Vulnerability Research · OSINT Automation · Exposure Intelligence
Cybersecurity practitioner specializing in vulnerability discovery and OSINT automation. Transforming digital footprints into actionable intelligence. 5+ years disassembling attack surfaces. Recognized for preventing 1.14 TB of sensitive data exposure.
Cybersecurity researcher specializing in vulnerability discovery, OSINT automation, and exposure intelligence.
I specialize in mapping digital infrastructure to uncover vulnerabilities, exposed assets, and intelligence signals that are often overlooked. My work focuses on practical security research, structured OSINT methodologies, and actionable vulnerability discovery.
Recognized by Google Bug Hunters and Bugcrowd for responsible disclosure of vulnerabilities including XSS, Open Redirect, CSRF, and infrastructure misconfigurations.
Contributed to the prevention of 1.14 TB of sensitive data exposure through responsible disclosure and infrastructure misconfiguration analysis.
Current Work: Building TBV Server — a self-hosted intelligence platform combining real-time system monitoring, multi-source OSINT, CRM, CCTV integration, and structured threat analysis.
XSS, CSRF, Open Redirect, infrastructure exposure analysis across live targets
Breach intelligence, digital footprinting, and passive reconnaissance pipelines
Exposure tracking, warning-oriented analysis, structured risk reporting
Building TBV Server, automation pipelines, intelligence tooling at scale
Shortwave listening, spectrum analysis, wireless security research
Formal recognition from major vulnerability disclosure programs and proven impact in data protection.
Google Bug Hunters · Oct 2024
Recognized for responsible disclosure of critical XSS and Open Redirect vulnerabilities in YouTube. Formal recognition from Google's security team.
Bugcrowd Program · Jan 2025
High-volume submission recognition. Reported and validated critical security flaws in public platforms, directly contributing to vendor security improvements.
SMIU · Apr 2026
Recognized for participation in Civil Applications of Radio Technologies in Emergencies — covering RF systems and disaster response communications.
Discovered critical misconfigurations across 5 Pakistani software firms. Coordinated responsible disclosure preventing large-scale sensitive financial and employee data exposure.
Coordinated with educational institution administrators to mitigate a student data leak, safeguarding thousands of users and improving their protection framework.
Identified and reported an Open Redirect vulnerability in Bugcrowd's own platform, directly contributing to improved application security and vendor awareness.
TBV Bot OSINT automation tool used by 450+ security practitioners for breach detection and Exposure Intelligence workflows worldwide.
Independent cyber intelligence collective focused on OSINT, exposure analysis, and warning-oriented research.
TBV (To Be Verified) operates as the strategic framework for organized cyber intelligence work. Built on three layers: TBV Server (the operational backbone), TBV Bot (field automation, now retired), and the broader intelligence methodology.
The goal is simple: take messy digital footprints, scattered signals, and exposed data — then transform them into something that can actually be reasoned about. Everything integrates — collection, verification, analysis, and delivery.
Self-hosted LAN intelligence platform combining system monitoring, CRM, OSINT, CCTV, and network tooling into unified operational control.
OSINT automation tool used by 450+ users. Modular Python architecture with breach detection, threat correlation, and social media reconnaissance.
Hands-on discovery of web application vulnerabilities, infrastructure misconfigurations, and digital exposure through systematic analysis.
Methodology-driven investigations into exposure analysis, infrastructure mapping, and threat landscape intelligence.
Systematic detection of security weaknesses in web applications and infrastructure. Focus on XSS, Open Redirect, CSRF, and infrastructure misconfigurations.
Intelligence gathering on data breaches, exposure discovery, and compromise confirmation. Automated breach monitoring and correlation.
Comprehensive mapping of digital identity exposure. Social media reconnaissance, identity metadata extraction, and cross-platform analysis.
Passive mapping and asset discovery. DNS enumeration, WHOIS analysis, Shodan scanning, and technology fingerprinting without active probing.
Identification of sensitive data exposure vectors. Risk assessment, remediation coordination, and prevention strategies for data loss.
Python-powered automation of intelligence workflows. Integration of multiple OSINT APIs, scheduled research, and real-time threat correlation.
Production systems, research tools, and intelligence platforms built for cybersecurity analysis and OSINT operations.
Self-hosted LAN intelligence platform combining monitoring, OSINT, CRM, CCTV, and network tooling into unified operational control.
OSINT automation tool used by 450+ users for breach detection and Exposure Intelligence workflows. Modular Python architecture.
Responsible vulnerability disclosure with formal recognition from major tech platforms. Google, Bugcrowd, and more.
Complete overview of research systems, intelligence pipelines, and operational infrastructure.
Dedicated infrastructure for OSINT research, data collection, and intelligence analysis workflows.
Automated intelligence aggregation and processing pipeline for real-time threat monitoring.
Automated workflows for recurring research tasks, scanning, and intelligence gathering.
Real-time monitoring, alerting systems, and operational dashboards for infrastructure oversight.
Scalable storage infrastructure and high-performance data processing for large datasets.
API infrastructure and integrations with third-party services and intelligence sources.
Comprehensive skill set across cybersecurity, OSINT, infrastructure, and intelligent systems development.
Open to collaboration, research partnerships, and security consulting inquiries.
Cybersecurity Practitioner · OSINT Builder