MultiHAT-Academy
Full-stack e-learning platform turning technical notebooks into premium, verifiable micro-credentials.
Built with Next.js 15 and NestJS 11, featuring dynamic watermarked e-books, interactive quizzes, public
certificates, built-in Wallet, referral rewards, and native aamarPay integration for local payments.
sydneywheelsandtyres
High-performance static marketing website for Sydney Wheels & Tyres. Built with Next.js,
TypeScript, and Tailwind v4, featuring immersive UI animations, 3D tilt cards, automated sitemaps, and
rich local business schema designed to showcase auto services and drive customer bookings in
Campbellfield.
multihat.dev
Digital solutions agency portal building secure software, high-performance websites, AI-powered
workflows, and privacy-first tools, turning complex enterprise challenges into reliable, secure technology
through thoughtful engineering and modern design.
sagarbiswas-multihat.github.io
Privacy-first static developer and cybersecurity portfolio for Sagar Biswas (MultiHAT). Fast, SEO-friendly
GitHub Pages hub showcasing operations, tutorials, and technical write-ups, featuring RSS/Atom feeds, XML
sitemaps, responsive design, and automated verification suites.
attack-surface-toolkit
Non-destructive passive attack surface mapping utility analyzing DNS, SSL, headers, and historical assets
to compute a 0-100 exposure score with interactive visual graphs.
osint-exposure-toolkit
Modular passive reconnaissance CLI inspecting emails, domains, and usernames for leaks, generating
interactive exposure graphs, GitHub secret scans, and breach reports.
Phoneint-OSINT-Toolkit
Reconnaissance suite for phone number validation, international carrier extraction, timezone resolution,
and passive reputation verification.
Speech2Speech-AIAssistant
Offline-capable voice interaction pipeline integrating wake-phrase detection, speech-to-text
transcription,
modular intent routing, and synthesized TTS feedback.
BlackHAT-AI-Assistant
Desktop automation assistant interfacing with Groq LLM inference, rapid web query orchestration,
and local session memory recall.
PythonicHackathon-CLI
Terminal-first virtual assistant for computer science students offering multi-line command parsing,
curated resource automation, and integrated AI model Q&A support.
Web_Vulnerability_Scanner-AI
Queue-based rate-limited web vulnerability crawler inspecting missing security headers, cookie flags,
reflected XSS, and SQL injection indicators with AI triage export.
NmapScanningTool
Secure, production-ready Python CLI wrapper for Nmap providing 12 automated scan profiles, vulnerability
and
NSE checks, interactive and non-interactive workflows, strict input validation, and Docker container
support.
MAC-Changer_Pro
Linux MAC address spoofer with random vendor assignment for wireless security testing in authorized
virtual labs.
bazaarflow-ecommerce
Production full-stack e-commerce architecture with Next.js storefront, NestJS API, Redis caching,
Meilisearch indexing, and dual Stripe and bKash payment gateway integrations.
FedUni-Clinical-EMR-Simulator
Enterprise electronic medical record simulation platform built on ASP.NET Core 8 and SQL Server, providing
14 hospital modules, deterioration alerts, risk scoring, and clinical audit tracking.
Impress-Crush-Cpp-ASCII
High-performance multithreaded C++ image-to-ASCII converter leveraging brightness gradients,
gamma correction curves, and regional character shape matching.
Email-Harvester
Production-ready passive OSINT CLI discovering publicly visible business contacts via search engine APIs,
robots-aware crawling, MX record verification, and CSV reporting.
WebSource-Harvester
Breadth-first web asset crawler that archives client-side site assets and rewrites internal link paths
for safe offline browsing and perimeter reconnaissance.
HashAttackDemos
Cryptographic verification toolkit contrasting modern Argon2id, bcrypt, and scrypt hash algorithms
against dictionary and rainbow table cracking vectors.
WiFi-Dictionary-Attack
Educational wireless audit script scanning nearby 802.11 networks and validating WPA/WPA2 passphrase
strength using wordlists and automated connection handshakes.
A-Pythonic-Keylogger
Python endpoint keystroke interception tool designed for educational security audits, featuring real-time
caching, automated SMTP dispatch with retry logic, and multi-OS persistence guides.
EmailBomber
Educational SMTP automation script demonstrating TLS handshake negotiation, credential protection via
getpass, and controlled transmission loops for stress testing.
penetration-testing-roadmap
Structured 60-week penetration testing curriculum featuring 500+ TryHackMe labs, OWASP Top 10 deep dives,
tool mastery guides, and modern AI/LLM, Cloud, and API security tracks.
awsume-cybersecurity-paths
Comprehensive cybersecurity career roadmap and handbook covering 35 specialized roles across Offensive,
Defensive, and GRC domains, alongside 100+ tools, certification paths, and 10 security architectures.
awesome-cybersecurity-books
Curated directory of 70+ free cybersecurity texts structured across beginner to advanced tiers, spanning
exploit development, malware analysis, network defense, and web security.
promptVault
Private, offline-first prompt manager for AI power users featuring AES-256 encrypted local storage,
a built-in AI Librarian for prompt refinement with fallback support, dynamic variable templates, and
instant search.
PhishGuard-AI
Fast-paced defensive awareness web game powered by a Dual-AI Consensus Engine (OpenRouter and Groq)
generating verified, timed email phishing scenarios in real time.
Ai-Resume-Analyzer
Local-first Flask web application evaluating PDF and DOCX resumes with Groq and OpenAI models,
generating structured scoring, ATS keyword audits, and actionable rewrites.
