Skip to main content
Get in Touch
AVAILABLE FOR ENGAGEMENTS

KhubabAhmed

PENETRATION TESTER

PNPT and PJPT certified penetration tester with a BS in Cyber Security and deep expertise in Windows internals, privilege escalation, Active Directory attacks, and malware development. I find the paths attackers exploit before they do.

TYPICAL RESPONSE: < 24 HOURS
PNPT · PJPT CERTIFIED
khubab@pentest:~$bash
$
0+
Years Experience
0+
Certifications
0+
Assessments Done
0+
Security Tools Built
VERIFIED WORK

Proof, Not Percentages

Anyone can claim a skill level. These are externally validated results from the last twelve months.

CERTIFICATIONAug 2026

PNPT passed on a full engagement exam

Five days of external and internal network testing including Active Directory compromise, followed by two days of report writing and a live debrief with the assessor. Graded on methodology and reporting, not multiple choice.

TCM SecurityActive DirectoryReporting
CRITICAL FINDINGJun 2026

CVSS 10.0 accepted on YesWeHack

Found a ZipSlip path traversal in a Node.js plugin marketplace, chained it into remote code execution by writing outside the extraction directory, and reported it. Accepted as Critical at the maximum severity score.

ZipSlipRCENode.jsCVSS 10.0
HANDS-ON PRACTICESeason 11

Three Hack The Box machines rooted

Reactor, DevHub, and Connected. DevHub chained an unauthenticated RCE in an exposed developer tool through SSRF and a leaked Jupyter token to reach root, mirroring how real estates fall.

Hack The BoxSSRFPrivEscChaining
START HERE

What Brought You Here?

Find the situation that matches yours. Each one has a defined response, a realistic timeline, and a clear first step.

We think we have been breached

IMMEDIATE

WHAT YOU ARE SEEING

Unexplained logins, ransom notes, data appearing where it should not, alerts nobody can explain.

WHAT I DO

Incident triage and DFIR. Evidence preserved first, then memory and disk acquisition, timeline reconstruction, and a report establishing what happened and how far it reached.

Discuss This

A client or auditor is asking for a pentest report

1 TO 4 WEEKS

WHAT YOU ARE SEEING

Vendor due diligence, an ISO 27001 or SOC 2 cycle, or a contract that will not close without one.

WHAT I DO

Full-scope penetration test with a report built for both audiences: an executive summary the auditor reads, and CVSS-scored technical detail your engineers act on.

Discuss This

We are about to launch and nobody has tested it

1 TO 2 WEEKS

WHAT YOU ARE SEEING

A new application, API, or infrastructure going live with no independent security review behind it.

WHAT I DO

Pre-launch web application and API assessment against the OWASP Top 10, with findings prioritised so the blocking issues get fixed before release.

Discuss This

We found a suspicious file or process

3 TO 7 DAYS

WHAT YOU ARE SEEING

An unknown binary, a flagged executable, or a process behaving in a way nobody can account for.

WHAT I DO

Static and dynamic malware analysis to determine capability and intent, with extracted IOCs and YARA rules you can feed straight into detection.

Discuss This

We do not actually know what we are exposed to

1 TO 2 WEEKS

WHAT YOU ARE SEEING

No recent testing, unclear asset inventory, and no confident answer to what is reachable from the internet.

WHAT I DO

Attack surface mapping and vulnerability assessment, combining automated scanning with manual verification so you get a real risk picture rather than scanner noise.

Discuss This

We want to know if our defences actually work

2 TO 6 WEEKS

WHAT YOU ARE SEEING

Security controls and monitoring are in place, but they have never been tested against a real adversary.

WHAT I DO

Red team engagement simulating a genuine attacker from phishing through to objective, mapped to MITRE ATT&CK so you learn exactly what your telemetry missed.

Discuss This

Not sure which applies? Describe the situation and I will tell you what it needs.

Describe Your Situation
UNIQUE VALUE

Why Work With Me

Three things that separate this profile from every other “cybersecurity specialist” on your list.

PNPT + PJPT

Practically Certified, Twice Over

Passed TCM Security's PNPT in August 2026 after earning the PJPT in December 2025. The PNPT is a five day full-scope engagement plus two days of reporting and a live client debrief, not a multiple-choice exam.

External and internal network penetration
Active Directory compromise chain
Professional report and live debrief
DUAL DOMAIN

Offensive + Forensics Depth

A rare combination of attacker and investigator perspective. I build malware and analyse it, run penetration tests and respond to incidents. That dual lens surfaces what single-domain testers routinely miss.

Windows malware development (C/C++)
DFIR investigations and memory forensics
Reverse engineering malicious binaries
QUALIFIED

BS in Cyber Security, MS in Progress

BS in Cyber Security from FAST-NUCES, one of Pakistan's top computing institutions, now reading for an MS in Cyber Security at Air University. Formal grounding behind every practical finding.

BS Cyber Security, FAST-NUCES (2021 to 2025)
MS Cyber Security, Air University (ongoing)
Instructor and TA in the same discipline
PROFICIENCY

Technical Skills

Validated through certifications, real engagements, CTF competitions, and continuous lab practice.

Penetration Testing90%
Windows Privilege Escalation85%
Active Directory Attacks80%
Web App Security82%
Malware Analysis80%
Reverse Engineering72%

TOOL ARSENAL

Kali LinuxBurp SuiteMetasploitWiresharkIDA ProGhidraVolatilityAutopsyC/C++PythonPowerShellx64dbgNmapBloodHoundRubeusMimikatzCrackMapExecWinPEASPowerUpImpacketNucleiSQLMapYARASysinternals
SERVICES

What I Offer

Specialised offensive and defensive security services, from initial foothold to full forensic investigation.

