$ ls -la ~/WH!T5T!G5R
Dipongkor Roy at the HackerOne Bug Hunt event against a matrix code backdrop

Dipongkor Roy

Dipongkor Roy

I am Dipongkor Roy, also known as WH!T5T!G5R: a Cyber Security Enthusiast, Bug Bounty Hunter, and CTF player from Sylhet, Bangladesh. I hunt web vulnerabilities as a Security Researcher on HackerOne and Intigriti.

My focus is offensive web security: deep reconnaissance and manual testing for broken access control, IDOR, injection flaws, authentication bypasses, SSRF, and business logic errors. I work with Burp Suite, Nmap, and Wireshark alongside custom Python and Bash tooling, guided by the OWASP Top 10 and MITRE ATT&CK.

I hold 26+ certifications from EC-Council, Cisco Networking Academy, TryHackMe, Udemy, and Team Matrix, rank in the Top 1% on TryHackMe, and serve as Campus Ambassador for Team Matrix - Elite Hackers at Shahjalal University of Science and Technology.

> About Me

Hi, I am Dipongkor Roy

I am a Cyber Security Enthusiast, Bug Bounty Hunter, and CTF player based in Sylhet, Bangladesh. I currently work as a Web Security Researcher on both HackerOne and Intigriti, where I hunt for real-world vulnerabilities across public bug bounty and Vulnerability Disclosure Programs.

My focus is offensive web security: deep reconnaissance, manual testing, and hunting the bug classes that automated scanners miss: broken access control and IDOR, injection flaws, authentication bypasses, SSRF, and business logic errors. I work primarily with Burp Suite, Nmap, and Wireshark alongside custom scripting in Python and Bash, guided by the OWASP Top 10 and MITRE ATT&CK.

I have earned 26+ cybersecurity certifications from EC-Council, Cisco Networking Academy, TryHackMe, Udemy, and Team Matrix, including Ethical Hacking Essentials (EHE), Network Defense Essentials (NDE), Digital Forensics Essentials (DFE), and the Cisco Ethical Hacker badge. I rank in the Top 1% on TryHackMe and have completed five consecutive years of Advent of Cyber.

Alongside security research, I serve as Campus Ambassador for Team Matrix - Elite Hackers at Shahjalal University of Science and Technology, and as IT Secretary of Sonchalon, our voluntary blood donors organization. I believe volunteerism is not a charity but a responsibility.

> Skills

> Experience

HackerOne

Web Security Researcher

Apr 2025 - Present

Remote

  • Hunt for security vulnerabilities across public bug bounty and Vulnerability Disclosure Programs (VDP) on the HackerOne platform.
  • Perform in-depth reconnaissance and manual testing of web applications and APIs to uncover business logic flaws, access control issues, and injection vulnerabilities.
  • Write clear, reproducible vulnerability reports with proof-of-concept and actionable remediation guidance for security teams.
  • Participated in the HackerOne Bug Hunt 2026 community event in Dhaka, Bangladesh.

Intigriti

Web Security Researcher

Apr 2025 - Present

Remote

  • Research and report web application vulnerabilities on Intigriti bug bounty programs for European enterprise targets.
  • Focus on OWASP Top 10 classes of issues including broken access control, injection, authentication bypass, and misconfiguration.
  • Collaborate with triage teams to validate impact and drive findings through to resolution.

Team Matrix - Elite Hackers

Campus Ambassador

Jan 2024 - Present

Dhaka, Bangladesh

  • Represent Shahjalal University of Science and Technology (SUST), Sylhet as Campus Ambassador, bridging innovation and academia.
  • Promote cybersecurity education and awareness across the campus community through workshops, CTFs, and training sessions.
  • Coordinate participation in ethical hacking, digital forensics, and cloud security programs for fellow students.

Sonchalon, SUST

IT Secretary

Mar 2024 - Present

Sylhet, Bangladesh

  • Serve as IT Secretary of Sonchalon, the voluntary Blood Donors Organization at SUST.
  • Manage the digital presence, donor data workflows, and technical infrastructure supporting the organization.
  • Volunteerism is not a charity but a responsibility.

Sonchalon, SUST

Assistant Organizing Secretary

Mar 2023 - Mar 2024

Sylhet, Bangladesh

  • Spearheaded coordination of events driving dialogue and action towards sustainable practices and community welfare.
  • Managed logistics with precision, ensuring seamless execution of blood donation drives and awareness initiatives.
  • Engaged the SUST community to promote awareness, participation, and advocacy for social responsibility.

> Hobbies

> Badges

38 skill badges earned through hands-on labs, streaks, and seasonal challenges.

