authz. 200+ engagements completed.

View →
[03] / MOBILE

Android Pentest

Static & dynamic Android assessments with MobSF, APKTool, Frida, Objection, Jadx. eWPTX-grade rigor.

View →
[04] / EMBEDDED

IoT & Hardware

Firmware and hardware-level review of IoT devices, access-control hardware, biometric data, and telco assets.

View →
// 02 — Recent Writing

Field notes & writeups

CVE disclosures, research notes, and engagement-grade writeups — published when they're cleared for release.
All 6 entries →
№ 09 2026 · 05 · 06 mobile

iOS jailbreak detection bypass — a Frida + Objection field guide

Banking apps, e-wallets, and DRM clients all run a JB check before they trust their own code. The seven detection patterns and the runtime hooks that disarm each one.

21 min read →
№ 08 2026 · 05 · 04 mobile

Defeating Android SSL pinning in 2026 — a Frida-first methodology

The universal pinner script doesn't cut it anymore. A working playbook covering OkHttp, X509TrustManager, Network Security Config, custom validators, and native-layer pinning.

24 min read →
№ 10 2026 · 04 · 28 web

Server-Side Template Injection — from leak to RCE across five engines

A working playbook for SSTI in 2026 — engine fingerprinting, sandbox escapes, and the chains that get from a shell on Jinja2, Twig, Freemarker, Velocity, and ERB.

26 min read →