Cybersecurity Analyst/Network Administrator/Cloud & AI Security
I build secure networks, detect and contain threats with Wazuh, and explore where
cloud, AI, and quantum computing meet security — backed by hands-on red-team
operations and live SOC work.
A hands-on engineer across network operations, offensive security, and threat detection.
I'm Hafiz Asim Shayan Khan, a BS Computer Science graduate from Abasyn University, Peshawar,
with a concentration in Cybersecurity & Artificial Intelligence.
My work sits where network security, offensive testing, and threat detection meet.
On the offensive side, I've run full red-team engagements — OSINT, reconnaissance,
Active Directory attacks, phishing, and endpoint evasion. On the defensive side, I work as a
Network Administrator managing campus infrastructure and operating the
Wazuh XDR platform, writing custom detection rules and active-response
actions tailored to the university's requirements.
Python is my strongest language — it's the thread running through my threat-intel
pipelines, deep-learning detectors, automation scripts, and quantum research.
§ 02Explore by domain
Six areas of work.
Each area has its own page with the projects, labs, tools, and credentials behind it.
From breaking into labs on the red team to defending live infrastructure with Wazuh.
Network Administrator · Abasyn University
Jun 2026 — Present
Blue Team · SOC · Peshawar, Pakistan
Manage the university's network infrastructure — configuring and maintaining switches and Wi-Fi access points, monitoring performance, and troubleshooting connectivity issues across campus.
Deployed the Wazuh XDR platform and write custom detection rules for threat detection and active response, tailored to the university's requirements — with proper documentation of every rule and workflow.
Automate routine network and configuration tasks using AI for faster, consistent, and more efficient deployments.
Triage alerts, correlate logs, and map detections to MITRE ATT&CK to prioritise investigation and response.
Red Team Intern · Cyberster
Mar 2026 — May 2026
Offensive Security · Remote
Ran end-to-end penetration tests across Linux, Windows, and Active Directory labs — passive OSINT through to Domain-Admin compromise.
Performed OSINT and subdomain enumeration with Subfinder, Assetfinder, and OWASP Amass — 352 subdomains discovered, 21 live hosts validated via httpx & Gowitness.
Executed AD attacks — AS-REP Roasting, Kerberoasting, LLMNR/NBT-NS poisoning, GPO ACL abuse — reaching NT AUTHORITY\SYSTEM on domain controllers.
Built phishing campaigns with GoPhish and Havoc C2; applied AMSI bypass, LOLBAS, and payload obfuscation to evade endpoint defences in controlled labs.
Documented every finding in professional pentest reports mapped to CVSS and MITRE ATT&CK.
§ 04Programming
Python is my primary language.
Nearly every project on this site — offensive tooling, detection models, automation, research — is written in it.
🐍PythonPRIMARY LANGUAGE
My strongest language and the backbone of my work: the ThreatFusion AI intel pipeline,
the ThreatNet deep-learning SOC detector, the QSVM quantum research, network
scanning and asset-discovery automation, and offensive scripting for active defence and C2.
Representing communities, mentoring peers, and the professional skills that make the technical work land.
🎖️
Cyberster Ambassador
Cyberster Security Academy CURRENT
Represent and advocate for Cyberster — promoting its offensive-security training, championing
the program within the student and security community, and supporting aspiring red-teamers.
🗣️
Class Representative (CR)
Abasyn University · 2022 – 2026
Elected representative for the BS Computer Science cohort across the full four-year degree —
the liaison between students and faculty, coordinating academics and resolving issues.