// PENETRATION TESTER  ·  BUG BOUNTY HUNTER  ·  CTF PLAYER  ·  RED TEAMER

Musfikur Rahman

I break things on purpose, so real attackers can't break them first. Five years finding what's exploitable — in web apps, networks, and cloud infrastructure — before it becomes tomorrow's breach headline.

5+ Years in the field
60+ Vulnerabilities disclosed
12 Certifications earned
musfikur@decode420:~

Last login: Fri Jul 10 09:41:02 on ttys001

musfikur@decode420:~$

A day in the life: reconnaissance, exploitation, reporting — repeat.

$ ls ~/projects --sort=recent

Projects & Tools

A selection of tools, automation scripts, and engagement reports built while breaking (and fixing) real systems.

Active

ReconSpider

A modular Python framework that automates subdomain enumeration, port scanning, and tech-stack fingerprinting into a single OSINT report.

PythonAsyncioOSINT
Complete

Internal Network Pentest — FinTech Client

Full internal assessment for a mid-size fintech firm: AD misconfigurations, lateral movement paths, and privilege escalation chains, delivered as an executive + technical report.

Active DirectoryBloodHoundReporting
Active

BountyLogger

Self-hosted dashboard for tracking bug bounty targets, scope, findings, and disclosure status across multiple platforms in one place.

FlaskSQLiteREST API
Complete

Web App Security Audit — Healthcare SaaS

OWASP Top 10-aligned audit uncovering IDOR, auth bypass, and stored XSS issues in a patient-records platform. Coordinated remediation with the engineering team.

Burp SuiteOWASPXSS / IDOR
Ongoing

CTF Write-up Archive

A running archive of solved challenges from HackTheBox, TryHackMe, and live CTF competitions, with reusable exploitation notes and technique breakdowns.

CTFBinary ExploitationWeb
Complete

Phishing Simulation Toolkit

Internal red-team tool for running controlled phishing campaigns and measuring org-wide susceptibility, with an automated reporting dashboard for stakeholders.

GoPhishSocial EngineeringPython

$ cat skills.json

Skills & Certifications

Core competencies sharpened across five years of engagements, plus the credentials that back them up.

Networking

TCP/IP & Routing
Firewalls & VPNs
Wireshark / tcpdump

Penetration Testing

Web App Pentesting
Active Directory Attacks
Burp Suite / Metasploit

Systems

Linux Administration
Bash Scripting
Windows / AD Internals

Development

Python
Bash / Automation
REST APIs

Certifications

OSCP — Offensive Security Certified Professional

Offensive Security · 2023

CEH — Certified Ethical Hacker

EC-Council · 2022

CompTIA Security+

CompTIA · 2021

eJPT — eLearnSecurity Junior Penetration Tester

INE / eLearnSecurity · 2020

CCNA — Cisco Certified Network Associate

Cisco · 2020

$ cat career.log

Experience

Five years, four roles, one throughline: finding the gap before someone else does.

2024 — Present

Senior Penetration Tester

Vantablack Security · Remote
  • Lead full-scope penetration tests for enterprise clients across fintech, healthcare, and SaaS.
  • Mentor junior testers and review methodology, evidence, and final report quality.
  • Built internal automation that cut recon time on new engagements by roughly 40%.
2022 — 2024

Penetration Tester

Redshift Cyber Labs · Austin, TX
  • Performed web application, network, and cloud security assessments for mid-market clients.
  • Delivered 50+ engagement reports translating technical findings into business risk.
  • Earned OSCP and CEH while actively billing client work.
2021 — 2022

SOC Analyst II

Northgate Financial · Austin, TX
  • Triaged and investigated security alerts across SIEM, EDR, and network monitoring tools.
  • Wrote detection rules that reduced false-positive alert volume by roughly a third.
  • Led incident response for two contained phishing-driven intrusions.
2019 — 2021

Network Administrator / SOC Analyst I

Northgate Financial · Austin, TX
  • Managed enterprise network infrastructure: switching, routing, firewalls, and VPN access.
  • Started competing in CTFs on weekends, which pulled me toward offensive security.
  • Earned CCNA and Security+ to formalize a self-taught networking background.

$ whoami --verbose

About

decode420
Dhaka , Bangladesh

I'm Musfikur Rahman, an offensive security professional who's spent the last five years learning how systems break so I can help teams fix them before someone with worse intentions finds the same gap. I started on the defensive side as a network admin and SOC analyst, which still shapes how I think today — I don't just report a vulnerability, I explain what it actually costs a business if it's left alone.

Outside of client work, I spend evenings on bug bounty programs and weekends on CTF teams — partly for the prize money, mostly because it's the fastest way to stay sharp against techniques that haven't made it into a training course yet. I believe good security work is equal parts technical depth and clear communication: a finding no one understands is a finding no one fixes.

  • 5+ years in cybersecurity & networking
  • B.Sc. in Computer Networking
  • English & Bengali
  • Currently focused on cloud & Active Directory security

$ ./contact.sh --secure

Get In Touch

Open to penetration testing engagements, security consulting, and interesting bug bounty collaborations.