[ active ] · Red Teaming · OSINT

Aqueel Ahmed

// security, in practice.

I’m really into figuring out how things work, then seeing how far I can push them. I love OSINT too — I find it exciting and thrilling. Currently learning Malware Development, Rust, and LLMs.

work 01 / 05

ASTRA — Cyber Range

End-to-end adversary simulation platform with real-time telemetry streaming, MITRE ATT&CK mapping, and a live SOC triage interface. Built the SessionDriver to orchestrate the attack, log generation, detection, and scoring engines as an async pipeline over Redis pub/sub. Owned the detection engine (Sigma, anomaly, correlation), the streaming layer, scoring, and reporting. Production-hardened with Firebase auth, IDOR closures, Redis-backed rate limiting, CSP/CORS, and fail-closed security defaults.

Hosted on Render free tier — the live demo and api may take ~30s to cold-start. Open the api link first to wake the backend.

fastapi redis mitre att&ck sigma detection engineering python security architecture

VaultSync

github pages

A personal vault that runs entirely in your browser. Files are encrypted with AES-256-GCM using keys derived through 150,000 PBKDF2-SHA-256 iterations — all before anything leaves your machine. The server only ever sees ciphertext. Firebase handles identity, Supabase stores the encrypted blobs, the plaintext stays with you.

web crypto api aes-256-gcm pbkdf2 firebase supabase es modules

QR Code Generator

github pages

A minimalist QR code generator that runs entirely in your browser. Encode URLs, WiFi credentials, vCards, Google Maps locations, or any text — pick a size and color, hit generate, download the PNG. No backend, no tracking; the data never leaves your machine. Single HTML file, no build step.

vanilla js qrcode.js html5 css3 static

stack 02 / 05

Languages

Python, JavaScript, C, Rust

Web, Backend & Streaming

FastAPI, Redis, WebSockets, Firebase, Supabase, Web Crypto API

Offensive Toolkit

Nmap, Wireshark, Burp Suite, Metasploit, Maltego, Aircrack-ng

Detection & Threat Intel

Sigma, MITRE ATT&CK, YAML, Splunk, Elastic Stack (ELK)

Focus Areas

OSINT · GEOINT · Red Teaming · Detection Engineering · Traffic Analysis · Cryptography · Web App Security · Threat Intel · Malware Development · Security Architecture

Environment

Linux (Debian & Arch), Windows, Bash, Git, VS Code, VirtualBox

writing 03 / 05

I write on Substack about network traffic analysis and the gap between privacy theory and what surveillance actually sees — trying to turn the intimidating parts into something a curious person can follow. On Medium I publish longer writeups: security findings, debugging postmortems, and how the projects above actually got built.

ctfs & wargames 04 / 05

Operation Gambler — UK OSINT Community
Real-world investigative scenarios. Certified finisher.
29th place
Maltego Community CTF 2025
Link analysis and entity resolution challenges.
83rd place
TryHackMe — First Shift CTF
Completed rooms covering initial access and triage.
completed
OverTheWire — Bandit
Hands-on Linux CLI, file permissions, networking, privilege escalation.
completed
TryHackMe learning paths
Pre Security, Cybersecurity 101, Advent of Cyber 2024.
owasp top 10 metasploitable networking nerd ohsint webbed blue cat linux.txt
@darknight707

// contact 05 / 05

Drop a line at shado_404@proton.me — or find me in any of these corners of the internet.