__  __ _____ __  __  ____  _    _ _____ _______
  |  \/  |_   _|  \/  |/ __ \| |  | |_   _|__   __|
  | \  / | | | | \  / | |  | | |__| | | |    | |
  | |\/| | | | | |\/| | |  | |  __  | | |    | |
  | |  | |_| |_| |  | | |__| | |  | |_| |_   | |
  |_|  |_|_____|_|  |_|\____/|_|  |_|_____|  |_|
SESSION_ESTABLISHED // Welcome Visitor

MD MONZURUL ISLAM

[username: mimohit]

|

I build systems that hold up under pressure - Zero Trust architectures, hardened APIs, the odd browser extension at 2AM. Between deployments I read Kafka, Dostoevsky, and Camus, brew pour-over coffee, and occasionally cry at anime finales. This archive is the story of all of it.

↓ scroll to begin, or try the terminal
USER: mimohit
NODE: DHAKA_BD // 23.81°N 90.41°E
UPTIME: 00:00:00
↑↑↓↓←→←→BA — try it sometime
VOLUME 00ORIGIN STORY
~/about/me.sh
$ whoami
> aspiring cybersecurity researcher & engineer

$ cat interests.txt
> threat detection, browser security tooling,
> authentication systems, API security,
> privacy-preserving systems

$ cat guilty_pleasures.txt
> Kafka, Dostoevsky, Camus, V60 coffee,
> cyberpunk anime, the occasional 3AM CTF

$ echo $MISSION
> "translate complex security challenges into
>  practical, human-readable implementations"
TAP TAP TAP

It starts, as most things do, with a keyboard and too much curiosity. I got into security by looking at systems I used every day and asking why they trusted what they did — analyzing network traffic, questioning default configurations, and seeing how fragile our foundations can be.

"Security isn't a feature you patch on later; it's the foundation you lay from day one."

Finding vulnerabilities is only half the equation; the real craft is building defenses that endure. That obsession drives me to design perimeterless architectures and secure APIs built to stay standing when compromised.

VOLUME 01FIELD LOG

A running log of where I've deployed. Chronological. Mostly true.

JUNE 2026 — PRESENT · DHAKA, BANGLADESH

Cybersecurity Researcher & Research Associate — Arché Intelligence Lab

  • Conduct advanced cybersecurity research focused on threat analysis, system vulnerabilities, and secure data architectures.
  • Collaborate with cross-functional research teams to develop security frameworks and publish findings under the Arché Intelligence initiative.
2026 — PRESENT · USA (REMOTE)

CEO & Founder — FrithX LLC

  • Founded and lead a cybersecurity, privacy, and AI governance platform focused on helping organizations assess and manage technology risk.
  • Designed and developed security and compliance modules spanning threat modeling, Zero Trust assessment, privacy compliance, and AI governance.
  • Engineered an MCP-based integration layer enabling AI agents to securely query risk registers and interact with compliance workflows.
MAY 2026 — PRESENT · DHAKA, BANGLADESH

Software Developer — Ledgercross

Blockchain & Cloud Solutions
  • Develop and maintain core software modules for enterprise blockchain and cloud-based solutions.
  • Collaborate on smart contracts and decentralized modules, ensuring secure and efficient transaction processing.
FEB 2026 — MAY 2026 · DHAKA, BANGLADESH

Software Developer Trainee — Ledgercross

Blockchain & Cloud Solutions
  • Analyzed decentralized system architectures, data flows, and consensus mechanisms in multi-tenant blockchain environments.
  • Assisted with cloud infrastructure implementation and unit testing for blockchain protocols.
VOLUME 02INTELLIGENCE LOGS

Classified-adjacent research. Declassified for this archive.

FILE_01 // THESIS Submitted to NDSS

Hardware-Based Zero Trust Authentication Framework

Final Year Thesis — Submitted to NDSS

Spearheaded a research team of five to design a device-bound Zero Trust authentication framework using TPM-backed proof-of-possession and OpenID Connect. Implemented contextual access decisions with session risk scoring, adaptive MFA enforcement, and policy-driven authorization.

"The perimeter is dead. Identity, bound to hardware, is the new boundary."
TPMOIDCRISK SCORINGADAPTIVE MFA
FILE_02 // INDEPENDENT FINAL STAGE

Open Banking API Security

Independent Research — Ongoing

Empirical analysis of Open Banking API implementations to identify privacy gaps and session-hijacking vectors. Built proof-of-concept attack simulations using JavaScript, cURL, and Keycloak to evaluate token misuse and replay scenarios, then documented practical mitigations.

"APIs are the veins of modern software — secure them or bleed data."
OPEN BANKINGKEYCLOAKTOKEN REPLAYPoC
FILE_03 // INDEPENDENT Submitted to NDSS

Adaptive Malware Containment System (AMCS)

Independent Research — Submitted to NDSS

Designing an AI-driven, real-time runtime isolation system that shifts endpoint security from reactive process termination to continuous, proactive mitigation. Implementing a zero-overhead telemetry pipeline using eBPF kernel probes alongside Landlock LSM and cgroups v2 middleware to dynamically mutate process boundaries mid-execution. Developing a lightweight temporal machine learning engine to evaluate streaming system calls and data entropy, enforcing granular resource constraints and isolation rules based on dynamic risk scores.