Explore Services
PROJECTS

Featured Work

Security tools, forensic utilities, and research projects built from scratch to solve real problems.

Nether's Gate

PRIVATE

Custom C/C++ shellcode loader implementing AES/RC4 payload encryption, process injection, and sandbox evasion for red team engagements.

C++ShellcodeEvasion

SUMCESA

Cyber Essentials compliance automation that correlates installed software against NVD/CVE databases and generates CVSS-scored PDF reports.

PythonFlaskCVE
View Source

Windows Write Blocker

Registry-level forensic write-blocker for Windows that preserves evidence integrity during acquisition with chain-of-custody CSV logging.

PythonForensicsDFIR
View Source
All 7 Projects
STRUCTURED TRAINING

Featured Courses

52+ weeks of rigorous structured training covering every layer of offensive security and digital forensics.

All 4 Courses
COMMON QUESTIONS

Frequently Asked

Straight answers on credentials, scope, and how engagements actually run.

Khubab Ahmed is a penetration tester and security researcher based in Islamabad, Pakistan. He holds the PNPT (Practical Network Penetration Tester) and PJPT certifications from TCM Security, along with a BS in Cyber Security from FAST-NUCES. He works as a VAPT Engineer at SNSKIES and teaches Digital Forensics and Cybersecurity as an Instructor at FAST-NUCES.

He holds over 21 certifications. The most significant are the PNPT (Practical Network Penetration Tester, TCM Security, August 2026) and the PJPT (Practical Junior Penetration Tester, TCM Security, December 2025). Others include the External Pentest Playbook, OSINT Fundamentals, Windows and Linux Privilege Escalation from TCM Security, advanced digital forensics certifications from Belkasoft, Junior Penetration Tester from TryHackMe, and Microsoft Certified Azure Fundamentals.

He holds a BS in Cyber Security from FAST-NUCES (National University of Computer and Emerging Sciences), completed between 2021 and 2025, and is currently reading for an MS in Cyber Security at Air University. This formal education sits alongside practical certifications including the PNPT and PJPT.

He offers penetration testing across networks, web applications and Active Directory, red team operations and adversary simulation, vulnerability assessment with CVSS-scored reporting, malware analysis and reverse engineering, digital forensics and incident response, and original security research. Engagements typically run from one to six weeks depending on scope.

The PNPT (Practical Network Penetration Tester) from TCM Security is a fully hands-on certification. The exam gives five days to perform a complete external and internal network penetration test including Active Directory exploitation, then two days to produce a professional client-facing report, followed by a live debrief. It assesses real engagement methodology rather than multiple-choice knowledge.

You can reach him through the contact form on this site, by email at contact@khubabahmed.com, or via LinkedIn at linkedin.com/in/khubabbahmed. Every engagement starts with a scoping conversation to define objectives, rules of engagement, in-scope targets, and success criteria before any testing begins.

Engagements follow a four-stage process. Scoping defines objectives, rules of engagement and in-scope targets. Reconnaissance covers passive OSINT and active enumeration to map the attack surface. Exploitation involves controlled, evidence-based exploitation to measure real-world impact. Reporting delivers CVSS-scored findings, proof-of-concept evidence, an executive summary, and a prioritised remediation roadmap. The approach aligns with PTES and OWASP standards.

Preserve evidence before you clean anything up. Do not wipe or rebuild affected machines, because that destroys the forensic artefacts needed to establish what happened and how far the attacker reached. Isolate affected systems from the network rather than powering them off, since shutting down loses volatile memory. Then capture memory and disk images, rotate credentials from a known-clean device, and begin timeline reconstruction. Khubab Ahmed provides DFIR support covering incident triage, memory and disk acquisition, timeline reconstruction, and a court-ready investigation report.

A vulnerability assessment identifies and catalogues weaknesses, usually with automated scanning plus manual verification, and tells you what could theoretically be exploited. A penetration test goes further by actually exploiting those weaknesses in a controlled way to prove real-world impact, chaining findings together to show how far an attacker could genuinely reach. An assessment answers what is wrong. A penetration test answers what an attacker could actually do about it. Khubab Ahmed offers both, and the right choice depends on whether you need coverage or proof.

Timelines depend on scope. A vulnerability assessment typically runs one to two weeks, a penetration test one to four weeks, and a full red team engagement two to six weeks. Malware analysis is usually three to seven days, and incident response begins immediately. Cost scales with the number of in-scope targets, the depth of testing, and whether a re-test is included. Every engagement starts with a free scoping conversation that produces a fixed quote before any work begins, so there are no open-ended bills.

Most security frameworks either require or strongly expect independent testing. ISO 27001, SOC 2, PCI DSS, and Cyber Essentials Plus all involve some form of technical verification, and clients increasingly ask for a recent pentest report during vendor due diligence. Reports are written with two audiences in mind: an executive summary an auditor or client can read directly, and technical detail with CVSS scoring and proof-of-concept evidence your engineers can act on.

Yes, all three, and testing them together usually reveals more than testing them in isolation. A foothold in a web application often becomes a route into the internal network, and from there into Active Directory. Khubab Ahmed is PNPT certified specifically in full-scope external and internal network testing with Active Directory exploitation, and holds separate credentials in Windows and Linux privilege escalation.

Yes. Khubab Ahmed is based in Islamabad, Pakistan, and works with clients worldwide. Penetration testing, vulnerability assessment, malware analysis, and security research are all delivered remotely as standard. Scoping calls and debriefs are scheduled to suit your timezone, and reporting and communication are in English.

CURRENTLY AVAILABLE

Ready to Test Your Defences?

Penetration test, red team engagement, malware analysis, or forensic investigation. Let's define the scope and start finding what needs fixing before attackers do.