Skip to content
View umair-aziz025's full-sized avatar
๐ŸŽฏ
๐ŸŽฏ

Block or report umair-aziz025

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
umair-aziz025/README.md

Banner


Typing SVG

Application Security Analyst | AppSec

I focus on finding, validating, and communicating security issues across web applications, APIs, Android apps, and infrastructure-facing tooling. My work combines secure development, vulnerability research, CTF practice, bug bounty methodology, and clear technical reporting.


Skills & Tools

Application Security

Web App Testing
API Security Testing
Authentication & Access Control
IDOR, Logic Flaws & Payment Flow Review
Vulnerability Validation & PoC Writing
Offensive Security

Reconnaissance
Directory Bruteforcing
Endpoint Fuzzing
CTF Challenge Solving
Bug Bounty Reporting
Security Engineering

Python Security Automation
Packet Analysis
Android App Assessment
APK/API Investigation
Security Documentation
Languages

Python
JavaScript
TypeScript
PHP
Kotlin
HTML/CSS
Frameworks & Platforms

Flask
Node.js
React
Tailwind CSS
Firebase
Android Studio
Libraries & Utilities

Requests
Scapy
CustomTkinter
Playwright
Three.js
Git & GitHub

AppSec Workflow

Recon
Map assets, endpoints, exposed surfaces, and trust boundaries.
Test
Validate authentication, authorization, input handling, and business logic.
Report
Write practical PoCs, impact summaries, and remediation-focused findings.

Current Focus

AppSec
Web, API, Android
Research
CTFs, CVEs, bug bounty
Automation
Python tooling and scanners
Reporting
PoCs, impact, remediation


๐Ÿ” "Hack The Planet, Secure The Future" ๐Ÿ”


โญ Star my repositories if you find them useful!

Pinned Loading

  1. echo-response-offsec-challenge echo-response-offsec-challenge Public

    ๐Ÿ—๏ธ The Voidweaver's Trail: Season 1 Investigation Reports for Echo Response. Uncovering hidden identities and securing the Nullform Key across the Cyber Realm via advanced forensics and cryptanalysis.

    Python 15

  2. dahua-cve-research dahua-cve-research Public

    Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

    Python 18 6

  3. arctic-howl-offsec-season2 arctic-howl-offsec-season2 Public

    ๐Ÿบ Arctic Wolf's Last Stand: Official Season 2 Writeups for the Tundra Realm Cyber Defense Gauntlet. Log analysis, digital forensics, and threat hunting in a frozen cybersecurity battleground.

    3 1

  4. dune-phantom-offsec-Season3 dune-phantom-offsec-Season3 Public

    ๐Ÿฆ‚ Dune Phantom challenge writeups from the Ember Expanse, where logs shimmer, evidence disappears, and every investigation is a fight to separate signal from illusion.

    2