"Don't kill the process. Cage it, watch it, and let it hang itself."
eBPFLANDLOCK LSMCGROUPS V2RUNTIME ISOLATIONTEMPORAL ML
VOLUME 03CONSTRUCT ARCHIVE

Things I've built. Click a card to expand the dossier.

DOSSIER_01 🔐

FrithX

React · TypeScript · Firebase

FrithX is an all-in-one cybersecurity compliance platform that converts static privacy policies into an active, evidence-backed dashboard for managing legal regulations (GDPR/CCPA), third-party vendor risks, and AI governance.

GRCZERO TRUSTPRIVACY-FIRST
DOSSIER_02 🔗

LedgerScan

React · Node.js · Keycloak · Docker · Solidity · Web3.js · Redis · PostgreSQL

A blockchain-powered product authentication platform transforming supply chain barcodes into cryptographic identities, enabling real-time counterfeit protection and verified integrity tracking. Developed while working as a software developer at LedgerCross.

A Product of Ledgercross
BLOCKCHAINIDENTITYANTI-COUNTERFEIT
DOSSIER_03 👁️

DeepFake Detector

Python · Node.js · React

AI-based browser extension detecting deepfake media in real time. Optimized asynchronous requests for low-latency scanning without disrupting normal browsing.

NEURAL NETFORENSICSEXTENSION
DOSSIER_04 🛡️

Malicious URL Detector

JavaScript · HTML · VirusTotal API

Chrome extension identifying phishing and malware domains via VirusTotal reputation checks, with lightweight instant UI alerts for flagged URLs.

HEURISTICSNETWORK SECEXTENSION
DOSSIER_05 🕵️

WhoStoleMyName?

Next.js · TypeScript · Supabase · Tailwind CSS · SerpAPI

Developed a real-time funky search engine to check business name availability across domains (via RDAP lookups), social media handles, and existing web footprints. Engineered a parallelized query engine and a shared JSONB caching layer on Supabase to minimize latency, integrated Google OAuth for auth-gated history logs, and designed a custom cartoon/glassmorphism UI.

OSINTSEARCH ENGINEGLASSMORPHISM
DOSSIER_06 🔨

Auction

Solidity · React · Web3

Decentralized auction platform with on-chain bid escrow and transparent settlement logic — smart contracts handling bid validation, timed closes, and trustless fund release to the winner.

SMART CONTRACTSBLOCKCHAINESCROW
VOLUME 04CAPABILITY MATRIX
💻

LANGUAGES

SECTOR // 01 — CORE EXECUTION LAYER
Python JavaScript TypeScript SQL Solidity HTML/CSS
⚙️

FRAMEWORKS

SECTOR // 02 — BUILD SCAFFOLDING
React Node.js Firebase Streamlit Web3.js
🔐

AUTH & IDENTITY

SECTOR // 03 — TRUST & ACCESS CONTROL
Keycloak OIDC JWT OAuth 2.0 TPM
🛠️

TOOLS & INFRASTRUCTURE

SECTOR // 04 — FIELD OPERATIONS KIT
Burp Suite Nmap Wireshark Metasploit Postman Git VS Code Remix Linux eBPF Draw.io OverLeaf Docker Redis PostgreSQL

SIGNAL DIAGNOSTICS

Python 94%
JavaScript 90%
Linux 85%
Problem Solving 96%
Patience 99%
TELEMETRY_CONSOLE // CAPABILITY_MONITOR
> SYSTEM SCANNER: ACTIVE
> NODE STATE: STABLE
> Hover over a capability node above to query telemetry link...
CERTIFICATIONS//
TryHackMe — Jr Penetration Tester Google — Foundations of Cybersecurity Google — Play It Safe: Manage Security Risks Google — Connect and Protect: Network Security IBM — JavaScript Backend Development Udemy — Ethereum & Solidity Coursera — Blockchain TryHackMe — Jr Penetration Tester Google — Foundations of Cybersecurity Google — Play It Safe: Manage Security Risks Google — Connect and Protect: Network Security IBM — JavaScript Backend Development Udemy — Ethereum & Solidity Coursera — Blockchain
VOLUME 05DIRECT LINK

Skip the scrolling. Talk to the archive directly. Type help to begin.

mimohit@archive: ~
Welcome to mimohit.sys — interactive shell v2.1.0
Type help for a list of commands.
mimohit@archive:~$
VOLUME 07RECOVERY MODE

Not everything is exploits and access control. Some of it is just... quiet.

COFFEE

V60 precision. Single origin Ethiopia, always. The ritual matters more than the caffeine.

📖

BOOKS

Kafka, Dostoevsky, Camus on rotation. Stories where the dread is the plot twist.

🎬

ANIME

Attack on Titan, Jujutsu Kaisen, Classroom of the Elite, Vinland Saga, FMAB, and Black Clover.

🌱

COMMUNITY

Volunteer Lead teaching underprivileged children · Former Senior Executive, BRAC Business Club · Duke of Edinburgh Award, Bronze.

"if you've read this far — thank you for staying a while. make yourself a coffee. i'll wait."