OffensiveSecurity.
Building practical skills in penetration testing, reconnaissance, and red team operations through hands-on labs and security projects.
MuhammadUmar.
Cybersecurity Student | Aspiring Red Team Operator
Building practical offensive security skills through hands-on labs, security projects, and a structured path toward professional red team operations.
Cybersecurity with a professional edge.
My journey into cybersecurity started with a fascination for the hidden layers of digital systems — network traffic, misconfigurations, exposed services, and the difference between how systems are designed to work and how they behave under pressure.
I'm building my foundation through hands-on labs, structured security learning, and practical experimentation across Linux, networking, reconnaissance, and vulnerability analysis. My current focus is preparing for eJPT, with OSCP and CRTO as the next milestones in my path toward professional red team operations.
Let's build secure systems.
Skills Arsenal.
A developing offensive security toolkit built through structured learning, hands-on labs, and continuous practice.
Network Enumeration
Systematically discovering hosts, ports, services, and potential attack surfaces across target environments.
Vulnerability Analysis
Identifying, understanding, and assessing security weaknesses, misconfigurations, and potential exploitation paths.
Privilege Escalation
Learning to identify privilege boundaries, insecure configurations, and escalation opportunities in controlled environments.
Network Analysis
Inspecting network traffic and protocol behavior to understand communication patterns and identify useful security information.
Security Tooling
Hands-on use of security tools for reconnaissance, enumeration, analysis, exploitation, and controlled lab exercises.
Learning Focus
Certifications & Roadmap.
A structured progression from cybersecurity fundamentals toward professional red team operations.
Hunarmand Punjab
Government of Punjab
eJPT
Junior Penetration Tester
INE Security
OSCP
Offensive Security Certified Professional
OffSec
CRTO
Certified Red Team Operator
Zero-Point Security
Lab Operations & Achievements
Documented hands-on security work across controlled labs, exploitation, reconnaissance, and vulnerability analysis.
EternalBlue (MS17-010) Exploitation
Successfully identified and exploited the EternalBlue vulnerability on a Windows 7 target machine within an isolated VirtualBox lab, gaining remote code execution and demonstrating practical understanding of SMB protocol weaknesses and Metasploit-based exploitation chains.
Custom Payload Development & Reverse Shell
Developed a custom Windows executable payload using Metasploit's msfvenom framework and delivered it to a target Windows 7 machine via a locally hosted HTTP server within an isolated VirtualBox lab network. Established a reverse TCP shell connection using Netcat, gaining remote command-line access and confirming full system-level control.
vsftpd 2.3.4 Backdoor Exploitation
Confirmed host reachability with ping and identified the vulnerable vsftpd 2.3.4 service using Nmap. Then used Metasploit's exploit/unix/ftp/vsftpd_234_backdoor module, triggered the ':)' backdoor, established a Meterpreter session, and confirmed root-level access on Metasploitable2.
Featured Projects
Open-source repositories, lab environments, and operational documentation built to sharpen offensive security skills.
No projects published yet.
Explore the full catalog
Browse the complete set of lab notes, tooling walkthroughs, and security research projects.
Let's Connect
Have a project, a security question, or a red team opportunity in mind? I'd like to hear from you.