ChatAutomationForMarketing-AI-Assistant
Desktop chat response automation utility for Messenger and WhatsApp integrating PyAutoGUI, clipboard
capture, and Groq AI inference with dry-run telemetry and configurable coordinates.
SharpLink-URL-Allies
Flask-based URL shortening service featuring custom aliases, TTL expiration, rate limiting, and SQLite
persistence for backend service architecture.
Fake_FACEBOOK_Login_Page
Educational phishing simulation login interface demonstrating credential capture vectors, designed
strictly
for controlled security awareness training to instruct users on URL verification and phishing prevention.
Multi-FA-Auth
Two-factor and multi-factor authentication engine in Python implementing RFC 6238 TOTP, defensive rate
limiting, and session security verification.
SecurePay_E-Wallet-V1
Local PHP/MySQL e-wallet application and hands-on vulnerability demonstration lab featuring CSRF
protection,
session hardening, and a toggleable environment illustrating XSS and session hijacking mitigations.
Password-Strength-Checker
Accessible offline password entropy analyzer and cryptographic generator calculating character complexity,
weak pattern detection, and real-time ARIA feedback.
BF-IDS Project Proposal
Behavioral Fingerprinting-Augmented Embedded IDS proposal for Raspberry Pi 4 and ESP32. Architecture
design exploring anomaly detection via Isolation Forest.
TCP-Playground
Multi-client socket communication toolkit supporting TLS-wrapped connections, symmetric message
encryption,
and raw protocol inspection for network audits.
CustomerSlip-CLI
Production-grade C++17 CLI point-of-sale utility with atomic file transactions, discount computation
algorithms, and dual CSV/JSONL durability.
Secure-Photo-PDF-Bidirectional-Converter
Lightweight Windows converter turning photos into high-fidelity PDFs and extracting pages back to images.
Preserves EXIF orientation, supports lossless compression, and operates entirely locally without cloud
uploads.
Library-Management-System
Compact desktop library management application built with Python and Tkinter, featuring TOTP two-step
sign-in,
local lending and return workflows, overdue tracking, and offline data privacy.
PyTextEditor
Cross-platform Tkinter text editor engineered with atomic file writes, crash recovery journals,
BOM encoding validation, and customizable UI themes.
SafeTodoManager
Task management system built with defensive programming standards, parameterized queries, and local
database security.
Contact-Management-System-CLI
Single-binary C11 contact manager integrating SQLite persistence, Argon2id password hashing,
transactional CSV dry-run imports, and automated test suites.
PyCalculator
Secure scientific desktop calculator using Abstract Syntax Tree (AST) node parsing to prevent
code injection vulnerabilities without eval functions.
WSL2-Kali-Setup-Guide
Installation walkthrough for WSL2, Kali Linux, and Win-KeX graphical desktop on Windows with GPU
acceleration notes.
researchVault
Personal research vault covering career roadmaps (2026-2030), study systems for computer science, and
data-backed timing analytics.
infosec-vocabulary
Bilingual English-Bangla cybersecurity glossary providing concise definitions, synonyms, real-world breach
context,
and educational notes designed for learners, SOC trainees, and educators.
BAD_USB
Defensive security research compendium analyzing USB HID injection vectors, physical perimeter hardening,
endpoint detection rules, and user awareness controls.
BruteforceLab1
Interactive browser authentication simulator modeling PIN keyspace entropy, rate limits,
CAPTCHA penalties, and account lockout curves for defensive training.
BruteforceLab2
Full-stack authentication lab pairing a vulnerable Flask endpoint with an automated CLI attack
harness to benchmark sliding-window rate limiters and lockouts.
TextBombing-Toolkit
Cross-platform keystroke and clipboard automation utility featuring hardware failsafes,
countdown confirmations, dry-run validations, and stress-test routines.
virusNewFolder
Cross-platform testing CLI managing temporary directory simulation routines, dry-run validations,
and controlled cleanup for forensic staging research.
WinTempCleaner
Lightweight Windows batch maintenance script clearing sensitive temporary staging directories and Prefetch
caches to eliminate common malware staging artifacts.
Saved-WiFi-Restore
Admin-focused local CLI for enumerating Windows wireless profiles, featuring explicit consent prompts,
key masking, encrypted exports, and locale-aware netsh parsing.
WiFi-QR-Generator
Client-side privacy-first wireless QR code generator supporting WPA/WPA2, hidden SSIDs, vector SVG
exports,
and offline credential payload rendering.
Student-Management-MVC-Learning-Project
Educational PHP architectural pattern implementation utilizing front controller routing,
PDO prepared statements, and clean separation of concerns without dependencies.
domain2ip
Concurrent network utility resolving hostnames to IP addresses with error handling and deduplication for
recon pipelines.
PyAlarmClock
Focused command-line alarm system accepting 12-hour timestamps with live terminal schedules,
cross-platform audio fallback routines, and pytest validation.
SecureBankingSystem
Desktop banking and account manager featuring Argon2id password and PIN hashing, audited balance ledgers,
and local SQLite persistence.
SecureBank-CLI
Compact C++17 command-line banking system demonstrating audited transaction logs, atomic file persistence,
secure credential handling, sanitizers, and Docker support.
Port_Scanner-Python
Dual-interface network reconnaissance utility providing both a fast CLI socket scanner and a local
Flask dashboard for inspecting open TCP port perimeters.
XSS-WebGuard
Client-side HTML sanitization interface demonstrating DOM-based XSS neutralization, event handler
stripping,
and safe DOM manipulation without external libraries.
SeleniumFirefoxGoogleSearchAutomation
End-to-end browser automation research script with headless Firefox drivers, test steps,
and architectural guidance for API migration.