000

Waqqas H

CTF competitor and security researcher specializing in web exploitation, Active Directory pentesting, and digital forensics. Team leader with a track record across national and international competitions.

Rank 4BEST CTF PLACEMENT
EliteHACK THE BOX STATUS
Oct 2024CTF CAREER START

About

I got into security through capture-the-flag competitions in October 2024, and it turned into a focused track toward penetration testing — web exploitation, Active Directory attack paths, and the forensics work that comes after a breach.

Most of my time goes into three things: breaking web applications through logic flaws and injection classes, chaining Active Directory misconfigurations with Kerberos and BloodHound, and writing up the process so the reasoning is reusable, not just the flag.

I also build my own tooling when the off-the-shelf options don't fit the workflow — a CLI toolkit for CTF and lab setup, and a diagramming tool for mapping attack paths.

LOCATIONHyderabad, India
FOCUSWeb + Active Directory
STATUSElite, Hack The Box
STUDYINGSt Aloysius, 2025–2029
LANGUAGESEnglish, Hindi, Urdu

Technical skills

Core security domains
Web application security (LFI, RCE, SQLi, SSTI), authentication bypass & service misconfiguration, Active Directory & enterprise security, Kerberos / AD CS / BloodHound / GPO abuse, digital forensics & incident response, cryptography & applied cryptanalysis, reverse engineering (static & dynamic)
Analysis & CTF tools
CyberChef, Wireshark, Autopsy, Volatility, Radare2, Ghidra, BloodHound, Impacket suite, custom tooling development
Penetration testing
Burp Suite Professional, Nmap, Gobuster, FFUF, Metasploit Framework, exploit development, network enumeration

Projects

Selected projects spanning browser-based tooling, technical publishing, and CLI automation for repeatable security workflows.

LIVE — Browser diagramming tool

ArcFlow

Browser-based diagramming tool for building clean node-and-edge flow diagrams with custom styling, smart snapping, JSON save/load, and SVG, PNG, or JPG export. Runs entirely in the browser with no backend, no dependencies, and no build step.

DiagrammingWebSVG ExportJSON
ACTIVE — Publishing platform

WaqqasSec Writeup Platform

A dedicated home for long-form CTF writeups and technical breakdowns, giving challenge analysis a cleaner reading surface than a simple profile feed.

WriteupsWebKnowledge Base
ACTIVE AND UPGRADING — CLI toolkit

Waqqas Toolset

Opinionated CLI toolkit for CTF, Hack The Box, lab, and repeatable Linux setup workflows, with commands for project scaffolding, notes, recon wrappers, archive handling, and workflow management.

CLICTFHTBLinux

Competitive achievements

Track record of strong placements in national and international CTF competitions since October 2024.

Rank <30
HackTheBox India
All India ranking on HTB Labs
Rank 4
IIT Bhubaneswar CTF
Best overall team placement to date
Rank 11
FooBar CTF 2025
NIT Durgapur · 64 competing teams
Rank 24
Pragyan CTF 2025
NIT Trichy · 440+ competing teams
Rank 58
Hack The Box Season 9
Global ranking among 9,500+ players
Elite
Hack The Box Status
Top tier ranking achieved

Publications & CTF writeups

Selected writeups and technical posts where I break down CTF challenges, methodologies, and mitigations.

RSTCON 2024 — Escalator

2024

Privilege escalation writeup: found SUID binaries on the host and abused /usr/bin/find with -exec to spawn a root shell and read the flag.

Read writeup

Pearl CTF 2025 — oxmagic

2025

Stego + media repair: extracted a Base64 string from image metadata, used it as a steghide passphrase, repaired a damaged WAV header, and decoded Morse audio to recover the flag.

Read writeup

ACECTF 2025 — Insanity Check

2025

Logic & OSINT: used Discord role metadata and the Discord API to locate a Pastebin entry containing the flag — following breadcrumbs across services.

Read writeup

PatriotCTF 2024 — Really Only Echo

2024

Constrained shell challenge: leveraged /bin/base64 inside an echo-only terminal to retrieve and decode a base64-encoded flag string.

Read writeup

PatriotCTF 2024 — Give me four words, Vasily

2024

Image analysis + geolocation: matched a satellite image, extracted coordinates, then used what3words to produce the location string in the flag.

Read writeup

H7CTF International — No Paste

2024

Client-side bypass: deobfuscated page JS, found a hardcoded submission value blocked by input handlers, then triggered the submit function directly.

Read writeup

HackTheBox — Editor

2026

XWiki RCE → foothold → SSH access → SUID privilege escalation via Netdata. Chained CVE-2025-24893 for RCE and CVE-2024-32019 for a root shell.

Read writeup

HackMD profile — Collection of notes

A hub for all CTF writeups and technical notes — the full set of posts and linked repositories.

Visit profile

Education & career goals

St Aloysius (Deemed To Be University)

2025 – 2029

Currently pursuing a bachelor's degree with a focus on cybersecurity and information security.

International Junior College, Hyderabad

2022 – 2024

Completed senior secondary education with Physics, Chemistry, and Mathematics.

Oasis School, Hyderabad

Up to 2022

Completed secondary education with CBSE.

Develop comprehensive penetration testing and network security expertise through hands-on practice and continued competitive participation.
Pursue a long-term career in cybersecurity and vulnerability research, contributing to enterprise security and open-source security tools.

Languages

EnglishFluent
HindiNative
UrduNative
TeluguBasic

Get in touch

Open to collaboration, research opportunities, and professional networking.

GITHUBw4qq4s
HACKTHEBOXxtasyyy #IN