Every security analyst eventually reaches a tipping point. It’s the moment you realize that relying solely on off-the-shelf scripts and generic tools isn't enough to tackle modern web application security. To truly understand an attack surface, you have to know how to build the infrastructure underneath it.
My name is Koushiq Murad (also known online as XOppenheimer). I am a CAPT Certified Penetration Tester and Full-Stack Engineer. I built this blog to serve as my digital brain, a public research log, and the central hub for my offensive security journey as I prepare to transition into the Australian cybersecurity market.
Why This Blog Exists
The cybersecurity industry is flooded with noise, automated scanner outputs, and fragmented methodologies. I want to cut through that. Instead of just running tools, my philosophy is to architect them.
Over the coming months, this space will serve as a message bearer for my active research. Here is what you can expect to see:
- Offensive Tool Architecture: Deep dives into how I leverage AI-accelerated development to build custom client-side weapons using React, TypeScript, and Python.
- Methodology Breakdowns: How to standardize OWASP assessments so critical vulnerabilities—like complex SSRF or BOLA—don't slip through the cracks.
- CTF Walkthroughs & Write-ups: Tactical notes from compromising hardened systems on TryHackMe and Hack The Box.
The Security Arsenal (My Custom Tooling)
If you want to see my approach to offensive development in action, I’ve already deployed a suite of privacy-first, client-side tools designed for pentesters:
- 🛡️ PentestVault: A bespoke knowledge base and reporting engine for standardizing OWASP assessments.
- ⚡ CipherLab: An advanced crypto analyzer and reverse-shell payload generator.
- 🔥 Wordlist Forge: A high-performance, client-side dictionary mutator for password spraying.
Let's Connect
I am actively seeking Junior/Associate Penetration Tester roles and love connecting with fellow security engineers. You can verify my official Hackviser CAPT Credential here.
Feel free to reach out to me on LinkedIn or review my code and CTF progress on GitHub and TryHackMe.
Stay curious. Break things. Build better ones. — Koushiq Murad













