Available for: Web App PentestingAvailable for: SOC AnalystAvailable for: Detection Engineering

Penetration Tester
& SOC Analyst

Dual offensive/defensive background — web app pentesting, bug bounty on HackerOne & Bugcrowd, plus 500+ endpoint SIEM detection engineering.

Based in Lahore, Pakistan Open to remote and international roles
40+
MITRE Rules Authored
500+
Endpoints Secured
10+
Vulnerabilities Reported
Top 1%
TryHackMe

// about.me

Offensive Mindset,
Defensive Depth

Cybersecurity professional with 3+ years of experience and a dual offensive/defensive background, now focused on web application penetration testing and bug bounty research.

Proficient in full-cycle web app pentesting — recon through exploitation and reporting — applying OWASP Top 10 methodology, Burp Suite Pro, and manual exploitation across XSS, SQLi, IDOR, authentication flaws, and business logic vulnerabilities. Actively hunting on HackerOne and Bugcrowd.

Real-world detection engineering experience — authoring 40+ MITRE ATT&CK-mapped rules across a 500+ endpoint fintech environment — directly informs attacker thinking and exploit identification depth.

Current Role
Cybersecurity Engineer & SOC Analyst
PostEx Fintech — Lahore, Pakistan
Specialization
Web App Pentesting & Bug Bounty
OWASP Top 10 · HackerOne · Bugcrowd · Burp Suite Pro
TryHackMe
Top 1% — Rank #19,078
218 Rooms · 39 Badges · Jr. Pen Tester Path
Education
BS Computer Science
NCBA&E, Lahore — Completed in 2023

// work.history

Professional Experience

Cybersecurity Engineer & SOC Analyst

PostEx (Fintech)

Jan 2025 – PresentLahore, Pakistan
Burp SuiteMITRE ATT&CKWazuhSplunkElastic DefendOpenVASNmapSysmonn8nThreat IntelIncident Response
  • Engineered 40+ custom detection rules mapped to MITRE ATT&CK (T1059, T1486, T1078, T1053, T1021), developing attacker-pattern intuition applied directly to offensive research.
  • Lead full-cycle incident response — triage, containment, eradication, and post-incident review — producing root-cause reports and detection improvements for each engagement.
  • Conduct proactive threat hunting across endpoint and network telemetry (Sysmon, Zeek, firewall logs), surfacing lateral movement, persistence, and C2 patterns transferable to purple/red team scenarios.
  • Perform vulnerability assessments using OpenVAS and Nmap; lead CVE analysis, CVSS v3.1 prioritization, patch coordination, and OS hardening against CIS Benchmark controls.
  • Operate Elastic Defend EDR — monitoring process injection, credential access, and suspicious network behavior — building hands-on understanding of EDR detection logic exploited during offensive engagements.
  • Integrate threat intelligence feeds (IOCs, TTPs) into SIEM correlation and enrich alerts with VirusTotal, AbuseIPDB, and OSINT lookups for faster, higher-confidence triage.
  • Reduced SIEM false positives by ~40% through correlation tuning, threshold calibration, allow-listing, and log-source filtering — verified to preserve true-positive coverage.
  • Designed n8n SOAR automation pipelines achieving sub-2-minute MTTN for P1/P2 alerts via auto-enrichment, ticketing, and Telegram/email notification.
  • Author SOC runbooks and playbooks, mentor junior analysts, and report security posture and KPIs to management on a recurring basis.

Assistant Network Administrator

PostEx (Fintech)

May 2023 – Dec 2024Lahore, Pakistan
MikroTikOSPF/BGPVLANL2VPNFirewall ACLVPNDNS/DHCPMonitoring
  • Managed firewall ACL rules, VLAN segmentation, and network topology for a 500+ node environment — network knowledge directly supporting network-layer pentest reconnaissance.
  • Configured MikroTik routers with OSPF/BGP routing and L2VPN tunnels; supported threat containment by isolating compromised segments during SOC-flagged incidents.
  • Administered core network services — DNS, DHCP, and site-to-site VPN — and enforced least-privilege access between office, server, and production VLANs.
  • Deployed network monitoring (SNMP, syslog, uptime alerting) to detect outages and anomalous traffic early, cutting mean time to detection for link failures.
  • Hardened network devices — disabled unused services, enforced strong management-plane access, and applied firmware updates — reducing the exposed attack surface.
  • Maintained change logs, device configurations, and network documentation supporting audit and compliance requirements.

Technical Support Engineer

StormFiber

Feb 2023 – May 2023Pakistan
L1/L2/L3 SupportNOCSLAFiber OpticGPONTroubleshootingTicketing
  • Diagnosed L1/L2/L3 network faults for enterprise customers; coordinated with NOC during outages following SLA escalation procedures.
  • Troubleshot GPON / fiber-optic connectivity — signal levels, ONU/OLT provisioning, and last-mile faults — restoring service within SLA targets.
  • Managed the ticketing lifecycle end to end, documenting root cause and resolution steps to build a reusable knowledge base for recurring issues.
  • Guided customers through remote diagnostics and configuration, consistently maintaining high first-contact resolution and customer-satisfaction scores.
  • Escalated and tracked complex incidents with upstream teams, ensuring timely resolution and clear status communication to stakeholders.

