FILE: MH-2026-OPS CLEARANCE: LEVEL-3
Black and white operator portrait of Sagar Biswas
OPERATOR: Sagar Biswas
DESIGNATION: Security Technologist
DISCIPLINE: Assess · Harden · Govern
STATUS: AVAILABLE FOR ROLE
VERIFIED OPERATIONAL EVIDENCE // NO INFLATED METRICS

Sagar Biswas

MultiHAT Operations // Software, AI & Security Engineer

Recruiter-first security portfolio built on proven work. Moving seamlessly through the continuous loop: Assess attack surfaces lawfully, Harden defensive architectures with verifiable controls, and Govern / Disclose risk with technical clarity and ethical precision.

03 Unified Disciplines
100% Self-Hosted Provenance
0 Third-Party Runtime Bloat
// PROOF ARCHITECTURE

The Three Continuous Security Vectors

Replacing arbitrary skill percentages with equal-weight evidence dossiers. Each vector follows strict provenance: Objective & Scope, Method, Tangible Artifact, Result State, and Direct Evidence Link.

VECTOR 01: ASSESS Scope-Limited

Offensive Security

Methodical adversarial assessment, passive reconnaissance, and attack-surface analysis scoped strictly to authorized environments and educational research.

1. Objective & Scope: Passive OSINT & web vulnerability mapping in controlled labs
2. Method / Control: Information gathering, port discovery, and parameter analysis
3. Tangible Artifact: System design, system programming, OSINT, and the comprehensive cybersecurity Roadmap.
4. Result State: Documented reconnaissance workflows and toolchain
Inspect Assess Dossier →
VECTOR 02: HARDEN Public Implementation

Defensive Hardening

Converting attack insight into resilient infrastructure: hardened CSP, local-only asset isolation, multi-factor authentication, and zero-trust engineering.

1. Objective & Scope: Eliminate attack surfaces and unauthorized script execution
2. Method / Control: Strict CSP headers, TOTP multi-factor, input validation
3. Tangible Artifact: Multi-FA-Auth engine and portfolio's inspectable CSP
4. Result State: 100% self-hosted assets, 0 remote third-party leaks
Inspect Harden Dossier →
VECTOR 03: GOVERN Published Case

Risk & Disclosure

Translating technical findings into prioritized business risk. Enforcing responsible disclosure ethics, remediation roadmaps, and clear executive reporting.

1. Objective & Scope: Communicate perimeter security findings without data leakage
2. Method / Control: Confidence scoring, severity prioritization, remediation advice
3. Tangible Artifact: Sanitized Passive Recon Case File & Security Articles
4. Result State: Remediation paths communicated; zero sensitive data exposed
Inspect Govern Dossier →
// OPERATIONS LEDGER

Selected Inspectable Operations

Curated repositories and functional tools. Every entry links directly to public code with stated operational scope.

OP-OFF-05 Recon Tool

attack-surface-toolkit

Non-destructive passive attack surface mapping utility analyzing DNS, SSL, headers, and historical assets to compute a 0-100 exposure score with interactive visual graphs.

OP-OFF-06 OSINT Tool

osint-exposure-toolkit

Modular passive reconnaissance CLI inspecting emails, domains, and usernames for leaks, generating interactive exposure graphs, GitHub secret scans, and breach reports.

OP-OFF-07 Public Code

Phoneint-OSINT-Toolkit

Reconnaissance suite for phone number validation, international carrier extraction, timezone resolution, and passive reputation verification.

OP-SEC-11 AI Scanner

Web_Vulnerability_Scanner-AI

Queue-based rate-limited web vulnerability crawler inspecting missing security headers, cookie flags, reflected XSS, and SQL injection indicators with AI triage export.

OP-NET-12 Public Code

NmapScanningTool

Secure, production-ready Python CLI wrapper for Nmap providing 12 automated scan profiles, vulnerability and NSE checks, interactive and non-interactive workflows, strict input validation, and Docker container support.

OP-NET-13 Lab Tool

MAC-Changer_Pro

Linux MAC address spoofer with random vendor assignment for wireless security testing in authorized virtual labs.

MultiHAT Technical Broadcast: Root Your Android Emulator
TELEMETRY // FEED: LIVE-CH-01
Broadcast Intel TRANSMISSION NO. YOUTUBE-01

MultiHAT Technical Broadcast

Direct video transmission demonstrating hands-on security concepts, tool development, and defensive configuration walkthroughs.

// CASE STUDY & DISCLOSURE

Passive Reconnaissance Case Study

Anonymized summary of an authorized passive reconnaissance assessment conducted against a production web platform.

