Available for VAPT Engagements

Mohammed

Arif P
role: 

CEH v12 certified offensive security professional with 2+ years of hands-on VAPT experience. Author of 4 cybersecurity books under WhiteFox InfoSec. Committed to identifying real threats before attackers do.

CEH v12 Certified 4 Books Authored 15+ Apps Tested
0+
Web Apps Tested
0+
Years VAPT Experience
0
Books Authored
0+
Certifications & Courses
01 · About Me

Security Expert.
Published Author.

I'm a Certified Ethical Hacker (CEH v12) with over two years of hands-on experience delivering end-to-end Vulnerability Assessment and Penetration Testing. My methodology is precise, evidence-based, and aligned with globally recognized standards including OWASP Top 10 and MITRE ATT&CK.

"Offense informs defense — and I've built a career mastering both sides of the equation."

My engagements span the full attack lifecycle — scoping, reconnaissance, exploitation, post-exploitation, and client debrief — with a strong emphasis on communicating risk clearly to both technical and executive stakeholders.

Beyond consulting, I author cybersecurity books under WhiteFox InfoSec, creating structured learning resources for the next generation of security professionals.

Location
Kerala, India
Brand
WhiteFox InfoSec
Mohammed Arif P — Penetration Tester & Cybersecurity Author
Mohammed Arif P
CEH v12 · VAPT Consultant · Author
Mohammed Arif P working as a Cybersecurity Professional
WhiteFox InfoSec
// WhiteFox InfoSec
Arif,
Cyber Security
Professional
WhiteFox InfoSec · Kerala, India
02 · Publications

Authored Books

Published under WhiteFox InfoSec — practical, field-tested cybersecurity guides built from real-world penetration testing experience.

Engineering Web Application VAPT Part 1
Engineering Web App VAPT · Part 1

Foundations & Web Security Core

A complete foundation guide covering web application vulnerability assessment methodology, OWASP Top 10, and testing frameworks for security practitioners.

Mohammed Arif P · WhiteFox InfoSecRead Book ↗
Engineering Web Application VAPT Part 2
Engineering Web App VAPT · Part 2

Offensive Web Application VAPT

Advanced offensive techniques — exploiting SQL Injection, XSS, IDOR, broken authentication, and business logic flaws in real-world applications.

Mohammed Arif P · WhiteFox InfoSecRead Book ↗
Shadow Hunters
Shadow Hunters · Part 1

Complete Guide to Cybersecurity & Ethical Hacking

Foundations of Cyber Defense & Offensive Security — an 85-chapter comprehensive study guide for modern cybersecurity practitioners.

Mohammed Arif P · WhiteFox InfoSecRead Book ↗
Engineering Cybersecurity with Kali Linux
Engineering Cybersecurity

Engineering Cybersecurity with Kali Linux

Offensive security, defense, automation, and incident response — a hands-on Kali Linux guide for security engineers and ethical hackers.

Mohammed Arif P · WhiteFox InfoSecRead Book ↗
03 · Capabilities

Technical Skills

A full-spectrum offensive security toolkit refined through real-world engagements, research, and continuous learning.

🌐
Web Application Security
OWASP Top 10SQL InjectionXSSIDORBroken AuthSession MgmtAPI SecurityBusiness Logic
🔗
Network Penetration Testing
Network VAPTReconnaissanceEnumerationExploitationPost-ExploitationTCP/IPFirewall Analysis
📊
Security Reporting
CVSS ScoringPoC WritingRisk AssessmentThreat ModelingMITRE ATT&CKClient Debrief
📡
Threat Intelligence & SOC
CTIOSINTPhishing AnalysisIncident ResponseAlert TriageTTP Analysis
⚙️
Frameworks & Standards
NIST CSFISO 27001PCI-DSSOWASPMITRE ATT&CKSecure SDLC
💻
Programming & Protocols
PythonBashSQLHTTP/HTTPSDNSTCP/IPSMTP
// Security Tools Arsenal
Burp Suite
OWASP ZAP
Nmap
Wireshark
SQLmap
Metasploit
Nikto
Gobuster
Dirsearch
Hydra
TCPdump
Nessus
Shodan
Maltego
SpiderFoot
BloodHound
SonarQube
Splunk
MS Sentinel
MS Defender
CrowdStrike
Kali Linux
04 · Experience