// tech.stack

Tools & Technologies

A practical toolkit spanning the full offensive-to-defensive lifecycle — from reconnaissance and exploitation through detection engineering, SIEM operations, and network hardening.

Web & App Pentest

Burp Suite Pro
OWASP ZAP
SQLMap
Nikto
ffuf
Nuclei
Postman
JWT Tooling

Recon & OSINT

Amass
Subfinder
dnsx / httpx
Shodan
Arjun
GoBuster
theHarvester
Wayback Machine

Exploitation & Post-Ex

Metasploit
Hydra
John the Ripper
Hashcat
Impacket
BloodHound

SIEM & Detection

Splunk
Wazuh
Elastic Stack
ELK + Kibana
Sigma Rules
Sysmon
OpenVAS
Elastic Defend

Networking & Infra

MikroTik
Wireshark
OSPF / BGP
Active Directory
Proxmox VE
VMware
Docker
Linux / Windows

Scripting & Frameworks

Python
Bash
PowerShell
Git
n8n Automation
OWASP Top 10
MITRE ATT&CK
CVSS v3.1

// projects

Featured Work

Featured

Bug Bounty & Web Application Security Research

Systematic OWASP Top 10 hunting on HackerOne and Bugcrowd. Recon-to-report methodology producing high-signal, reproducible findings across access control, injection, and business-logic flaws.

HackerOneBugcrowdBurp SuiteOWASP Top 10CVSS
Read case study

Web Application Penetration Testing Lab

Self-hosted lab (DVWA, custom Docker targets, PortSwigger) for full exploitation chains: SQLi, XSS, file-upload bypasses, SSRF, JWT flaws, deserialization, SSTI, and API abuse.

DVWAHackTheBoxTryHackMeDockerMetasploit
Read case study

Authentication & Session Attack Research

Deep-dive into broken auth chains: JWT alg:none, session fixation, OAuth misconfiguration, MFA bypass, and password-reset host-header injection. PoC-driven with CVSS scoring (lab targets only).

JWTOAuthMFA BypassBurp SuiteCVSS
Read case study

MITRE ATT&CK Detection Rule Library

Authored 40+ detection rules across 15+ ATT&CK techniques (T1059, T1486, T1078, T1053) for ransomware, lateral movement, and persistence. Attacker-informed logic validated against simulated activity.

Splunk SPLWazuh XMLEQLSigmaMITRE ATT&CK
Read case study

SOC Automation Pipeline (n8n)

Orchestration achieving sub-2-minute MTTN for P1/P2 alerts: auto-enrichment, ticketing, multi-channel notification, and guarded endpoint containment.

n8nWazuh APIJIRATelegram BotPython
Read case study

SIEM False Positive Reduction Program

Reduced Wazuh/Splunk false positives by ~40% through correlation tuning, threshold calibration, and log filtering — verified to preserve true-positive coverage.

SplunkWazuhELKCorrelation RulesLog Analysis
Read case study

Vulnerability Assessment & Hardening Program

Recurring OpenVAS and Nmap assessment across a 500+ node estate, prioritized by CVSS and business impact, with CIS Benchmark hardening for Linux and Windows Server.

OpenVASNmapCIS BenchmarkCVSS v3.1Hardening
Read case study

Zero-Trust Network Segmentation

VLAN-based micro-segmentation across 50+ segments using MikroTik and firewall ACL policy enforcement, with OSPF/BGP routing and L2VPN tunnel management.

MikroTikVLANOSPF/BGPL2VPNFirewall ACL
Case study coming soon

EDR Monitoring & Endpoint Hardening

Operate Elastic Defend EDR monitoring process injection, file activity, and network behavior — building hands-on understanding of EDR detection logic relevant to offensive engagements.

Elastic DefendFIMWazuhProcess InjectionCIS
Case study coming soon

// detection.rules

Detection Research

Sanitized, generalized detection logic mapped to MITRE ATT&CK (Splunk, Sigma, Wazuh, Elastic). Shared for demonstration only — no employer-specific thresholds or internal logic. Offensive value: reverse-engineering rule logic exposes detection gaps and informs evasion thinking during pentest engagements.