CASE REF: RECON-2025-01 // PRODUCTION WEB PLATFORM
PASSIVE RECON ONLY RESPONSIBLE DISCLOSURE

Assessment Scope & Rules of Engagement

Strictly non-invasive, passive reconnaissance was conducted without intrusive automated scanning, denial of service, or data exfiltration. The objective was to evaluate external exposure surface, DNS integrity, header configurations, and authentication boundaries. All sensitive target identifiers and specific endpoints are redacted.

01. Origin IP Exposure via DNS

DNS records leaked the direct backend origin IP address, bypassing cloud proxy protection and exposing server ports directly.

02. Exposed Media Storage Bucket

Asset storage bucket permissions permitted unauthenticated listing and direct retrieval of stored media files.

03. Unvalidated Redirect Parameter

Login flow accepted arbitrary destination paths in redirection parameters, enabling potential credential harvesting relay.

04. Unthrottled Verification Endpoint

SMS and email verification codes exhibited no visible rate limits or progressive throttling, creating brute-force risk.

05. User Enumeration Differentiation

Authentication failure responses varied based on account existence, allowing systematic username and phone discovery.

06. Missing Defense-in-Depth Headers

Absence of strict Content-Security-Policy (CSP), HSTS, and framing controls elevated clickjacking and injection risks.

Remediation guidance with prioritized CVSS scorings was shared directly with platform administrators.

View Sanitized Public Report (PDF) →
// CREDENTIAL VAULT

Verified Clearance Records

Certified milestones with documented provenance. Inspect scans directly or verify via official issuer records.

Certified Phishing Prevention Specialist (CPPS) Credential Scan

Certified Phishing Prevention Specialist (CPPS)

Verified
ISSUER: Security Training Authority
CREDENTIAL TRACK: Social Engineering Defense
PROVENANCE: Original PDF Document Available
Download PDF Verification →
Certified Red Certificate Scan

Certified Red Operations Certificate

Verified
ISSUER: Red Team Operations Program
CREDENTIAL TRACK: Adversarial Operations
PROVENANCE: Original PDF Document Available
Download PDF Verification →
// FIELD MANUALS

Technical Field Manuals & Study Notebooks

Handcrafted reference guides and interactive study vaults covering systems programming, defensive tradecraft, network protocols, and security automation.

NB-PREM-01

Choose Your Cybersecurity Path, WISELY!

Premium

A complete guide for aspiring cybersecurity professionals. Breaks down 35 career roles across Offensive Security, Defensive Security, and GRC with tool ecosystems, real scenarios, and step-by-step certification roadmaps.

OSINT / Careers Live Vault →
NB-PREM-02

Google Dorks: The Complete Handbook

Premium

The expanded edition covering advanced search syntax and security queries. Connects Google Dork operators to OSINT investigations, vulnerability discovery, ethical hacking, bug bounties, and safe academic research.

OSINT / Careers Live Vault →
NB-SEC-03

Understanding Phishing

Published

A full walkthrough of phishing, from its 1990s origins to today's AI-powered scams. Covers attacker infrastructure, phishing types, warning signs, and the checklists, MFA, and training defenders use to spot and stop attacks.

PDF Guides Live Vault →
// INTEL ARCHIVE

Research Transmissions & Technical Writing

Detailed security teardowns, cryptographic resilience notes, and defensive field manuals authored for practitioners.

Why attackers target the Windows Temp folder illustration

February 2026 · Endpoint Security

Why Attackers Target the Temp Folder, and How to Protect It

Analysis of initial access persistence mechanisms targeting default temporary directories and specific filesystem access control defenses.

Read Full Transmission →
Understanding OSI layers through real security attack examples

February 2026 · Network Security

Understanding OSI Layers Through Real-World Attack Scenarios

From physical rogue APs to application-layer deserialization attacks: mapping practical exploits to layer-specific mitigations.

Read Full Transmission →
Post-quantum cryptography and encryption standards

January 2026 · Post-Quantum Security

Post-Quantum Cryptography: Why Classical RSA is Vulnerable

Practical walkthrough of Shor's algorithm impact on public-key infrastructure and transition roadmaps for NIST PQC standards.

Read Full Transmission →
// DIRECT CHANNEL

Clearance Communications

Available for security engineering, web security assessment, and technical roles.

Engage Operator

Reach out directly for professional roles, technical collaborations, or responsible vulnerability reporting.

Direct Email:
Professional Network:
Sagar Biswas
Executive Résumé:
View Printable Résumé →

Responsible Research Charter

All security assessments, vulnerability research, and penetration testing workflows presented in this portfolio are conducted strictly within:

  • Authorized educational environments, local virtualized networks, and CTF challenges.
  • Passive, non-destructive public reconnaissance adhering to legal authorization limits.
  • Standard coordinated disclosure guidelines providing target organizations ample remediation windows prior to public discussion.
Zero automated exploitation against unauthorized production targets.