Work History

Cyber Security Consultant
Competitive Cracker Pvt. Ltd May 2025 – Feb 2026
  • Conducted end-to-end VAPT for 15+ web applications, identifying critical vulnerabilities including SQL Injection, XSS, IDOR, and Broken Authentication across diverse client environments.
  • Performed attack surface analysis covering authentication, session management, and access control mechanisms aligned with OWASP Top 10 and MITRE ATT&CK.
  • Prepared detailed technical reports with CVSS scoring, proof-of-concept exploits, business impact analysis, and remediation strategies for technical and non-technical stakeholders.
  • Delivered hands-on cybersecurity training sessions on web application security, exploitation techniques, and real-world attack scenario simulations.
  • Led penetration testing interns, guiding them through VAPT methodologies, real-world testing scenarios, and professional security reporting practices.
  • Conducted controlled attack simulations and supported knowledge-sharing sessions on vulnerability exploitation and mitigation strategies.
Junior Penetration Tester
Funtastic Sports Pvt. Ltd Nov 2023 – Dec 2024
  • Performed vulnerability assessments on web applications and internal systems, identifying security flaws aligned with OWASP Top 10 methodology.
  • Executed reconnaissance, vulnerability scanning, exploitation, and post-exploitation activities across authentication, session management, and access control mechanisms.
  • Documented exploitation techniques, attack vectors, and mitigation steps with proof-of-concept and risk-based prioritization.
  • Assisted in remediation validation, system hardening, and secure configuration improvements in collaboration with development teams.
Cyber Security Intern
Riss Technologies Aug 2022 – Mar 2023
  • Developed a blockchain-based forensic evidence security system ensuring tamper-proof data integrity and secure digital evidence handling.
  • Applied secure validation workflows, cybersecurity principles, and integrity controls to enhance system reliability and evidence protection.
  • Supported system architecture design, security testing, documentation, and secure deployment activities.
  • Gained hands-on exposure to digital forensics concepts, secure architecture practices, and cybersecurity fundamentals.
05 · Projects

Featured Projects

Real-world security projects combining offensive research, tool development, and applied cybersecurity principles.

// Project 01
Blockchain-Based Forensic Evidence Security System

Designed and implemented a tamper-proof digital evidence management system using blockchain technology. Ensured data integrity, secure validation workflows, and transparent forensic chain-of-custody — applied at Riss Technologies.

BlockchainDigital Forensics Data IntegritySecure Architecture Python
// Project 02
Web Application Security Testing Lab

Practiced exploitation of OWASP Top 10 vulnerabilities on DVWA and OWASP Juice Shop. Conducted manual testing using Burp Suite, simulated real-world attack scenarios, and documented complete findings with PoC and remediation guidance.

OWASP Top 10Burp Suite DVWAJuice Shop SQLi / XSS / IDOR
// Project 03
OSINT & Threat Analysis Practice

Conducted open-source intelligence reconnaissance using Shodan to identify exposed services and attack surfaces. Practiced threat profiling, attack pattern mapping against MITRE ATT&CK, and produced structured intelligence reports.

OSINTShodan MITRE ATT&CKThreat Profiling Maltego
// Publication
WhiteFox InfoSec — 4-Book Cybersecurity Series

Authored 4 field-tested cybersecurity books translating real VAPT experience into structured learning resources — covering web application VAPT (Parts 1 & 2), ethical hacking foundations (Shadow Hunters), and Kali Linux security engineering.

Technical WritingVAPT Web App SecurityKali Linux Ethical Hacking
06 · Credentials

Certifications & Education

Industry-recognised certifications, verified credentials, and formal academic qualifications across offensive security, threat intelligence, and cloud security.

// Primary Certifications
CEH v12 Certificate
EC-Council
Certified Ethical Hacker (CEH v12)
ECC2183607954 · 27 Jul 2024 · Valid till Jul 2027
Google Cybersecurity Certificate
Google / Coursera
Google Cybersecurity Professional
Dec 4, 2024 · ID: Y866NXOLSD1W
Cisco Ethical Hacker
Cisco Networking Academy
Cisco Verified Ethical Hacker
May 30, 2024
arcX CTI Certificate
arcX
Cyber Threat Intelligence 101
Foundation Level Analyst · Nov 29, 2023
AWS Security Fundamentals
Amazon Web Services
AWS Security Fundamentals (2nd Ed.)
May 25, 2024
AWS IAM Certificate
Amazon Web Services
AWS IAM Auth & Authorization
May 27, 2024
AWS Shared Responsibility Model
Amazon Web Services
AWS Shared Responsibility Model
May 25, 2024
Advanced Diploma Cyber Defense
Red Team Hacker Academy
Advanced Diploma in Cyber Defense
ID: RTXSTU11225 · May 14, 2024
// EC-Council Course Certificates
SQL Injection Attacks
SQL Injection Attacks
Oct 31, 2023 · #262338
Android Bug Bounty
Android Bug Bounty: Hunt Like a Rat
Oct 30, 2023 · #262104
Dark Web
Dark Web, Anonymity & Cryptocurrency
Nov 11, 2023 · #265675
Cloud Computing
Practical Intro to Cloud Computing
May 14, 2024 · #325544
Cisco LABS
Cisco LABS Crash Course
May 16, 2024 · #326214
Juniper Router
Juniper SRX Router via J-Web
May 17, 2024 · #326780
Python Beginners
Python for Absolute Beginners
May 22, 2024 · #328548
Cyberbullying
Cyberbullying & Beating-the-Bully
May 26, 2024 · #330090
// Education
Bachelor of Computer Applications
Calicut University · Assabah Arts & Science College

BCA focused on CS fundamentals, networking, and cybersecurity. Reg. No: AVAUBCA012, Valayamkulam, Kerala.

Advanced Diploma in Cyber Defense
Red Team Hacker Academy · May 2024

IT Infrastructure · Network & Offensive Security · Cyber SOC · Application Security · ML for Cybersecurity · Cyber Kill Chain & Compliance

Continuous Security Research
TryHackMe · HackTheBox · CTFs

Hands-on labs, DVWA, OWASP Juice Shop, CTF competitions, OSINT research, and active threat intelligence study.

07 · Contact

Get In Touch

Available for VAPT engagements, security consulting, training sessions, speaking events, and collaboration opportunities.