whoami
Hi, I’m Surajit — a technology enthusiast, cybersecurity researcher, and backend developer. While most people spend their time outside, I’ve always felt at home sitting at my desk, hands on the keyboard and eyes on the screen, always eager to learn something new.
It all started back in 7th grade when I joined a basic computer tuition class. At that time, I only knew how to use MS Paint, Word, Excel — and I thought that was really cool! But soon, I realized that to truly learn tech, I had to explore it on my own. My curiosity became my biggest teacher.
I got my first computer around 8th or 9th grade. It came with Windows 10 pre-installed, and instead of waiting for someone to teach me, I turned to the internet. I started watching YouTube videos, reading tutorials, and exploring everything from scratch — from configuring systems to removing viruses and building my first programs.
Then came a turning point in 11th grade when a video titled “How to Hack CCTV Cameras” popped up on my feed. That curiosity led me to discover ethical hacking and cybersecurity. I began watching videos about Linux, IP addresses, networking, HTTP protocols, phishing, Tor, and web applications. I loved learning how systems work — and more importantly, how they can break.
I started digging deeper into malware, Linux exploitation, reverse shells, payload creation, and CTF challenges. Real security isn’t just about looking cool — it’s about deep technical knowledge, thinking like an attacker, and protecting systems against real-world threats.
All of this I owe to the open web — from tech forums and documentation to CTFs and security blogs. Everything I’ve learned has come from this amazing community.
And this is just the beginning…
Languages & Tools I Use
- Languages: JavaScript (ES6+), Python, C, Ruby, Bash/Shell Scripting.
- Primary Backend & Runtimes: Node.js, Express, Hono, MongoDB, Redis, and Firebase.
- Infra & DevOps: Arch (Daily Driver BTW 🗿), Docker, Nginx, Git/GitHub, and Postman/curl.
- Frontend & Styling: React, Tailwind CSS, and HTML5/CSS3.
Security Related Competencies
Defense & Monitoring
- IDS/IPS & Monitoring: Intrusion detection with Snort, event monitoring, and log analysis.
- System & Infrastructure Hardening: System security configuration, container security (Docker hardening), and proactive defense mechanisms.
Forensics & OSINT
- Traffic & Log Analysis: Deep packet inspection using Wireshark, network traffic analysis, and web/system log investigation.
-
Digital Forensics: Disk imaging (
dd), data recovery, encryption bypass fundamentals (BitLocker), and investigative Open-Source Intelligence (OSINT) gathering.
Offensive Security & AppSec
- Web App Pentesting: Active CTF player focused on OWASP Top 10 vulnerabilities. Proficient in manual and automated security testing using Burp Suite, SQLMap, Nuclei, and OWASP ZAP.
- Privilege Escalation & Active Directory: Manual Privilege Escalation on Linux/Windows and core Active Directory security concepts.
- Infra & Mobile Analysis: Mobile security analysis with MobSF/ADB, container security, and network reconnaissance.
Explore all links via Linktree (linktr.ee/blackxploit).