Karachi, PK · available for work

Maaz
Shahid

Offensive Security Engineer · Founder. I break things carefully, then build the tools that stop the next person.

22,000+
lines in Bug Hunter Machine
20+
certifications & simulations
8
shipped security tools
2
leadership roles
NED · BSc Computer Science · 3rd Yearstatus: online
$ whoami
maaz_shahid :: offensive security · founder · builder
$ cat ./focus.txt
web exploitation · detection engineering · security tooling
01about

Who is behind the terminal

I'm Maaz — a third-year BSc Computer Science student at NED University of Engineering & Technology, founder of Pentest App, and the Director of the Cyber Security Module at Synteck Society.

My work sits between two worlds: the offensive side, where I hunt bugs, chain recon and write tooling like the 22,000+ line Bug Hunter Machine; and the defensive side, where I build SOC labs, detection rules and incident response workflows.

I also care a lot about how software feels — spatial interfaces, neumorphic depth and motion that has a reason to exist. Security tools do not have to look like they were built in 2003.

Offensive
Web App PentestingRecon & OSINTExploit DevBurp SuiteNmapMetasploit
Defensive
SOC OperationsSIEM / SplunkIncident ResponseWiresharkThreat Intel
Engineering
PythonC++BashReactMongoDBLinux
Design
Spatial UINeumorphismMotion DesignDesign Systems

Founder & CEO

Pentest App

2026 — Present

Building an all-in-one offensive security platform: automated recon, vulnerability triage and reporting for teams that cannot afford a full red team.

StartupProductAppSec

Director, Cyber Security Module

Synteck Society · NEDUET

2026 — Present

Leading the cyber security module: workshops, CTF nights, and mentoring juniors from Linux fundamentals to live web exploitation.

LeadershipCTFTraining

Cyber Security Intern

DevShieldX

2026

Hands-on vulnerability assessment, SOC workflows and reporting under a live engagement pipeline.

VAPTSOCReporting

BSc Computer Science Student

NED University of Engineering & Technology

3rd Year

Balancing coursework with independent research in exploit development, network forensics and detection engineering.

NEDUETResearch
02the startup

Pentest App

I'm the Founder & CEO of Pentest App — a platform that compresses an entire penetration testing workflow into something a small team can actually run.

  • Automated recon and attack-surface mapping
  • Guided exploitation workflows with safe defaults
  • Client-ready reports generated from raw findings
role :: founder & ceo
stage :: building in public
See it in action — pentestapp.tech

Product walkthrough — Pentest App

03projects & demos

Selected work

flagship

Bug Hunter Machine

A 22,000+ line offensive automation engine — recon chaining, fuzzing, vulnerability correlation and report generation in one pipeline.

PythonAutomationRecon
$ wc -l bug_hunter_machine/
22,000+ lines · recon → fuzz → correlate → report

SIEM Detector

Custom detection rules and correlation engine turning noisy logs into ranked incidents.

DetectionPythonLog Analysis

CSNE SOC Lab

A full blue-team lab: simulated attacks, live triage and incident response runbooks.

SOCBlue TeamSplunk

Network Security Scanner

Host discovery, port and service fingerprinting with risk scored output.

PythonNetworkingNmap

WiFi Scanner

Wireless recon tool mapping access points, encryption posture and rogue devices.

Python802.11Recon

Lead Scraper

OSINT-flavoured scraper that collects, dedupes and enriches structured leads.

OSINTScrapingPython

Library Enchant GUI

Desktop library management system with a full C++ GUI and persistent storage.

C++GUIOOP

Hangman C++ GUI

Classic game rebuilt as a polished C++ graphical application.

C++GUI
04the arsenal

How I run an engagement

Recon

01

Subdomain enumeration, asset discovery, OSINT correlation and attack-surface mapping.

amasssubfindercustom scrapers

Exploitation

02

Manual web testing backed by automated fuzzing — auth bypass, IDOR, injection, logic flaws.

burp suiteffufmetasploit

Detection

03

Turning attacker behaviour into SIEM rules, dashboards and triage-ready incidents.

splunkwiresharksigma

Reporting

04

Reproducible write-ups with severity, impact and remediation a developer can act on.

cvssmarkdown → pdfpentest app
05receipts, not claims

Certifications & internships

badgestap to enlarge

Cyber Security InternDevShieldX

certificatesclick to zoom

IBM Penetration Testing

IBM

CAISR Certificate

CAISR

CCEP Certificate

CCEP

CTIGA Certificate

CTIGA

Splunk Core Certified

Coursera

Wireshark Network Analysis

Course

Incident Response

Mindluster

Associate SOC Analyst

Mindluster

Intro to Cyber Security

Simplilearn

C++ Programming

Cursa

MongoDB

Cursa

06contact

Let's build something secure

Open to security engineering roles, freelance pentests, collaborations on tooling, and speaking at university events. The fastest way to reach me is LinkedIn or email.