  • TryHackMe
  • Hack The Box Academy
  • Cisco Networking Academy
  • 180 Day Streak badge from TryHackMe180 Day Streak
  • 90 Day Streak badge from TryHackMe90 Day Streak
  • 30 Day Streak badge from TryHackMe30 Day Streak
  • 7 Day Streak badge from TryHackMe7 Day Streak
  • 3 Day Streak badge from TryHackMe3 Day Streak
  • AI Odyssey badge from TryHackMeAI Odyssey
  • Advent of Cyber 2025 badge from TryHackMeAdvent of Cyber 2025
  • Advent of Cyber 2024 badge from TryHackMeAdvent of Cyber 2024
  • Advent of Cyber 2023 badge from TryHackMeAdvent of Cyber 2023
  • Advent of Cyber 4 badge from TryHackMeAdvent of Cyber 4
  • Advent of Cyber 3 badge from TryHackMeAdvent of Cyber 3
  • OWASP Top 10 badge from TryHackMeOWASP Top 10
  • Intro to Web Hacking badge from TryHackMeIntro to Web Hacking
  • World Wide Web badge from TryHackMeWorld Wide Web
  • Webbed badge from TryHackMeWebbed
  • Burp'ed badge from TryHackMeBurp'ed
  • Introduction to Security Engineering badge from TryHackMeIntroduction to Security Engineering
  • Pentesting Principles badge from TryHackMePentesting Principles
  • Metasploitable badge from TryHackMeMetasploitable
  • Linux PrivEsc badge from TryHackMeLinux PrivEsc
  • cat linux.txt badge from TryHackMecat linux.txt
  • Hash Cracker badge from TryHackMeHash Cracker
  • Network and System Security badge from TryHackMeNetwork and System Security
  • Networking Nerd badge from TryHackMeNetworking Nerd
  • Software Security badge from TryHackMeSoftware Security
  • Blue badge from TryHackMeBlue
  • Cyber Ready badge from TryHackMeCyber Ready
  • Sword Apprentice badge from TryHackMeSword Apprentice
  • Shield Apprentice badge from TryHackMeShield Apprentice
  • Calculated Risk badge from TryHackMeCalculated Risk
  • League Locked Legend badge from TryHackMeLeague Locked Legend
  • Raffle Royalty badge from TryHackMeRaffle Royalty
  • Just have to deal with it badge from TryHackMeJust have to deal with it
  • Academician badge from Hack The Box AcademyAcademician
  • Cyber Rookie badge from Hack The Box AcademyCyber Rookie
  • Unwavering User badge from Hack The Box AcademyUnwavering User
  • Ethical Hacker badge from Cisco Networking AcademyEthical Hacker
  • Introduction to Cybersecurity badge from Cisco Networking AcademyIntroduction to Cybersecurity

> Certifications & Achievements

Ethical Hacking Essentials (EHE)

EC-CouncilCredential ID : 227193

June 2023

Network Defense Essentials (NDE)

EC-CouncilCredential ID : 244111

August 2023

Digital Forensics Essentials (DFE)

EC-CouncilCredential ID : 246093

August 2023

Ethical Hacker

Cisco Networking Academy

February 2024

Certified Ethical Hacker (CEH)

Team Matrix - Elite HackersCredential ID : CEHE0555R

2024

Two-Day Cybersecurity Webinar

Team Matrix - Elite HackersCredential ID : W00588

2024

Advent of Cyber 2025

TryHackMeCredential ID : THM-OSWFIQHI5H

December 2025

Advent of Cyber 2024

TryHackMeCredential ID : THM-VELRIKDUH0

December 2024

Advent of Cyber 2023

TryHackMeCredential ID : THM-1VWHEQUACX

December 2023

Advent of Cyber 2022

TryHackMeCredential ID : THM-4IV4M5NO1E

December 2022

Advent of Cyber 2021

TryHackMeCredential ID : THM-DFMFLGC4TD

November 2022

Security Engineer Learning Path

TryHackMeCredential ID : THM-5JH18DHUGF

September 2023

Cyber Security 101

TryHackMeCredential ID : THM-SYIOXJCUCC

2024

Web Fundamentals

TryHackMeCredential ID : THM-XST0TK4WVT

2023

The Complete Computer Forensics Course for 2023 PRO: CFCT+

UdemyCredential ID : UC-2cf9c5a1-f200-46de-9070-700c1fe82d83

August 2023

Complete Beginner Learning Path

TryHackMeCredential ID : THM-PKNQSCBVZL

September 2023

Introduction to Cyber Security Learning Path

TryHackMeCredential ID : THM-ZWRXDM1CFM

December 2022

Pre Security Learning Path

TryHackMeCredential ID : THM-33YIURBKRK

December 2022

Introduction to Cybersecurity

Cisco Networking AcademyCredential ID : d141c2e4-3e44-4f53-b6c1-26867bcec4f4

2024

Cisco LABS Crash Course

EC-Council CodeRedCredential ID : 190307

January 2023

Android Bug Bounty Hunting

EC-Council CodeRedCredential ID : 226723

2023

SQL Injection Attacks

EC-Council CodeRedCredential ID : 171471

2023

Introduction to Dark Web, Anonymity, and Cryptocurrency

EC-Council CodeRedCredential ID : 171580

2023

Python for Absolute Beginners

EC-Council CodeRedCredential ID : 243644

2023

Ethical Hacking & Bug Bounty Course

UdemyCredential ID : UC-9007df0c-5571-4492-a66d-505db8ce6a26

2023

Web Ethical Hacking & Bug Bounty Course

UdemyCredential ID : UC-97e6656e-1856-420a-91ef-aa9d077c9d24

2023

> Education

Bachelor of Social Science (BSS), Social Work

Shahjalal University of Science and Technology (SUST)

