Skip to content
MasaudSec Academy

Our Team

Masaud Ahmad - MasaudSec Academy Founder
Founder & Principal

10K+

Enrolled Students

2+

HoF Recognitions

#01 — Founder & Principal

Masaud Ahmad

Cybersecurity Researcher | Ethical Hacker | Penetration Tester | Mentor — Tank, South Waziristan Tribal District, KP, Pakistan

Objective

I am a cybersecurity researcher and penetration tester with a strong focus on offensive security, drawing on years of hands-on experience probing the defenses of websites, servers, and networks. My work centers on identifying real vulnerabilities before they can be exploited by malicious actors — running structured vulnerability assessments, carrying out controlled exploitation to confirm impact, and translating technical findings into clear, actionable reports that organizations can actually use to fix what’s broken. I take pride in approaching every engagement methodically, balancing the mindset of an attacker with the discipline and responsibility of someone entrusted to protect systems and the people who depend on them.

Professional Experience

Cyber Security Trainer & Researcher

MasaudSec Academy

In my role as a trainer, I design and deliver hands-on sessions covering offensive security, open-source intelligence (OSINT), and the OWASP Top 10, aiming to give participants practical, immediately usable skills rather than just theoretical knowledge. I run these sessions as interactive workshops, encouraging participants to work through real scenarios so that core security concepts stick with them well beyond the classroom.

This approach has resonated widely — my courses have attracted more than 10,000 enrolled students on Udemy, and I continue to grow that community through new content and direct engagement with learners. Alongside training, I carry out authorized penetration testing engagements and conduct responsible disclosure research, reporting vulnerabilities to organizations through proper channels so they can be remediated before they are exploited.

Skills & Technical Foundation

My technical foundation is built around offensive security work, including penetration testing, web application security, OSINT-driven reconnaissance, and vulnerability assessment aligned with the OWASP Top 10. I script in both Bash and Python to automate reconnaissance and testing workflows, and I am equally comfortable operating in Linux and Windows environments, which lets me adapt my approach to whatever infrastructure I’m assessing. Beyond the purely technical side, I rely heavily on structured problem solving and clear report writing, since the value of a penetration test ultimately comes down to how well its findings are communicated to the people who need to act on them.

Penetration TestingWeb App SecurityOSINT ReconnaissanceOWASP Top 10Bash ScriptingPython AutomationLinux & WindowsReport WritingVulnerability Assessment

Education

Associate Degree in Computer Science

Gomal University, DI-Khan Campus, Tank (2020 – 2022)

Intermediate in Computer Science (ICS)

Tank, KP, Pakistan

Languages

I communicate fluently in English, Urdu, and Pashto, which allows me to train and collaborate effectively with both local and international audiences.

Acknowledgments / Hall of Fame

My responsible disclosure work has been formally recognized by organizations including the University of Sheffield (UK) and Crunch, a UK-based accounting platform, both of which credited me for identifying and reporting security vulnerabilities through their official disclosure programs.

Agha Asfandyar Khan - MasaudSec Academy Co-Founder
Co-Founder & Co-Principal

5+

Yrs Red Team

4+

Certifications

#02 — Co-Founder & Co-Principal

Agha Asfandyar Khan

Red Team Operator | Malware Developer & Analyst | Linux System Administrator — Rahim Yar Khan, Pakistan

Profile

I work in offensive security, and my path into it started from the ground up. I spent my early years (2018-2019) learning Linux inside out, then moved into red teaming, and along the way picked up malware development and reverse engineering as its own focus. I like understanding systems at every layer, from how a Linux box is administered to how a payload behaves once it lands on a target. That range is what I bring to a team: I can build the tooling, run the operation, and then sit down and analyze the result.

Experience

Red Team Operator

2020 to Present

I have been working as a red team operator since 2020, and the learning never really stopped, it has run alongside the actual work the whole time. Most engagements involve taking an environment from initial foothold through to full compromise rather than testing one thing in isolation. Over the years this has meant:

  • Exploiting weaknesses across internal and external network services to gain and expand access.
  • Working through operating system level exploitation on both Windows and Linux, including privilege escalation and post exploitation activity.
  • Attacking Active Directory (AD DS) environments, from abusing misconfigurations to building out lateral movement and privilege escalation paths inside a domain.

Linux System Administrator

2018 to 2019

Before moving into red teaming, I spent two years focused entirely on Linux, working through everything a proper system administrator needs to know. That included managing users and permissions, configuring services, writing shell scripts, handling networking, and hardening systems against attack. It was not a short course or a certificate, it was two years of genuinely learning the operating system, and it still shapes how I approach offensive work today since I understand the systems I am attacking from the administrator’s side too.

Malware Development & Analysis

Alongside red teaming, I develop malware in Rust, mostly focused on evasion and getting past modern defenses rather than just getting code to run. This includes writing self injection and process injection techniques, DLL side loading, sleep obfuscation to dodge behavioral detection, and abusing living off the land binaries already present on a system. I also work with in memory execution so payloads never touch disk, and I have built kernel embedded malware for deeper, harder to detect footholds.

On the analysis side, I spend a good amount of time reverse engineering both my own tools and other malware samples to understand how they actually behave and how defenders might catch them. My regular toolkit includes Binary Ninja, Ghidra, IDA Pro, GDB, radare2, OllyDbg, and x64dbg, depending on what the sample needs and how deep I have to go.

C2 Frameworks

Hands-on experience deploying and operating in lab and operational settings:

Sliver C2Mythic C2Havoc C2Covenant C2Villain C2Metasploit

Malware Development (Rust)

Self InjectionProcess InjectionDLL Side LoadingSleep ObfuscationLOTL BinariesIn-Memory ExecKernel Malware

Certifications

Certified Ethical Hacker (CEH)

Hunarmand Punjab Program

Critical Infrastructure Security

OPSWAT Academy

Skeler Certified Malware Analyst

Skeler Security

Skeler Certified Penetration Tester

Skeler Security

Chat on WhatsApp