Waqqas H
CTF competitor and security researcher specializing in web exploitation, Active Directory pentesting, and digital forensics. Team leader with a track record across national and international competitions.
About
I got into security through capture-the-flag competitions in October 2024, and it turned into a focused track toward penetration testing — web exploitation, Active Directory attack paths, and the forensics work that comes after a breach.
Most of my time goes into three things: breaking web applications through logic flaws and injection classes, chaining Active Directory misconfigurations with Kerberos and BloodHound, and writing up the process so the reasoning is reusable, not just the flag.
I also build my own tooling when the off-the-shelf options don't fit the workflow — a CLI toolkit for CTF and lab setup, and a diagramming tool for mapping attack paths.
Technical skills
Projects
Selected projects spanning browser-based tooling, technical publishing, and CLI automation for repeatable security workflows.
ArcFlow
Browser-based diagramming tool for building clean node-and-edge flow diagrams with custom styling, smart snapping, JSON save/load, and SVG, PNG, or JPG export. Runs entirely in the browser with no backend, no dependencies, and no build step.
WaqqasSec Writeup Platform
A dedicated home for long-form CTF writeups and technical breakdowns, giving challenge analysis a cleaner reading surface than a simple profile feed.
Waqqas Toolset
Opinionated CLI toolkit for CTF, Hack The Box, lab, and repeatable Linux setup workflows, with commands for project scaffolding, notes, recon wrappers, archive handling, and workflow management.
Competitive achievements
Track record of strong placements in national and international CTF competitions since October 2024.
Publications & CTF writeups
Selected writeups and technical posts where I break down CTF challenges, methodologies, and mitigations.
RSTCON 2024 — Escalator
2024Privilege escalation writeup: found SUID binaries on the host and abused /usr/bin/find with -exec to spawn a root shell and read the flag.
Read writeupPearl CTF 2025 — oxmagic
2025Stego + media repair: extracted a Base64 string from image metadata, used it as a steghide passphrase, repaired a damaged WAV header, and decoded Morse audio to recover the flag.
Read writeupACECTF 2025 — Insanity Check
2025Logic & OSINT: used Discord role metadata and the Discord API to locate a Pastebin entry containing the flag — following breadcrumbs across services.
Read writeupPatriotCTF 2024 — Really Only Echo
2024Constrained shell challenge: leveraged /bin/base64 inside an echo-only terminal to retrieve and decode a base64-encoded flag string.
Read writeupPatriotCTF 2024 — Give me four words, Vasily
2024Image analysis + geolocation: matched a satellite image, extracted coordinates, then used what3words to produce the location string in the flag.
Read writeupH7CTF International — No Paste
2024Client-side bypass: deobfuscated page JS, found a hardcoded submission value blocked by input handlers, then triggered the submit function directly.
Read writeupHackTheBox — Editor
2026XWiki RCE → foothold → SSH access → SUID privilege escalation via Netdata. Chained CVE-2025-24893 for RCE and CVE-2024-32019 for a root shell.
Read writeupHackMD profile — Collection of notes
—A hub for all CTF writeups and technical notes — the full set of posts and linked repositories.
Visit profileEducation & career goals
St Aloysius (Deemed To Be University)
Currently pursuing a bachelor's degree with a focus on cybersecurity and information security.
International Junior College, Hyderabad
Completed senior secondary education with Physics, Chemistry, and Mathematics.
Oasis School, Hyderabad
Completed secondary education with CBSE.
Languages
Get in touch
Open to collaboration, research opportunities, and professional networking.