ReconSpider
A modular Python framework that automates subdomain enumeration, port scanning, and tech-stack fingerprinting into a single OSINT report.
// PENETRATION TESTER · BUG BOUNTY HUNTER · CTF PLAYER · RED TEAMER
I break things on purpose, so real attackers can't break them first. Five years finding what's exploitable — in web apps, networks, and cloud infrastructure — before it becomes tomorrow's breach headline.
Last login: Fri Jul 10 09:41:02 on ttys001
musfikur@decode420:~$ █
A day in the life: reconnaissance, exploitation, reporting — repeat.
$ ls ~/projects --sort=recent
A selection of tools, automation scripts, and engagement reports built while breaking (and fixing) real systems.
A modular Python framework that automates subdomain enumeration, port scanning, and tech-stack fingerprinting into a single OSINT report.
Full internal assessment for a mid-size fintech firm: AD misconfigurations, lateral movement paths, and privilege escalation chains, delivered as an executive + technical report.
Self-hosted dashboard for tracking bug bounty targets, scope, findings, and disclosure status across multiple platforms in one place.
OWASP Top 10-aligned audit uncovering IDOR, auth bypass, and stored XSS issues in a patient-records platform. Coordinated remediation with the engineering team.
A running archive of solved challenges from HackTheBox, TryHackMe, and live CTF competitions, with reusable exploitation notes and technique breakdowns.
Internal red-team tool for running controlled phishing campaigns and measuring org-wide susceptibility, with an automated reporting dashboard for stakeholders.
$ cat skills.json
Core competencies sharpened across five years of engagements, plus the credentials that back them up.
Offensive Security · 2023
EC-Council · 2022
CompTIA · 2021
INE / eLearnSecurity · 2020
Cisco · 2020
$ cat career.log
Five years, four roles, one throughline: finding the gap before someone else does.
$ whoami --verbose
I'm Musfikur Rahman, an offensive security professional who's spent the last five years learning how systems break so I can help teams fix them before someone with worse intentions finds the same gap. I started on the defensive side as a network admin and SOC analyst, which still shapes how I think today — I don't just report a vulnerability, I explain what it actually costs a business if it's left alone.
Outside of client work, I spend evenings on bug bounty programs and weekends on CTF teams — partly for the prize money, mostly because it's the fastest way to stay sharp against techniques that haven't made it into a training course yet. I believe good security work is equal parts technical depth and clear communication: a finding no one understands is a finding no one fixes.
$ ./contact.sh --secure
Open to penetration testing engagements, security consulting, and interesting bug bounty collaborations.