$ whoami && cat about.mdx
Muhammad Abdullah aka Hwat Sauce
❯_
About
Muhammad Abdullah aka Hwat Sauce
Creative, passionate, and self-taught individual with a love for Offensive Security, Penetration Testing, Red Teaming, Reverse Engineering, CTFs and Little bit of Crypto. Willing to work with others in the hopes of learning new things and creatively providing solutions to complex problems and collaborating with them.
By day, I'm a coffee-fueled coder and nerd, hammering out lines of code like there's no tomorrow. But when the sun sets, the real fun begins. I don my virtual cape, pull on my digital gloves, and dive deep into the cyber-verse. I'm not just a hacker — I safeguard the digital landscape.
I dance through encryption like it's a rhythm game, always two steps ahead of the cyber crooks. Don't worry, though — I mostly focus on keeping things secure.
In this age of digital goldmines, I'm the silent protector, watching over your data while you sleep. If there's a breach to be patched or a botnet to be busted, you can count on me. So if you need a partner in code or just someone to talk shop about the latest infosec trends, I'm your go-to. Here's to being a keyboard ninja by night and a security enthusiast by day!
Skills#
- Programming Languages: Python, C++, C#, Java, Bash, and Assembly.
- Tools & Frameworks: Docker, Metasploit, Burp Suite, Nessus, and Nmap.
- Platforms: Linux, Windows, AWS, GCP, Azure, and Cloudflare.
- Blogging: As a hobby, I periodically blog about cybersecurity. You can find my posts on Medium.
Experience#
- ABHI Microfinance Bank, Ltd. — Islāmābād, Pakistan [Full Time - On Site]
- Asst. Mgr. System Security & QA (Jul 2026 - Present)
- Officer System Security & QA (Dec 2025 - Jul 2026)
- Penetration Tester at Pakistan National CERT (May 2025 - August 2025) [Intern - On Site]
- Security Challenge Developer at Trustline (April 2024 - Sep 2024) [Frelance - Remote]
- Cyber Security Analyst at NCCS - National Center Of Cybersecurity in collaboration with Cybericks (June 2024 - Sep 2024) [Intern - Hybrid]
Education#
- Bachelor's in Cyber Security from Air University, Islamabad (2022 - 2026)
Certifications#
- Certified in Cyber Security (CC)
- Certified ISO/IEC 27001 Information Security Associate
- INE Certified Cloud Associate (ICCA)
- INE Certified Jr. Penetration Tester (eJPT)
- Certified Network Security Practitioner (CNSP)
- Certified Red Team Analyst (CRTA)
- Certified Penetration Testing Specialist (CPTS)
Publications:#
Achievements#
- 2nd Place at Hack Arena CTF organized by UET Peshawar, onsite (2025)
- Top 50 at Black Hat MEA 2025 CTF Quals organized by Flagyard, online (2025)
- 4th Place at Cyber Muhafiz CTF'25 organized by Pakistan National CERT, onsite (2025)
- 4th Place at SofTech CTF'25 organized by Fast University Lahore, onsite (2025)
- 50th Global Rank at PicoCTF'25 organized by PicoCTF, online (2025)
- Top 50 at Black Hat MEA 2024 CTF Finalists organized by Flagyard, onsite (2024)
- 98th Global Rank at CSWA CTF Qualifiers 2024 organized by New York University, online (2024)
- 4th Place at AirTech CTF'24 organized by Air University Islamabad, onsite (2024)
- 5th Place at SofTech CTF'24 organized by Fast University Lahore, onsite (2024)
- 10th Place at Digital Pakistan Cyber Security Hackathon organized by IGNITE, onsite in Islamabad (2023)
- 5th Place at CyberQuest CTF'23 organized by Sir Syed CASE Institute of Technology, onsite (2023)
- 4th Place at BlitzStorm CTF'23 organized by Blitzstorm, online (2024)
- 8th Place at NasCon'23 organized by FAST University Islamabad, onsite (2023)
- 4th Place at CyberStorm organized by Air University, onsite in Islamabad (2023)
- Ranked in the top 6% on TryHackMe, online (2022 - Present)
Projects#
- DeepTrace: DeepTrace is an Internet Protocol Detail Record (IPDR) system that captures, parses, and visualizes network traffic data at flow level. It supports both offline PCAP file analysis and real-time packet capture, with a multi-layer security analysis engine capable of detecting 23 distinct attack types.
- pathhound-mcp: An MCP (Model Context Protocol) server that lets an LLM reason over an Active Directory attack graph already collected by BloodHound — shortest paths to Tier 0, blast radius from a principal, the highest-leverage choke points to remediate, and defender-facing remediation text — with every action scoped to an authorized engagement and logged.
- ActiveDecoy: An automated ITDR (Identity Threat Detection and Response) framework designed to orchestrate and deploy believable Active Directory honey-objects for proactive lateral movement detection.
- GPO-Audit: GPO-Audit audits Microsoft Group Policy Object (GPO) reports exported via Get-GPOReport (HTML or XML). It focuses on identifying common hardening gaps, risky delegation, and unresolved (orphaned) security principals, and it can export results and compare drift against a baseline.
- HeepHound: HeapHound is a Python-based tool built with my dear friend Muhammad Munib and Radeel Ahmed for analyzing Java heap dump files (
.hprof) to extract sensitive data, assess risks, and generate forensic reports. It identifies credentials, tokens, and other artifacts using built-in heuristics, producing reports inJSON,HTML, and text formats. Ideal for security investigations, malware analysis, and incident response. - NetEye: Net-Eye is an all-in-one Python-based network reconnaissance tool that detects live hosts, scans ports, grabs banners, resolves DNS, performs GeoIP lookups, and runs detailed Nmap scans. It also identifies known vulnerabilities based on discovered services, helping users assess and secure their networks effectively.
- hwatlib: A practical pentesting and exploitation python library with wrappers for recon, web enumeration, reverse shells, and privilege escalation.
- Blockchain Implementation: Developed a Java-based blockchain with features like user authentication, transaction tracking, and dynamic coin rate fluctuation. This project was a collaborative effort with Muhammad Munib, [Radeel Ahmed]
Additional Experiences#
- Student Advisor at Air University Cyber Security Society (Feb 2026 - July 2026)
- Technical Secretary at Air University Cyber Security Society (Dec 2024 - Feb 2026)
- Director Developer at AirTech'25 CTF (May 2025)
- CTF Challenge Developer at Air University Cyber Security Society (Dec 2023 - Dec 2024)
- Member - Cyber Research Club at Air University Cyber Security Society (Feb 2024 - Dec 2024)
- Core Member - Awareness Club at Air University Cyber Security Society (Jan 2023 - June 2023)
Contact Me#
- Email:
muhammadabdullah8040@gmail.com - Twitter: @iabdullah_215
- LinkedIn: Muhammad Abdullah
- GitHub: iabdullah215
- Discord:
n0tabdu11ah
