security researcher

Faraz Ahmed @PakCyberbot

Security Researcher

Red teamer, bug bounty hunter and CTF player. I break things, document them clearly, and build tooling for offensive security.

verified credentials

Certifications

Industry certifications, each with a public verification link. Course-completion certificates are archived separately.

GCP PCSE badge

Professional Cloud Security Engineer

Google Cloud · 2024

Google Cloud's professional certification for designing and operating secure workloads and infrastructure on Google Cloud Platform.

Verify credential
OSCP badge

Offensive Security Certified Professional

Offensive Security (OffSec) · 2024

Hands-on penetration-testing certification with a 24-hour practical exam. Awarded to me by OffSec after winning their report-writing contest.

Verify credential
eJPTv2 badge

eLearnSecurity Junior Penetration Tester v2

INE Security · 2023

Fully hands-on penetration-testing certification covering assessment methodology, host & network auditing, and exploitation.

Verify credential

Full certificate archive

Every course-completion and training certificate is stored in the repository.

View all certificates
capabilities

What I do

Click any area to read exactly what I do and verify it through the proof links.

Red Teaming

What I do

I simulate real-world attackers end to end — from external enumeration and initial access through privilege escalation, lateral movement and reporting. I work comfortably across Linux, Windows and cloud, and I care as much about a clear, reproducible report as about the exploit itself.

  • Full-scope penetration testing and adversary simulation
  • Privilege escalation and Active Directory / cloud attack paths
  • Clear, reproducible reporting (the reason OffSec awarded me a free OSCP)

Proof & verification

Bug Bounty

What I do

I hunt for impactful vulnerabilities in web and cloud applications — auth flaws, access-control issues, injection, SSRF and misconfigurations — and write them up so they can be reproduced and fixed.

  • Web and API security testing
  • Cloud misconfiguration review
  • Responsible disclosure and clear proof-of-concept write-ups

Proof & verification

OSINT

What I do

I run open-source intelligence investigations — people and infrastructure footprinting, verification and evidence collection — and I have both competed in and judged Trace Labs Search Party CTFs that support real missing-persons cases.

  • OSINT collection, correlation and verification
  • Trace Labs Search Party CTF participant and judge
  • Tooling for evidence gathering and documentation

Proof & verification

Cloud Security

What I do

I design and review secure cloud architectures and hunt for cloud misconfigurations — IAM, storage, network exposure and logging — with a focus on Google Cloud, where I hold the Professional Cloud Security Engineer certification.

  • Cloud security architecture and hardening
  • IAM and misconfiguration review
  • Cloud incident-investigation challenges (e.g. my HTB “MisCloud” Sherlock)

Proof & verification

Content Creation

What I do

I create practical cybersecurity content that turns real-world security concepts, research, and hands-on experience into challenges, labs, tutorials, and educational resources.

My work spans both technical challenge development and public cybersecurity education, with content designed to help security professionals, students, and enthusiasts understand how vulnerabilities and security concepts work in practice.

  • CTF challenge and lab design across web, forensics, OSINT, cloud, and other security domains
  • Realistic scenarios with intentional vulnerabilities, infrastructure, objectives, and solution paths
  • Cybersecurity tutorials, technical walkthroughs, and research-based content
  • YouTube videos covering penetration testing, cybersecurity tools, techniques, research, and practical security concepts
  • Technical articles and write-ups published on Medium and other platforms
  • Educational content focused on practical, hands-on security learning
  • Content creation for HackTheBox, TryHackMe, onsite events, and organizations

Platforms & Publications

  • HackTheBox — CTF challenges and Sherlocks
  • TryHackMe — Hands-on rooms and cybersecurity learning content
  • YouTube — Cybersecurity tutorials, research, tools, walkthroughs, and educational content
  • Medium — Technical articles, research, write-ups, and cybersecurity learning resources
  • Onsite Events & Organizations — Custom challenges, labs, and security-focused educational content

Proof & Verification

Programming

What I do

I build tooling and automation for offensive security and day-to-day work, mainly in Python with Bash and PowerShell for scripting, plus general programming across several languages.

  • Security tooling and automation (Python, Bash, PowerShell)
  • Open-source projects for red teaming and OSINT
  • Comfortable across multiple languages

Proof & verification