Sylhet, Bangladesh

2022 - 2026

Higher Secondary Certificate (HSC)

Rangpur Government City College

Rangpur, Bangladesh

2017 - 2019

Secondary School Certificate (SSC)

Nilphamari Government High School

Nilphamari, Bangladesh

2011 - 2017

Never Stop Learning

Self-taught: TryHackMe, Hack The Box, CTFs & Bug Bounty

Everywhere

Present - ∞

> Projects

Open-source security tooling and research write-ups:

Coming Soon

Public security tooling and research write-ups are in the works. Follow my GitHub to see them the moment they land.

> Knowledge Bases

Here are some of my Knowledge Base resources:

OWASP Top 10

The industry-standard awareness document for the most critical web application security risks, and my baseline checklist on every engagement.

OWASP

OWASP Top 10 for LLM Applications

The reference framework for securing generative AI systems, covering prompt injection, insecure output handling, and excessive agency. Core to my AI Security work.

OWASP

MITRE ATLAS

The adversarial threat landscape for AI systems. A living knowledge base of real-world attacks against machine learning, modelled after MITRE ATT&CK.

MITRE

PortSwigger Web Security Academy

Free, hands-on labs covering every major web vulnerability class from the makers of Burp Suite.

PortSwigger

HackerOne Hacktivity

Publicly disclosed vulnerability reports, the single best resource for learning real-world bug bounty methodology.

HackerOne

TryHackMe Learning Paths

Guided, gamified paths from Pre Security through Security Engineer and AI Security, where I built my foundations as a Top 1% user.

TryHackMe

PayloadsAllTheThings

A community-curated arsenal of payloads and bypass techniques for web application security testing.

GitHub

MITRE ATT&CK

A globally accessible knowledge base of adversary tactics and techniques based on real-world observations.

MITRE

> Achievements

Platform Rankings

  • Top 1% on TryHackMeOngoing
  • Hack The Box: Active CTF PlayerOngoing
  • 38 Skill Badges across TryHackMe, HTB Academy & Cisco2021 - 2026
  • 5x Advent of Cyber Completion (2021 - 2025)Dec 2021 - Dec 2025

AI Security

  • AI Odyssey Badge, TryHackMeEarned
  • TryHackMe AI Security Learning PathIn progress
  • AI1 Professional CertificationApproaching

Community & Leadership

  • Campus Ambassador: Team Matrix - Elite Hackers (SUST)Jan 2024 - Present
  • IT Secretary: Sonchalon, SUSTMar 2024 - Present
  • Assistant Organizing Secretary: Sonchalon, SUSTMar 2023 - Mar 2024

Events & Conferences

  • Phoenix Summit Dhaka 2026: Blue Team & Red Team Days26 - 27 June 2026
  • HackerOne Bug Hunt 2026, Dhaka11 January 2026
  • Hack for Good Participant2025

Security Research

  • Web Security Researcher at HackerOneApr 2025 - Present
  • Web Security Researcher at IntigritiApr 2025 - Present
  • 26+ Cybersecurity Certifications Earned2022 - 2026

> AI Security

Offensive security is shifting from applications to the models behind them. I am building deep, hands-on expertise in AI Security so I can test the systems most teams do not yet know how to break. My web and API background transfers directly: an LLM application is still an attack surface with inputs, trust boundaries, and privilege.

Target Roles

  1. Primary target

    LLM / Generative AI Security Engineer

    The strongest fit for my background. Prompt injection, insecure output handling, RAG data leakage, and agent tool abuse are business logic and access control bugs wearing new clothes, which is exactly what I already hunt on HackerOne and Intigriti. Highest market demand and the shortest path from where I am today.

  2. Next step

    AI Red Teamer / Adversarial ML Specialist

    The natural progression once my model-internals knowledge deepens. Adversarial examples, model evasion, data poisoning, and extraction attacks build on the same red team mindset I use in CTFs, with added machine learning depth.

  3. Long term

    AI Security Researcher

    The long game. Original research, novel attack classes, and published findings. This is where the bug bounty reporting discipline I have built becomes research output that the wider community can use.

Attack Surface Focus

  • Direct & Indirect Prompt Injection
  • Jailbreaks & Guardrail Bypass
  • Insecure Output Handling
  • RAG & Vector Store Data Leakage
  • Agent Tool Abuse & Excessive Agency
  • Sensitive Information Disclosure
  • Model Denial of Service
  • Training Data Poisoning
  • Model Extraction & Inversion
  • AI Supply Chain & Plugin Security

Learning Track

  • TryHackMe AI Security Learning PathIn progress
  • AI Odyssey Badge, TryHackMeEarned
  • AI1 Professional CertificationApproaching

Frameworks & Standards

> Contact

Support Me

If my research or write-ups helped you, you can support my work through bKash Send Money.

bKash: 01774246227

Support via bKash

Opens bKash Send Money. On mobile, you can also dial *247# and send to 01774246227.