╔══════════════════════════════════════════════════════════════════════════════════╗
║ ☠ WARNING — CLASSIFIED OPERATOR FILE — AUTHORIZED PERSONNEL ONLY ☠ ║
╠══════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ ██████╗ ███████╗██╗ ██╗ █████╗ ███╗ ██╗ ███╗ ███╗ ║
║ ██╔══██╗██╔════╝██║ ██║██╔══██╗████╗ ██║ ████╗ ████║ ║
║ ██████╔╝█████╗ ███████║███████║██╔██╗ ██║ ██╔████╔██║ ║
║ ██╔══██╗██╔══╝ ██╔══██║██╔══██║██║╚██╗██║ ██║╚██╔╝██║ ║
║ ██║ ██║███████╗██║ ██║██║ ██║██║ ╚████║ ██║ ╚═╝ ██║ ║
║ ╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ║
║ ║
╠══════════════════════════════════════════════════════════════════════════════════╣
║ [ 0.001337 ] kernel :: offensive_security .............. LOADED [ OK ] ║
║ [ 0.013370 ] module :: zero_day_engine .................. ARMED [ OK ] ║
║ [ 0.133700 ] auth :: REHAN_MALEK :: identity_ok ....... PASS [ OK ] ║
║ [ 1.337000 ] net :: cyrad_radius_module .............. ONLINE [ OK ] ║
║ [ 1.337001 ] ics :: kotori_scada_exploit .............. ARMED [ OK ] ║
║ [ 1.337002 ] hw :: flipper_zero_rf_nfc_rfid ......... LOADED [ OK ] ║
║ [ 1.337003 ] ops :: mission_control ▓▓▓▓▓▓▓▓▓▓▓▓ 100% ONLINE ║
╠══════════════════════════════════════════════════════════════════════════════════╣
║ ● ALL SYSTEMS NOMINAL — HUNTING MODE ACTIVE — TARGET LOCKED ║
╚══════════════════════════════════════════════════════════════════════════════════╝
⚠️ All vulnerabilities disclosed under Coordinated Vulnerability Disclosure (CVD). All research is authorized and ethical.
| 🔴 STATUS | CVE ID | TARGET | CVSS | CLASS | CREDIT |
|---|---|---|---|---|---|
| ⏳ PENDING | CVE-XXXX-XXXXX | Kotori ICS/SCADA | 🔴 CRITICAL | Unauthenticated Telemetry Poisoning | ✅ Confirmed |
╔════════════════════════════════════════════════════════════════════════════════╗
║ ⚠ EXPLOIT CHAIN REPORT — OPERATION KOTORI — EYES ONLY ⚠ ║
╠════════════════════════════════════════════════════════════════════════════════╣
║ ║
║ SYSTEM : Kotori ICS/SCADA Framework (Open-Source OT Monitoring) ║
║ ENDPOINT : Unauthenticated HTTP Route — Zero Auth Required ║
║ TECHNIQUE : Telemetry Data Injection → Sensor Value Falsification ║
║ IMPACT : Critical Infrastructure Disruption / False Sensor Readings ║
║ REACH : All internet-exposed Kotori instances pre-patch ║
║ METHOD : Coordinated Vulnerability Disclosure (CVD) — Ethical ║
║ STATUS : ✅ Contributor Credit Confirmed by Maintainer ║
║ CVE : Pending NVD Assignment ║
║ ║
║ CHAIN: Unauth HTTP ──► Inject Telemetry ──► Falsify Sensors ║
║ ──► Trigger False Alarms ──► Disrupt Critical Infrastructure ║
║ ║
╚════════════════════════════════════════════════════════════════════════════════╝
┌─────────────────────────────┐
│ ╔═══════════════════════╗ │
│ ║ ◉ TARGET ACQUIRED ║ │
│ ║ REHAN MALEK ║ │
│ ║ OPERATOR :: R3H4N ║ │
│ ╚═══════════╤═══════════╝ │
└──────────────┼───────────────┘
┌──────────────┬──────────┴──────┬──────────────┐
▼ ▼ ▼ ▼
┌────────────┐ ┌─────────────┐ ┌──────────────┐ ┌──────────────┐
│ 🌐 WEB APP │ │ 📡 HARDWARE │ │ 🏭 ICS / OT │ │ 🔐 NET/AUTH │
│────────────│ │─────────────│ │──────────────│ │──────────────│
│ OWASP Top10│ │ Flipper Zero│ │ Modbus/DNP3 │ │ RADIUS / AAA │
