Skip to content
View threatpointer's full-sized avatar

Block or report threatpointer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
threatpointer/README.md

Mohammed Tanveer

Security Researcher & Architect

GitHub Followers Profile Views

Twitter       LinkedIn       Blog       Website

Security About Me

I'm a seasoned security professional with over 15 years of experience in security engineering, product security, and cloud security. Currently, I lead security architecture and product security initiatives at Microsoft, driving secure development across Azure Edge & Platform, Windows & Devices, and Gaming.

Throughout my career at Microsoft, SAP Ariba, and Citrix, I've played a key role in strengthening security postures, establishing cross-functional security teams, and securing Microsoft acquisitions. My expertise spans threat modeling, vulnerability research, exploit development, penetration testing, and Red Teaming.

Beyond my technical contributions, I'm deeply committed to mentoring, fostering a security-first culture, and advancing the cybersecurity community. I actively contribute through speaking engagements, publications, and advisory roles, including consulting with the Data Security Council of India on cybercrime-related issues.

I'm also passionate about helping startups and enterprises build and implement security engineering practices for both offensive and defensive security needs, enabling them to scale securely.

Online, you might know me as threatpointer.

πŸ›‘οΈ Security Expertise

Threat Modeling Vulnerability Research Exploit Development Penetration Testing Cloud Security Product Security Fuzzing Red Teaming Application Security Incident Response & Threat Hunting Privacy & Compliance

πŸ’» Tech Stack


πŸ”Ή Core Programming & Scripting Languages

Python C# Java JavaScript Bash PowerShell C/C++

πŸ”Ή Offensive Security (Red Team, Pentesting, Exploit Development)

Metasploit Burp Suite SQLmap Nmap BloodHound Cobalt Strike Frida Ghidra IDA Pro Wireshark

πŸ”Ή Defensive Security (Blue Team, Incident Response, Threat Hunting)

Splunk OSQuery MITRE ATT&CK

πŸ”Ή Application Security & Secure Development

Semgrep SonarQube OWASP ZAP Snyk AFL CodeQL

πŸ”Ή Cloud Security & Infrastructure Security

AWS Security Azure Security GCP Security Terraform Kubernetes Docker

πŸ”Ή DevSecOps & CI/CD Security

GitHub Security GitLab Security Azure DevOps Vault Tenable

πŸ”Ή Identity & Access Management (IAM) & Zero Trust

Okta Azure AD OAuth SAML Zero Trust

πŸ”Ή Miscellaneous Security Tools

MISP Volatility Hashcat Microsoft Sentinel

πŸ” Featured Security Projects

πŸ“Š GitHub Stats

GitHub Stats GitHub Streak
Contribution Graph

πŸ† Achievements & Certifications

CISSP OSCP CEH SEC760 ECSA Azure Security CBSP

Pull Shark

Starstruck

πŸ“ Latest Blog Posts


Security Quote

Pinned Loading

  1. v8-optimized-fuzzer v8-optimized-fuzzer Public

    A specialized fuzzing framework for identifying vulnerabilities in the V8 JavaScript engine. Generates high-value test cases targeting specific vulnerability patterns like JIT type confusion, array…

    Shell

  2. Http3App Http3App Public

    A very simple app built to fuzz Quic Protocol

    C#