Founder & CEO
Pentest App
Building an all-in-one offensive security platform: automated recon, vulnerability triage and reporting for teams that cannot afford a full red team.
Karachi, PK · available for work
Offensive Security Engineer · Founder. I break things carefully, then build the tools that stop the next person.
I'm Maaz — a third-year BSc Computer Science student at NED University of Engineering & Technology, founder of Pentest App, and the Director of the Cyber Security Module at Synteck Society.
My work sits between two worlds: the offensive side, where I hunt bugs, chain recon and write tooling like the 22,000+ line Bug Hunter Machine; and the defensive side, where I build SOC labs, detection rules and incident response workflows.
I also care a lot about how software feels — spatial interfaces, neumorphic depth and motion that has a reason to exist. Security tools do not have to look like they were built in 2003.
Pentest App
Building an all-in-one offensive security platform: automated recon, vulnerability triage and reporting for teams that cannot afford a full red team.
Synteck Society · NEDUET
Leading the cyber security module: workshops, CTF nights, and mentoring juniors from Linux fundamentals to live web exploitation.
DevShieldX
Hands-on vulnerability assessment, SOC workflows and reporting under a live engagement pipeline.
NED University of Engineering & Technology
Balancing coursework with independent research in exploit development, network forensics and detection engineering.
I'm the Founder & CEO of Pentest App — a platform that compresses an entire penetration testing workflow into something a small team can actually run.
Product walkthrough — Pentest App
A 22,000+ line offensive automation engine — recon chaining, fuzzing, vulnerability correlation and report generation in one pipeline.
Custom detection rules and correlation engine turning noisy logs into ranked incidents.
A full blue-team lab: simulated attacks, live triage and incident response runbooks.
Host discovery, port and service fingerprinting with risk scored output.
Wireless recon tool mapping access points, encryption posture and rogue devices.
OSINT-flavoured scraper that collects, dedupes and enriches structured leads.
Desktop library management system with a full C++ GUI and persistent storage.
Classic game rebuilt as a polished C++ graphical application.
Subdomain enumeration, asset discovery, OSINT correlation and attack-surface mapping.
Manual web testing backed by automated fuzzing — auth bypass, IDOR, injection, logic flaws.
Turning attacker behaviour into SIEM rules, dashboards and triage-ready incidents.
Reproducible write-ups with severity, impact and remediation a developer can act on.
IBM
CAISR
CCEP
CTIGA
Coursera
Course
Mindluster
Mindluster
Simplilearn
Cursa
Cursa
Open to security engineering roles, freelance pentests, collaborations on tooling, and speaking at university events. The fastest way to reach me is LinkedIn or email.