Active Threat Hunting & Consulting

Defending Systems.
Exploiting Flaws.

I specialize in offensive security, infrastructure hardening, and automated threat detection—helping organizations fortify their digital perimeters before attackers strike.

OSCP & CISSP
Red & Blue Teaming
Zero Trust Arch
root@sec-ops:~ SECURE
Jawad@zawadabu:~$ nmap -sV -sC -p- target.domain.internal
Starting Nmap 7.94 ( https://nmap.org ) at 2026-03-29 10:14 UTC
Nmap scan report for target.domain.internal (10.0.42.15)
Host is up (0.012s latency).
22/tcp open ssh OpenSSH 8.9p1
80/tcp open http nginx 1.18.0
443/tcp open ssl/http Cloudflare Proxy
8080/tcp open http-proxy (VULNERABLE: CVE-2024-XXXX)
jawad@zawadabu:~$ ./audit_siem_logs.py --status
[✓] Firewall: Active (0 Rules Breached)
[✓] SIEM Integration: Splunk Operational
[!] Threat Matrix: 0 Critical, 0 High Vulnerabilities Active
Jawad@zawadabu:~$
Kali Linux Burp Suite Pro Wireshark Metasploit Splunk SIEM Python & Bash Docker & Kubernetes AWS Security Architecture CrowdStrike Falcon Kali Linux Burp Suite Pro Wireshark Metasploit Splunk SIEM

Core Expertise

Security Engineering &
Offensive Defense

Comprehensive security assessments, infrastructure hardening, and rapid incident mitigation designed for modern enterprise tech stacks.

Penetration Testing

Black-box and white-box security audits on web apps, APIs, and cloud infrastructure to identify zero-days and vulnerabilities.

  • OWASP Top 10 Audit
  • API & Microservice PenTesting
  • Exploit PoC & Remediation

SOC & Incident Response

Real-time threat monitoring, SIEM log aggregation (Splunk/ELK), malware analysis, and active intrusion containment.

  • Log Analysis & Threat Hunting
  • Automated Alert Rules
  • Post-Breach Forensics

Cloud Hardening & Zero Trust

Architecting secure AWS/Azure container environments with strict IAM roles, encryption standards, and least-privilege policies.

  • AWS / Kubernetes Security
  • IAM & CIS Benchmarking
  • CI/CD Pipeline DevSecOps

Case Studies

Featured Security Projects

Web Application Penetration Test
Penetration Test Financial Platform

FinTech Web Application Pentest

Identified 12 vulnerabilities (including SQLi & Broken Auth) and delivered full remediation pipeline.

2026
SIEM Threat Intelligence
SOC / Threat Intel Splunk + Python

Automated Threat Detection SIEM Engine

Built custom Splunk parser & Python alert bot reducing mean response time (MTTR) by 65%.

2026
Cloud Infrastructure Security
Cloud Infrastructure AWS EKS & IAM

AWS Kubernetes Zero-Trust Infrastructure Migration

Hardened multi-region EKS cluster with least-privilege IAM policies, automated CIS compliance scanning, and microservice mesh encryption.

Let's secure
your infrastructure.

Need a security audit, penetration test, or incident responder? Send details regarding your scope and timeline.

Secure Email (PGP Available)

zawad.abu@protonmail.com

Location / Availability

Global Remote & Emergency On-Call

0/300