│ SQLi / RCE │ │ RF Replay │ │ Telemetry Inj│ │ MITM / Deauth│
│ Auth Bypass│ │ NFC Cloning │ │ PLC Exploit │ │ Session Hijack│
│ SSRF / XXE │ │ RFID Spoof │ │ Kotori SCADA │ │ Cred Harvest │
│ LFI / IDOR │ │ BadUSB / HID│ │ OT Recon │ │ Wi-Fi Attacks│
└────────────┘ └─────────────┘ └──────────────┘ └──────────────┘
KILL CHAIN:
┌────────┐ ┌───────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌────────┐
│ RECON │─►│ WEAPONIZE │─►│ DELIVER │─►│ EXPLOIT │─►│ PERSIST │─►│ EXFIL │
│ OSINT │ │ Zero-Day │ │ Social │ │ Auth Byp.│ │ Backdoor │ │ C2 Ops │
│ Nmap │ │ HW Implant│ │ Phishing │ │ SCADA/OT │ │ RADIUS │ │ Loot │
│ Shodan │ │ Exploits │ │ Delivery │ │ ICS/PLC │ │ Persist │ │ Drain │
└────────┘ └───────────┘ └──────────┘ └──────────┘ └──────────┘ └────────┘
🔴 OPERATION : DROID BYPASS | Android Security | Root Lock Screen Circumvention
╔═══════════════════════════════════════════════════════════════════╗
║ OP_ID : DROID-BYPASS-001 CLASSIF : RESEARCH ONLY ║
╠═══════════════════════════════════════════════════════════════════╣
║ TARGET : Rooted Android Devices — All Versions ║
║ VECTOR : Root Shell → Privilege Escalation ║
║ METHOD : Scripted Lock Screen Bypass (Full PoC + Docs) ║
║ IMPACT : Full Device Access Without PIN / Bio / Pattern ║
║ STATUS : Demonstrated — Security Model Invalidated ║
╚═══════════════════════════════════════════════════════════════════╝
Root access completely invalidates Android's lockscreen security model. Script demonstrates full device takeover with zero authentication. Includes PoC & technical writeup.
🔴 OPERATION : CYRAD DEPLOY | Network Auth / AAA | Enterprise RADIUS System
╔═══════════════════════════════════════════════════════════════════╗
║ OP_ID : CYRAD-002 CLASSIF : CLIENT PROJECT ║
╠═══════════════════════════════════════════════════════════════════╣
║ BUILD : Designed & architected from zero ║
║ FEAT 1 : Per-user data quota enforcement (real-time) ║
║ FEAT 2 : Live session monitoring + AAA full stack ║
║ FEAT 3 : Admin dashboard + dynamic access policy engine ║
║ CLIENT : Cyndia Cyberspace LLP ║
║ RESULT : ✅ Letter of Recommendation Awarded ║
╚═══════════════════════════════════════════════════════════════════╝
Enterprise-grade AAA platform built from scratch — Authentication, Authorization & Accounting with per-user quota enforcement and live session management.
🔴 OPERATION : UNMASK | OSINT / Recon | Origin IP Discovery Behind CDN
╔═══════════════════════════════════════════════════════════════════╗
║ OP_ID : UNMASK-003 CLASSIF : PEN TEST TOOLS ║
╠═══════════════════════════════════════════════════════════════════╣
║ TARGET : CDN-shielded Web Applications ║
║ TECH : True-origin IP discovery — Cloudflare bypass ║
║ METHOD : Multi-vector passive recon + DNS enumeration ║
║ IMPACT : Direct origin attack — bypasses WAF / CDN layer ║
║ PHASE : Reconnaissance — pre-exploitation ║
╚═══════════════════════════════════════════════════════════════════╝
Automates uncovering the real origin server behind CDN/Cloudflare. Used to neutralize WAF protections and target the exposed origin directly during pen tests.
