CEH V12 · GCHQ-Accredited MSc Cyber Security · Targeting Penetration Testing & Red Team
Turning 4 years of enterprise infrastructure knowledge into offensive security expertise — finding the gaps before adversaries do.
I am a CEH-certified ethical hacker with a GCHQ-accredited MSc in Applied Cyber Security, making a deliberate move into offensive security from a foundation in enterprise IT — Active Directory, endpoint hardening, network operations, and incident investigation. That background gives me an attacker's instinct for where real systems break: misconfigurations, weak identity boundaries, and overlooked integrations.
My career began in enterprise IT and network operations — configuring and hardening 250+ devices, managing Active Directory and endpoint compliance, and running incident investigations across complex Windows environments. At Eurostop I now own data integrity and conduct security assessments across enterprise EPOS platforms, middleware, a cloud POS, and internal integrations, applying root-cause analysis and operational-security thinking at scale. The thread through all of it is the same instinct that drives good penetration testing: trace the data, find the anomaly, secure the boundary.
Academically, my research is offensive in nature — my MSc dissertation weaponised Generative Adversarial Networks against hardware Physical Unclonable Functions. Outside work I am continuously hands-on: completing TryHackMe pentest paths, working live HackTheBox machines, and building toward the eJPT and OSCP, with red team operations and the CRTO as the long-term target. I am based in London and open to junior penetration testing and security analyst roles across the UK.
Years managing LAN/WAN, Active Directory, and middleware gave me direct insight into the misconfigurations attackers exploit first.
MSc dissertation on Machine Learning Attacks on Physical Unclonable Functions — demonstrating threat research capability at hardware and cryptographic levels.
Actively practising manual exploit identification, network reconnaissance, and vulnerability assessment through TryHackMe Junior Pentest Path and HackTheBox.
Primary technical escalation point for enterprise EPOS and retail systems, overseeing secure data flows across in-store tills, middleware, head-office platforms, and third-party integrations.
Delivered enterprise-grade IT support for VIP executive clients, managing the full hardware and software lifecycle with a focus on security-hardened configurations.
Provided Tier 1–2 support for BT Broadband products, exceeding performance benchmarks through technical precision and cyber-awareness education.
Led network infrastructure operations for a large enterprise, delivering measurable security and efficiency improvements across 250+ devices.
Active CTF competitor building offensive skills across enumeration, exploitation, and privilege escalation. Currently active on the Junior Penetration Testing path on TryHackMe.
MSc dissertation weaponising GANs against PUF-based hardware authentication. Synthesised challenge-response pairs to train ML attack models against hardware security mechanisms.
Researched Honey Encryption returning fake plausible plaintext on incorrect decryption, blinding brute-force attacks. Proposed a developer API for real-world integration.
Forensic investigation into deleted file recovery using MFT analysis, slack space, disk imaging, and CLI tools. Applicable to cybercrime investigation and incident response.
Research into automated self-defence for enterprise networks — integrating IDS/IPS detection with an Intrusion Response System (IRS) that delivers pre-configured active and passive countermeasures to contain attackers and restore system health.
A client-side cybersecurity utilities toolkit — encoding/decoding, hashing, JWT/AES/RSA tools, a CyberChef-style recipe chainer, and OSINT lookups. Nothing ever leaves the browser except a few clearly-disclosed public API calls.
A fast, fully client-side knowledge base for 248 cybersecurity notes — cloud, GRC, OSCP, and red-team — with an Obsidian-style reader: instant full-text search, a command palette, wiki-style cross-links, an interactive link graph, and backlinks. No backend, nothing leaves the browser.
UK job aggregator that filters listings by visa sponsorship status and security clearance requirements — built for candidates who need to know eligibility before they apply. Resume parsing powered by Claude AI.
A project management dashboard for tracking tasks, milestones, and team progress. Built as a single-page app with a clean kanban-style interface.
Comprehensive personal finance tracker for NRI/UK professionals. Tracks income, expenses, investments, debts, and goals across GBP and INR. Includes ROAI analytics, envelope budgeting, bill calendar, SMS transaction parsing, and OLED dark mode.
Documented security research — vulnerability analysis, exploitation methodology, and remediation.
Exploited a format string vulnerability (CWE-134) in printf() to leak a flag from stack memory — no buffer overflow needed.
Exploited a stack buffer overflow (CWE-121) via gets() to overwrite an adjacent stack variable and bypass authentication.
Built a custom Python script to enumerate valid usernames via differential error messages and solve math-based CAPTCHAs programmatically.
Exploited CVE-2019-9053 (time-based blind SQLi, CVSSv3 9.8) in CMS Made Simple to extract credentials, then escalated to root via vim sudo misconfiguration.
Retrieved credentials via information disclosure in HTML comments and robots.txt, then achieved RCE and root escalation through a misconfigured sudo policy.
Queen's University Belfast
GCHQ-accredited. Modules: Network Security & Monitoring, Malware Analysis, Software Assurance, Computer Forensics, Applied Cryptography. Dissertation: ML Attacks on PUFs.
Pillai College of Arts, Commerce & Sciences
Core modules in network technologies, routing protocols, Cisco infrastructure, and network security. Python specialisation.
Pre Security (SEC0)
Exam
TryHackMe Pre Security certification
Ruby League
epic: 0.1%
Ruby League 1st place
Sapphire League
epic: 0.3%
Sapphire League 1st place
Platinum League
epic: 0.3%
Platinum League 1st place
Ice
rare: 1.9%
Exploiting Windows via a media server
90 Day Streak
rare: 2.1%
Hacking for 90 days solid
Sword Apprentice
rare: 2.7%
Completing the SQLMap room
Metasploitable
rare: 7.6%
Exploiting machines with Metasploit
Blue
rare: 8.4%
Hacking into Windows via EternalBlue
Advanced exploitation, Active Directory attacks, and post-exploitation methodology beyond the Jr path.
● In ProgressPractising real-world enumeration, foothold identification, and privilege escalation on live boxes.
● OngoingBuilding methodology for OffSec Certified Professional — buffer overflows, manual exploitation, and structured report writing.
◆ Targeting 2025–26Certified Ethical Hacker — foundations of offensive security
✓ CompletedStructured junior penetration testing curriculum
● OngoingHands-on entry-level pentesting certification
□ UpcomingIntermediate penetration testing certification — the PT1 exam
□ UpcomingIndustry-standard offensive security certification
□ UpcomingHands-on penetration testing certification — Hack The Box
□ UpcomingRed team operations, C2 frameworks, and adversary simulation
□ Long-term GoalAtharva demonstrated an unwavering commitment to his tasks. His ability to handle a wide array of responsibilities — from managing security for laptops for new joiners to troubleshooting network issues — showcased his versatility and problem-solving skills. His attention to detail and meticulous approach in cybersecurity, network ops, and overall tech support were truly commendable. His proactive attitude greatly contributed to the smooth operation of our IT support functions. He has proven to be a valuable asset, and I am confident that he will continue to excel in his future endeavors.
Atharva’s expertise in network support was evident throughout his internship. His adeptness in configuring and troubleshooting network devices ensured uninterrupted connectivity. Noteworthy was his initiative in setting up VPN connections for remote employees, showcasing his grasp of complex tunneling protocols and encryption methods. His proactive approach stood out — he not only excelled in routine tasks but also proposed network optimisation and security enhancement measures. He is a promising candidate for any network-related role, and I’m confident he will continue making valuable contributions.
Open to Junior Penetration Tester roles and security engineering opportunities in the UK. Always happy to discuss offensive security, CTF challenges, or potential collaborations.