sana@vapt:~$ whoami

Sana Rehman.

Penetration Tester / VAPT Analyst

RECON → EXPLOIT → VALIDATE → REPORT

Results-driven cybersecurity professional focused on offensive security, vulnerability research, web and API security, Android assessment, red-team operations, and security monitoring.

portfolio@research: ~/security
10+Boot-to-root machines
12+API vulnerabilities identified
8Critical mobile findings mapped
3rdACM SigSAG CTF 2025
§01

About Me

I'm a final-year BS Cybersecurity student with a practical focus on penetration testing, VAPT, vulnerability research, and SOC operations.

My security work spans web applications, APIs, Android applications, vulnerable machines, reverse engineering, and red-team simulations. I approach assessments through reconnaissance, attack-surface mapping, manual validation, controlled exploitation, impact assessment, and professional reporting.

My portfolio is intentionally organized around the work itself: every lab below links directly to its corresponding GitHub folder, so visitors can move from a high-level portfolio summary to the actual methodology, PoC evidence, and remediation guidance.

§02

Featured Security Work

Selected work from my security research portfolio. Each category opens the relevant GitHub repository or project so recruiters and technical reviewers can inspect the underlying work.

0x01 / WEB APPLICATION SECURITY

Web Application VAPT Labs

Hands-on testing across access control, JWT attacks, unrestricted file upload, CORS, XSS, SQL injection, SSRF, CSRF, clickjacking and related web security classes.

Burp SuiteOWASPNmapSQLMap
Open Web Testing Labs →
0x02 / API SECURITY

API Penetration Testing

OWASP API Top 10 testing using Burp Suite and Postman, including BOLA, BFLA, JWT mismanagement, mass assignment and authorization weaknesses.

BOLABFLAJWTPostman
Open API Testing Labs →
0x03 / ANDROID SECURITY

Android Security Assessment

Static and dynamic mobile testing with JADX, Ghidra and Frida, including SSL pinning and root-detection bypass, insecure storage, weak encryption and insufficient obfuscation.

FridaJADXGhidraMobile Top 10
Open Android Labs →
0x04 / RED TEAM & CTF

Red Team & Vulnerable Machines

Boot-to-root exploitation, credential attacks, network sniffing, reconnaissance, social-engineering simulations, privilege escalation and adversarial techniques across lab environments.

LinuxMetasploitPrivilege EscalationCTF
Open Red Team Labs →
0x05 / AUTOMATION

Recon-Master

A custom reconnaissance automation tool designed to streamline information-gathering workflows before web application penetration testing and reduce repetitive manual setup.

BashAutomationReconPentesting
Open Recon-Master →
0x06 / FULL PORTFOLIO

Poc-labs Repository

The central repository containing structured penetration-testing write-ups, methodology, proof-of-concept material and remediation guidance across web, API, Android and red-team labs.

Write-upsPoCMethodologyRemediation
Open Poc-labs Repository →
§04

VAPT Methodology

01Reconnaissance
02Enumeration
03Attack Surface Mapping
04Vulnerability Discovery
05Manual Validation
06Controlled Exploitation
07Impact Assessment
08Reporting & Remediation
§05

Professional Experience

Cybersecurity Intern — InfoSec

BankIslami Pakistan Limited
Jun 2026 — Aug 2026
  • Conducted internal website penetration testing and vulnerability assessments across multiple production servers using OWASP Top 10 methodology.
  • Performed reconnaissance, vulnerability identification and controlled exploitation during scheduled penetration tests on regulated banking assets.
  • Documented technical findings, proof-of-concept evidence and remediation recommendations for engineering and risk stakeholders.
  • Monitored and triaged SOC alerts in Elastic SIEM and correlated logs to detect anomalous activity.
  • Gained exposure to endpoint threat investigation, attack-surface monitoring and network-configuration auditing.

Cybersecurity Intern

National Centre for Cyber Security (NCCS)
Aug 2025 — Dec 2025
  • Contributed to SSU cybersecurity policy documentation as part of an organization-wide security governance initiative.
  • Performed authorized static reverse engineering of the E-Challan Android application using JADX and Ghidra, identifying 5+ structural security weaknesses.
  • Designed and executed LOLBAS-based red-team simulations and documented adversarial techniques to inform policy updates.
§06

Security Toolkit

WEB & API

Burp Suite · Nmap · Nuclei · SQLMap · Nikto · WPScan · Gobuster · Postman

NETWORK & RED TEAM

Wireshark · Metasploit · Hydra · Linux · LOLBAS

MOBILE & RE

Frida · JADX · Ghidra · Binary Ninja · Android Pentesting

SOC & ENTERPRISE

Elastic SIEM · Sirp · Trend Micro Apex One · CTM360 · Nipper ·

§07

Achievements

🏆

3rd Place — ACM SigSAG CTF 2025

Podium finish on a first competitive CTF appearance, competing against 40+ teams across web exploitation, binary exploitation and reverse engineering.

ProCom CTF & CyberScent CTF

Competed in advanced challenges spanning digital forensics, cryptography and application security.

§08

Education & Certifications

BS Cybersecurity — Dawood University of Engineering & Technology, Karachi · Final Year · Expected 2027
Certified Ethical Hacker (CEH) — Corvit
Certified in Cybersecurity (CC) — ISC²
Cybersecurity & Digital Forensics Program — IBA University Karachi
Certified Ethical Bug Bounty Hunter — Bloom Cybersecurity Solutions
Google Cybersecurity Professional Certificate — Google / Coursera
Introduction to CIP — OPSWAT
§09

Contact

Let's Connect_

Interested in penetration testing, vulnerability research, application security, or security collaboration? Let's talk.