🔴 OPERATION : HARDWARE KRAKEN | Hardware / Red Team | Flipper Zero 5-in-1 PCB
╔═══════════════════════════════════════════════════════════════════╗
║ OP_ID : HW-KRAKEN-004 CLASSIF : RED TEAM HW ║
╠═══════════════════════════════════════════════════════════════════╣
║ HW : Custom Flipper Zero 5-in-1 PCB Extension Board ║
║ CAP 1 : RF Replay + Sub-GHz frequency attack surface ║
║ CAP 2 : NFC emulation + full RFID cloning / spoofing ║
║ CAP 3 : Physical bypass modules + BadUSB HID injection ║
║ USE : Red team physical security assessments ║
║ STATUS : Designed, built, assembled & field-tested ✅ ║
╚═══════════════════════════════════════════════════════════════════╝
Custom PCB expanding Flipper Zero's attack surface for red team ops — RF, NFC, RFID, and physical bypass all on one hardware platform.
╔══════════════════════════════════════════════════════════════════════════════╗
║ ASSIGNMENT-001 │ KUBOTOR — Bug Bounty Hunter (Intern) ║
║ TIMELINE │ Sep 2025 → Jan 2026 ║
╠══════════════════════════════════════════════════════════════════════════════╣
║ ► Structured penetration tests executed across multiple live targets ║
║ ► Vulnerability chains assembled into critical-impact proof-of-concepts ║
║ ► Responsible disclosure pipeline — full exploit documentation delivered ║
╚══════════════════════════════════════════════════════════════════════════════╝
╔══════════════════════════════════════════════════════════════════════════════╗
║ ASSIGNMENT-002 │ CYNDIA CYBERSPACE LLP — Security Analyst (Intern) ║
║ TIMELINE │ May 2025 → Jul 2025 ║
╠══════════════════════════════════════════════════════════════════════════════╣
║ ► Architected CYRAD — enterprise RADIUS authentication system from zero ║
║ ► Per-user quota enforcement + real-time live session monitoring (AAA) ║
║ ► 🏅 Awarded Letter of Recommendation for exceptional delivery ║
╚══════════════════════════════════════════════════════════════════════════════╝
| ⚡ DOMAIN | 🛠️ STACK | 🔴 THREAT RATING |
|---|---|---|
| 🌐 Web App Pentesting | Burp Suite · OWASP Top-10 · SQLi | ████████████ ADVANCED |
| 🏭 ICS / SCADA Security | Kotori · Modbus · OT Networks | ██████████░░ ADVANCED |
| 🔐 Network & Auth | RADIUS · AAA · MITM · Wi-Fi | ████████████ ADVANCED |
| 📡 Hardware Hacking | Flipper Zero · RF · NFC · RFID | █████████░░░ PROFICIENT |
| 🔎 OSINT & Recon | Shodan · Nmap · DNS · Passive | ████████████ ADVANCED |
| 🐍 Exploit Scripting | Python · Bash · Automation | █████████░░░ PROFICIENT |
| 💾 Digital Forensics | Evidence · Analysis · Imaging | ███████░░░░░ INTERMEDIATE |
| 🚩 CTF Operations | Web · Pwn · Crypto · Misc | ████████░░░░ PROFICIENT |
| 🔐 CERTIFICATION | 🏛️ ISSUER | 🎯 DOMAIN | 🔰 |
|---|---|---|---|
| Cyber Security & Privacy | NPTEL | Offensive & Defensive SecOps | ✅ |
| Computer Networks & Internet Protocol | NPTEL | Network Architecture | ✅ |
| SQL Injection Attack | EC-COUNCIL | Web Application Exploitation | ✅ |
| PHP & MySQL | IIT Bombay | Backend & Database Development | ✅ |
| H4CKP13T 0X01 | International CTF | Capture The Flag Competition | ✅ |
| PHANTOM FLAB | CTF Event | Capture The Flag Competition | ✅ |
╔════════════════════════════════════════════════════════════════════╗
║ ⚡ AVAILABLE FOR THE FOLLOWING ENGAGEMENTS ⚡ ║
╠════════════════════════════════════════════════════════════════════╣
║ ✅ Freelance Penetration Testing & Vulnerability Assessments ║
║ ✅ Bug Bounty Collaborations & Joint Research Programs ║
║ ✅ Full-Time Offensive Security / Red Team Roles ║
║ ✅ Security Research Internships ║
║ ✅ CVE Research, Coordination & Responsible Disclosure ║
║ ✅ Hardware Hacking & Physical Security Red Team Operations ║
╚════════════════════════════════════════════════════════════════════╝

