CYBER SHADOW
Web platform developed for Cyber Shadow to present the organization's cybersecurity services, assessment inquiry workflows, and technical resources.

I build web applications and security automation tools. My work combines full-stack development, application security testing, and custom tooling using technologies such as Go and Python.

Web platform developed for Cyber Shadow to present the organization's cybersecurity services, assessment inquiry workflows, and technical resources.

Go-based command-line tool for Linux that automates subdomain discovery, HTTP probing, crawling, and endpoint categorization into a repeatable reconnaissance workflow.
Open-source Go CLI tool for automated search-engine dorking, parsing query operators and extracting clean, deduplicated target URLs for reconnaissance.
Web platform developed for Barishal Information Technology College, providing academic notices, department details, admission guidance, and responsive access for students and faculty.

Social-impact web platform developed to help people find voluntary blood donors across Bangladesh by filtering by blood group and district.

Sanitized case study from a cloud SaaS environment. Focused on deep authorization testing, tenant isolation, and API access-control logic where automated scanners commonly fail.
I work across application development, security assessment, and custom tooling automation. Balancing development and security helps me understand how applications are assembled from the ground up—and how access controls, business logic, and implementation oversights can be compromised.
My goal is straightforward: build reliable, accessible software and write focused security tools that make workflows simpler and safer.
Web applications and platforms built with Next.js, React, and TypeScript, focused on clean architecture, responsive usability, and solid fundamentals.
Vulnerability assessments and testing focused on business logic flaws, OWASP Top 10 risks, authentication, and authorization vulnerabilities.
Command-line tools and pipelines written in Go and Python to automate reconnaissance, URL filtering, and repetitive security workflows.
RESTful API design, database schemas, and server-side integrations built with security considerations like input validation, rate limiting, and access controls.
Have a product to build, an application to secure, or a security inquiry? Send a confidential message directly through the portal below.