$ id
uid=1337(armx64) gid=security(researcher) \
groups=red-team,vapt,exploit-dev,ai-security,bangladesh
$ cat /etc/passwd | grep armx64
armx64:9+ years offensive security, pentesting, research, open-source tooling9+ years breaking things professionally.
I work at CipherShield as a Senior Penetration Tester, focusing on offensive security and security assessments. Outside the day job, I run research and open-source work through System00 Security and publish hands-on vulnerability research at armx64.medium.com.
My work sits at the intersection of red teaming, vulnerability research, Windows/Linux internals, AI security, exploit development, and practical offensive tooling.
Recent research has focused on attack surfaces that live between traditional security boundaries — WSL/Windows interoperability, Microsoft Defender internals, MCP security, autonomous AI agents, and unconventional C2 infrastructure.
| Article | Focus |
|---|---|
| Abusing WSL Interop: An Offensive Deep-Dive into Microsoft's Stealth VM | WSL2 · Endpoint Evasion · Persistence |
| RoguePlanet: From Defender to Attacker | Windows Internals · Defender · LPE |
| A Pentester's Guide to the Model Context Protocol (MCP) | AI Security · MCP Pentesting |
| Type Confusion in Adminer → Persistent DoS | Vulnerability Research |
| Emergence Without Understanding: LLM Social Network Postmortem | AI Agents · Security Research |
| Abusing Image Hosting Service as C2 Server | C2 · Red Team Infrastructure |
| Chaining CVE-2024-24919 — Check Point LFI | CVE Exploitation · LFI |
- Red Team Operations — OPSEC-aware adversary simulation and offensive security
- Windows Internals — Defender attack surface, WSL, privilege boundaries, endpoint evasion
- Vulnerability Research — type confusion, LFI chains, application and infrastructure flaws
- AI × Security — MCP pentesting, agent security, tool poisoning and autonomous-system threats
- Offensive Tooling — maintainable security tooling in Python, Go, TypeScript, Bash, C and PHP



