I build the detection that catches the intrusion — then run the intrusion to prove the detection holds.
I defend infrastructure, and break into it
to make the defence stronger.
I'm Abdul Rafay Sadiq, a BS Cyber Security undergraduate at Air University Multan. I work both sides of the wire: building defences and then attacking them to find out exactly where they fail.
On the blue side, I build detection pipelines with SIEM, IDS/IPS and file-integrity monitoring, and handle the forensics when an alert fires. On the red side, I run enumeration, exploitation and privilege escalation inside isolated labs so the defenders know precisely what to watch for.
My focus is threat analysis, network monitoring, and security automation, applied to real-world infrastructure, not just theory.
Monitoring, detection & response
Enumeration, exploitation & escalation
Analysis & threat intelligence
Tooling & secure development
Segmented a hardened lab perimeter and wired real-time intrusion detection into centralised monitoring.
Simulated APT behaviour in an isolated AD forest and escalated from foothold to domain administrator.
Intercepted and manipulated traffic to find and exploit critical OWASP Top 10 flaws, then wrote the fixes.
Hunted Indicators of Compromise across packet captures and memory, then contained the malicious channel.
Detected unauthorised file changes in real time and automated the triage-to-response workflow.
Ran a full-lifecycle assessment on a 36k-line Flask app with 11 tools and remediated 70+ vulnerabilities.
Gathered OSINT, authored IOCs, and mapped adversary tradecraft to industry frameworks.
Stood up a hardened AWS environment with cloud-native IDS and an automated alerting pipeline.