Danish Abbas
@danishabbas1
I uncover web vulnerabilities and build threat detection workflows across offensive and defensive security engagements.
What I'm looking for
I've discovered and responsibly disclosed high-severity IDOR, XSS, SQL Injection, and authentication bypass vulnerabilities through YesWeHack and Bugcrowd. My web application testing combines manual Burp Suite assessment, attack-surface mapping, fuzzing, and Python-powered reconnaissance automation.
I've also built a Wazuh SIEM threat detection lab across Linux and Windows endpoints, tuning rules for brute force, privilege escalation, file integrity, and suspicious process activity. I bring hands-on experience in vulnerability reporting, CVSS scoring, OWASP-aligned remediation, incident triage, and secure full-stack development with PHP Laravel, MySQL, and JavaScript.
Experience
Work history, roles, and key accomplishments
Independent Security Researcher
Self Employed
Jul 2024 - Present (2 years 1 month)
Discovered and responsibly disclosed high-severity vulnerabilities in production web applications, including IDOR, XSS, SQL Injection, and Authentication Bypass. Authored CVSS v3.1-scored reports with PoC reproduction and remediation guidance.
Education
Degrees, certifications, and relevant coursework
Capital University of Science and Technology
Bachelor of Science, Software Engineering
2020 - 2024
Grade: 3.12 / 4.00
Bachelor of Science in Software Engineering with a focus on information security and forensics, computer networking, and database systems.
Availability
Location
Authorized to work in
Portfolio
github.com/DanishAbbas72Job categories
Skills
Interested in hiring Danish?
You can contact Danish and 90k+ other talented remote workers on Himalayas.
Message DanishGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
