AOUN SHAH

Cyber Security Expert
Pakistan, PK.

About

Recently graduated Cyber Security Expert with a Bachelor of Science degree, deeply passionate about identifying vulnerabilities and implementing robust mitigation strategies. Proven ability to conduct comprehensive security testing and analysis, highlighted by the discovery and reporting of CVE-2025-7503 with a critical CVSS score of 10.0. Possesses strong knowledge of operating systems, computer networking, and advanced web penetration testing techniques, ready to contribute immediate value to a dynamic cybersecurity team.

Work

intrusix
|

Website Security Analyst

Summary

Conducted comprehensive security testing and analysis to identify vulnerabilities and enhance the functionality of web applications, ensuring robust user experience and system integrity.

Highlights

Executed comprehensive security testing on website features, identifying critical vulnerabilities and ensuring robust functionality across the platform.

Designed and proposed an enhanced user interface prototype, contributing to improved user experience and potential security-driven design improvements.

Education

Sir Syed CASE Institute of Technology
Islamabad, Pakistan

Bachelor of Science

Cyber Security

Courses

Ethical Hacking

Digital Forensics

Vulnerability Assessment and Reverse Engineering

Cloud Computing Security

Network Security

Introduction to Security for IoT

Certificates

Certified Network Defender (CND)

Issued By

EC-Council

Skills

Programming Languages

Python, JavaScript, Bash Script, Batch Script, SQL, CSS, HTML.

Tools

Burp Suite, Nmap, Wireshark, Metasploit, Autopsy, Procmon, sqlmap, Postman, Ethercap, Binwalk, Wifite.

Technical Skills

Web Penetration Testing, Web Development, Network Security, Digital Forensics, Malware Analysis, VAPT, OWASP TOP 10, Reverse Engineering, Logs Analysis, OSINT, Windows Firewall Configuration, IoT Security.

Operating Systems

Windows, Linux.

Projects

Security Assessment & Penetration Testing of IoT Cameras (FYP)

Summary

Evaluated real-world security risks in IoT surveillance devices, addressing the rapid growth and inherent vulnerabilities that make them easy targets for attackers. This final year project involved in-depth analysis of two common IoT camera devices to identify critical security flaws.

Automated Detection of HTTP Request Smuggling in HTTPS Web Servers

Summary

Developed a robust Python CLI tool designed to automatically detect CL.TE and TE.CL HTTP Request Smuggling attacks over HTTPS, enhancing web server security analysis.

Automatic Malware Static Analysis

Summary

Engineered a Python script for comprehensive static analysis of suspicious files, providing insights into their nature and potential malicious activities.

Secure Journal Web App

Summary

Built a private journaling web application with a strong emphasis on security and user privacy, integrating robust protective measures against common web vulnerabilities.