// 04 — Credentials
Ashfaqul Haq
Five years across web, mobile, embedded, and adversary-simulation work. Two CVEs, four academic publications, 100+ Hall of Fame credits.
01 / Objective
Red Team specialist, end to end.
A results-driven Red Team specialist with experience identifying vulnerabilities across software, hardware, and network infrastructure. Comprehensive penetration testing of digital platforms (Web, Android) and physical / embedded systems — including IoT devices, access-control hardware, biometric data, and telco assets. Skilled in realistic APT simulations and bypassing modern defenses through sophisticated EDR and Antivirus evasion.
02 / Experience
Three roles, five years.
Off. Sec. Engineer · Shorborno
MSSP of Grameenphone Ltd. · GP House, Dhaka.
Cyber Security Analyst
Pentester Space · Agargaon, Dhaka.
Security Researcher
Synack Red Team Inc. · Redwood City, California (Remote).
Shorborno — Off. Sec. Engineer
- 200+ web and Android pentests on enterprise clients and bug-bounty programs.
- Critical web vulnerabilities — SQLi, SSRF, SSTI, XSS, broken auth and authorization.
- Embedded-systems assessments — IoT devices, access-control hardware, biometric data.
- Multi-stage Red Team engagements with APT simulations.
- Custom payloads — EDR evasion and DLP bypass.
- Technical reports with reproducible PoCs and strategic remediation.
Pentester Space — Cyber Security Analyst
- SOC monitoring with SolarWinds, Suricata, Wazuh, Splunk.
- SOAR-driven incident response across web, Android, network, and Active Directory.
- Compliance support — GDPR, ISO/IEC 27001, MITRE ATT&CK, NIST.
- IAM controls and AWS security best practices for new projects and vendors.
Synack Red Team — Security Researcher
- Vulnerability research on web and Android applications.
- Critical-to-low findings reported across the program lifecycle.
03 / Toolkit
Tools, languages, frameworks.
- Web Burp Suite Pro · Acunetix · OWASP ZAP · Nuclei · SQLMap
- Network Nmap · Wireshark · Nessus Pro · Tenable.io
- C2 Cobalt Strike · Sliver · Loki · Metasploit Pro
- AD BloodHound · CrackMapExec · Impacket · NetExec
- Mobile APKTool · MobSF · Jadx-GUI · Frida · Objection
- RE Ghidra · x32dbg · PE-Bear
- Crypto Hashcat · John the Ripper
- Code Python · Bash · C (elementary) · Snyk.io
- Compliance NIST SP 800-115 · ISO/IEC 27001:2022 · MITRE ATT&CK
04 / Certifications
Eight programs.
Offensive operations, web, mobile, infra, and cloud.
- CRTO Certified Red Team Operator Zero-Point Security
- eWPTX Web Pentester eXtreme v2.0 INE / eLearnSecurity
- CRTA Certified Team Analyst CWL
- CRT-ID Red Team Infra Dev CWL
- MCRTA Multi-Cloud Red Team Analyst CWL
- PAPI Practical API Hacking TCM Security
- MAPT Mobile App Pentesting TCM Security
- DFIR Autopsy Basics Hands-on Training
05 / Education & awards
Two degrees, five podium finishes.
M.Sc. Information Systems Security
Bangladesh University of Professionals (BUP) — Mirpur Cantonment, Dhaka.
B.Sc. Electrical & Electronic Engineering
International Islamic University Chittagong — Kumira. CGPA 3.09 / 4.0.
★ Champion · Team SiliconBits
National Cyber Drill 2020 — BGD e-GOV CIRT.
4× Runners-up
IIUC T3 (Inter-Univ. Cyber Drill) · SiliconBits (CTF Super League, IEEE CS BUET) · Bitsoverflow (National Cyber Drill 2021) · Secure Hex (IIUC CyberCon 2022).
06 / Hall of Fame
100+ acknowledged.
A partial list — full counter still climbing.
- Nokia
- ServiceNow
- Sony
- Lenovo
- Harvard University
- Avast
- CCleaner
- Jira PM
- Factorial
- Abbie
- Envato
- Gorgias
- Takeways
- +100 more
07 / CVEs
Two published.
Both stored XSS — disclosed responsibly through public CVE channels.
CVE-2024-44851
Stored XSS in the File Sharing module of Perfex CRM.
CVE-2024-46638
Stored XSS in HelpDeskZ v2.0.2.
08 / Publications
Four academic publications.
Faking Smart Industry — Honeypot Research
Co-author. Wireless Networks (WINET).
★ Same paper · Best Paper Award
14th EAI International Wireless Internet (EAI WICON 2021).
IoT Air Quality & Weather Monitoring
First-author. International Conference on Innovations in Science, Engineering, and Technology (ICISET-2022).
Risk-Based MITRE TTP Scoring
Co-author. 2025 14th International Conference on Software and Computer Applications. pp. 72–76.
Securing Agentic AI
Co-author. Threats, risks, and mitigation.
// Engagement