Security Researcher · Software Engineer · CTF Player

Abdul Hakim
Shifat

I build security tools, solve CTF challenges, and explore Linux and low-level systems with a planner's patience. The work blends software engineering, research, and open-source craftsmanship.

Open to security engineering, vulnerability research, systems programming, and open-source opportunities.

#49

Global CTF

#3

Bangladesh

20+

Notes & projects

Abdul Hakim Shifat
01

Experience

Co-Founder & Security Researcher

@ Cyb3r Invasi0n Army (CIA) ↗

Aug 2025 — Present Current

Co-founded a competitive CTF team focused on cybersecurity. Coordinate team strategy for international CTF competitions, manage challenge assignments based on member expertise, conduct post-competition analysis, and organize training sessions.

↳ Global Rank #49 · National Rank #3 (Bangladesh)

CTF Cybersecurity Leadership Problem Solving

Maintainer & Creator

@ YTUI Music (AUR) ↗

Mar 2026 — Present Current

Created and maintain a terminal-based YouTube audio player published on the Arch User Repository. Full-stack TUI development with Textual, AUR packaging via PKGBUILD, and release management.

↳ Published on AUR · One-command install

Python Textual AUR Open Source MPV

Open Source Contributor

@ iNiR (snowarch) ↗

Feb 2026

Contributed configurable bar scroll actions and global workspace scroll inversion to a Linux desktop shell built on Quickshell. Designed a reusable input abstraction layer and ensured cross-compositor compatibility.

↳ Cherry Picked & Merged (PR #53)

QML Linux Quickshell Niri UI

Campus Ambassador

@ GeeksforGeeks

Jan 2026 — Present Current

Official representative for GeeksforGeeks at Bangladesh University of Professionals. Promote technical resources, organize coding events and seminars, and build the campus tech community.

Community Leadership Event Management Tech Outreach
02

About

I am Abdul Hakim Shifat, known online as Joyboy__. I am from Bangladesh and study Computer Science and Engineering while building tools, writing technical notes, and competing in cybersecurity challenges.

My strongest work happens where systems thinking meets security research: CTF tooling, Linux experiments, reverse engineering notes, practical automation, and carefully documented learning.

I prefer durable work: small tools that solve real problems, writeups that teach clearly, and projects that keep improving after the first release.

3+

Years Building

20+

Projects & Notes

#49

Global CTF Rank

#3

National Rank

03

Education

B.Sc. in Computer Science and Engineering

Bangladesh University of Professionals (BUP)

Jun 2023 – Jul 2027 CGPA: 3.45 / 4.00 (5th Semester)

HSC

Nawab Fayzunnesa Govt. College

GPA: 5.00 / 5.00

SSC

Kakirtala High School

GPA: 4.89 / 5.00
04

Skills & Certifications

Languages

C C++ Python Java JavaScript SQL x86 Assembly

Frontend

Astro React TypeScript Tailwind CSS HTML5 CSS3

Systems & Security

Linux Docker IDA Burpsuite Wireshark Reverse Engineering

Tools & Platforms

Git VS Code Django PostgreSQL AWS QEMU

Certifications

Certified Red Team Operations Management (CRTOM)

Red Team Leaders

Dec 2025

Problem Solving (Intermediate)

HackerRank

Jan 2025

Linux 100

TCM Security

Dec 2024
05

Projects

YTUI Music

YTUI Music

A terminal-based YouTube audio player built with Textual, mpv, and yt-dlp. Keyboard-first, resource-efficient alternative to browser-based music listening. Published on the AUR.

Python Textual TUI YouTube MPV
Case study ↗
Tiny x64 Bootloader

Tiny x64 Bootloader

A minimal 512-byte x64 boot sector demonstrating BIOS boot process fundamentals including real mode initialization, segment register setup, and stack configuration.

Assembly x86_64 Low-Level OS Dev
Case study ↗
Personal Portfolio & Blog

Personal Portfolio & Blog

Theme-driven site that dynamically renders content from an Obsidian vault, automating the pipeline from private technical notes to public blog posts.

Astro Obsidian Tailwind
Project note SOC / EVALUATION

soc-triage-calibration

Engineering package for SOC L1 automation research, supporting dataset provenance auditing, independent split validation, selective-prediction evaluation, and adversarial prompt-injection experiments.

Python SOC Calibration Dataset Auditing Security Research
Case study ↗
Project note VISION / ANIME

Meme Mirror Local

A Linux Python camera application that turns meme or anime reaction images into local rehearsal prompts, then scores a user-taught face and hand pose against the reference.

Python OpenCV MediaPipe Local AI Anime
Case study ↗
Project note AUR / STATIC ANALYSIS

aurscan

A local, CLI-first, evidence-based scanner for Arch Linux AUR recipes that statically inspects PKGBUILD, .install, .SRCINFO, sources, and recipe commands without executing them.

Python CLI Arch Linux Static Analysis SARIF
Case study ↗
Project note STEGANOGRAPHY / WEB APP

SWE-Project

Secure Information Hiding System Using Steganography: a full-stack application for hiding text or files inside PNG/BMP images with optional password protection and later extraction.

React TypeScript Express PostgreSQL Steganography
Case study ↗
07

Achievements

TexSAW 2026

International
22nd Feb 2026

UMDCTF 2026

International
21st 2026

CTF@AC26 — Quals

International
22nd 2026

squ1rrel CTF 2026

International
43rd 2026

pingCTF 2026

International
44th 2026

BUET CTF

National
7th Jan 2026

Al-Khwarizmi CTF 2025

National
11th Dec 2025

Circuit Clash 1.0 CTF

National
6th Nov 2025

DIU CyberCon CTF

National
7th Oct 2025

ICPC Asia Dhaka Regional

ICPC
Participated 2023-2025
08

Contact

Let's connect.

I'm always open to discussing cybersecurity, open-source projects, competitive programming, or anything tech-related. Feel free to reach out.