Golf
Five years in. Best ideas happen on the back nine.
18-year-old penetration tester and builder working between Karachi and Dubai — offensive security by day, shipping products the rest of the time.
Ibreakthingstounderstandthem,thenbuildwhatIwishexisted.Shippingthreesystemsat theedge ofsecurity&AI.
Five years in. Best ideas happen on the back nine.
Massano, Argy, Anyma. It's about storytelling — selection, transitions, atmosphere.
Weekend games to get off the screens and reset.
US, UK, UAE, KSA, Qatar, Kuwait, Bahrain, Thailand. Prayer, reflection, time in Madinah — it keeps me grounded.
ALSO INTO — Gaming · Crypto markets · Discovering new music
I break things to understand them — then build what I wish existed.
I'm 18, working in offensive security between Karachi and Dubai — with Rewterz and SIRP — and building products at the intersection of security, AI, and everyday life. Most of it started because I wanted a better tool for myself: a scanner that thinks like an attacker, an assistant that actually runs my day, a platform that makes an organization legible.
I'd rather ship something imperfect, learn from real usage, and iterate fast than chase theoretical perfection. The two halves feed each other — testing shows me the failure modes worth building against, and building shows me how the systems I test are actually put together.
Web apps, APIs and the business logic underneath them — probed the way an attacker would, not the way a scanner would. Bug bounty on the side.
Turning what I find by hand into something that runs without me. OmniScan and Operon both started as that problem.
I think in agents, workflows and validation pipelines — systems doing real work on a schedule rather than demos.
3 systems in flight. Each one started as something I wanted to exist and couldn't find.

An AI-powered web-app vulnerability scanner — scans, attacks, validates and reports, like an autonomous pentester that never gets bored on hour nine.

My personal AI operating system — an assistant that runs my day by chat, by voice, and through a dashboard I actually open every morning.

A multi-tenant platform that unifies how an organization runs — from HR to workflows — without ten disconnected tools.
I test real-world targets for the flaws that only surface when you think adversarially — the ones a scanner reports as clean.
Active bug-bounty hunter alongside client work. Findings stay with the client — what I publish is method, never data.
Map the real attack surface — subdomains, endpoints, parameters, the hosts nobody remembers owning. Most findings start here.
Understand the app the way its developers do: roles, flows, trust boundaries, and what each endpoint quietly assumes.
Chain what's actually reachable. A finding that can't be reached isn't a finding.
Reproduce it cleanly and prove impact, so nothing reaches a report that can't survive being questioned.
Write it so it can be fixed — exact steps, real impact, and remediation that closes the class rather than the instance.

Eight handicap, five years in, still chasing the swing.

Afro house on a Karachi rooftop, laptop and a Coke.

The Dubai half of the split.

Controller, mixer, monitors. Selection is the whole craft.

Phone off, trees on.

The hour when most of the building actually happens.

Got into crypto around 15 — Bitcoin, Solana, and how blockchains actually work. That rabbit hole led to everything else.
It pulled me into cybersecurity, and then into offensive security.
Somewhere in there I realized I love building as much as hacking.
So I started making the tools I wished existed. Almost everything began as “why doesn't this exist yet?”
Long-term: build products people genuinely rely on.
If you have a system worth attacking or a product worth building, I want to hear about it.
me@hamzahmad.io→