Brute Force Detection

T1110 · Brute Force
brute_force.splSPL
index=windows_security EventCode=4625
| bucket span=5m _time
| stats count dc(src_ip) as unique_ips
    values(src_ip) as src_ips
    by _time dest_user Account_Name
| where count > 10
| eval risk_score=if(count>50,"CRITICAL",
    if(count>20,"HIGH","MEDIUM"))
| table _time dest_user count unique_ips
    src_ips risk_score | sort - count

Lateral Movement via PsExec

T1021.002 · SMB/Windows Admin Shares
lateral_movement.ymlSIGMA
title: Lateral Movement via PsExec
id: d5866ddf-ce8f-4aea-b28e-d96485a20d3d
status: production
author: Asad Noor
logsource:
  product: windows
  service: system
detection:
  selection:
    Channel: System
    EventID: 7045
    ServiceName: 'PSEXESVC'
  condition: selection
falsepositives:
  - Legitimate admin usage
level: high
tags:
  - attack.t1021.002
  - attack.lateral_movement

Malicious PowerShell Execution

T1059.001 · PowerShell
powershell_exec.xmlWAZUH XML
<group name="powershell,t1059,windows,">
  <rule id="100301" level="12">
    <if_group>windows_security</if_group>
    <field name="win.eventdata.commandLine"
           type="pcre2">
      (?i)(EncodedCommand|bypass|hidden|
      downloadstring|iex|invoke-expression)
    </field>
    <description>T1059.001: Suspicious
    PowerShell execution</description>
    <mitre><id>T1059.001</id></mitre>
  </rule>
</group>

Process Injection Hunt

T1055 · Process Injection
process_injection.eqlEQL
sequence by host.name with maxspan=30s
  [process where event.type == "start"
   and process.name :
     ("cmd.exe","powershell.exe")
   and process.parent.name :
     ("svchost.exe","explorer.exe")]
  [network where destination.port
     in (443, 4444, 8080)
   and not destination.ip : "10.0.0.0/8"
   and not destination.ip : "172.16.0.0/12"]

Ransomware Behaviour Hunt

T1486 · Data Encrypted for Impact
ransomware.splSPL
index=sysmon EventCode=11
  file_name="*.encrypted" OR
  file_name="*.locked" OR
  file_name="READ_ME*" OR
  file_name="HOW_TO_DECRYPT*"
| stats count dc(file_name) as unique_files
    values(file_name) as files by host
| where unique_files > 20
| eval severity="CRITICAL"
| table host unique_files files severity
| sort - unique_files

Persistence via Scheduled Task

T1053.005 · Scheduled Task
scheduled_task.xmlWAZUH XML
<group name="persistence,t1053,windows,">
  <rule id="100401" level="10">
    <if_group>windows_security</if_group>
    <field name="win.system.eventID"
           type="pcre2">^4698$</field>
    <description>T1053.005: Scheduled task
    created - possible persistence</description>
    <mitre><id>T1053.005</id></mitre>
    <group>persistence,</group>
  </rule>
  <rule id="100402" level="14"
        frequency="3" timeframe="300">
    <if_matched_sid>100401</if_matched_sid>
    <description>Repeated sched task
    creation - high confidence T1053</description>
  </rule>
</group>

// learning.certs

Certifications & Learning

TryHackMe
verify
Global Rank#19,078
PercentileTop 1%
Rooms Completed218
Badges Earned39
Jr. Penetration Tester Path
DevSecOps Path
Web Fundamentals Path

Verified Certifications (in progress / planned marked with a clock)

CCNA
Cisco / Corvit System · 2022
Done
Certified Ethical Hacker (CEH)
EC-Council · 2022
Done
CyberOps Associate
Cisco · 2024
Done
Ethical Hacker
Cisco · 2024
Done
SOC Analyst
Palo Alto Networks
Done
Fundamentals of Network Security
Palo Alto Networks
Done
Fundamentals of Cloud Security
Palo Alto Networks
Done
Jr. Penetration Tester Path
TryHackMe
Done
DevSecOps Learning Path
TryHackMe
Done
Web Fundamentals Path
TryHackMe
Done
Practical Web Hacking & Testing
TCM Security Academy
In progress
BTL1 — Blue Team Level 1
Security Blue Team
In progress

PortSwigger Web Security Academy

Actively completing all lab modules

80%
SQL Injection
XSS
CSRF
Clickjacking
SSRF
XXE Injection
OS Command Injection
Path Traversal
Authentication Bugs (not yet completed)
Business Logic (not yet completed)

// contact

Get In Touch

Open to web app pentesting, SOC analyst, and detection engineering roles — remote or based in Lahore, Pakistan. Send a message below or reach out on any verified profile.

0/2000
Lahore, Pakistan · Open to remote and international roles
LinkedInVerified profile
linkedin.com/in/asadnoor951
GitHubVerified profile
github.com/asadnoor9
HackerOne logo
HackerOneVerified profile
hackerone.com/bl4ck_h4wk
TryHackMe logo
TryHackMeVerified profile
tryhackme.com/p/asadnoor
Email
asadnoor951@gmail.com

Responsible disclosure: security reports are welcome via email or LinkedIn. I follow coordinated disclosure and program safe-harbor terms.