// CODENAME: HEAVEN · OFFENSIVE SECURITY ENGINE STARTING //
NISARG CHASMAWALA
NISARG CHASMAWALA
NISARG CHASMAWALA
PENETRATION TESTER · OFFENSIVE SECURITY ENGINEER · AI/ML RESEARCHER
INITIALIZING...0%
ACCESS GRANTED
[ESC] SKIP
HEAVEN ONLINE
SYS: BREACH-MODE
LOC: ENGLAND, UK
--:--:--
© 2026
SCR: 000%
CEH MASTER ■
CPENT ■ CHFI ■
ISO 27001 LA ■
NET: --ms
3D: WEBGL
FX: HYBRID
// CODENAME: HEAVEN · NISARG CHASMAWALA · ENGLAND, UK //
NISARGCHASMAWALA

Award-winning Offensive Security Engineer · Penetration Tester · Red Team Operator, holding CPENT · CEH Master · CHFI · ISO 27001 Lead Auditor among 23 credentials. Indian-origin international postgraduate, now UK-based, reading for an MSc in Cyber Security at Birmingham City University (England). I build the tooling as well as run it. As Lead Security Consultant to a £9.1M UK social housing provider, I pointed HEAVEN, my own autonomous penetration-testing framework, at their live cloud, web and internal estate: 1,800+ checks, 167 vulnerabilities triaged including an unauthenticated SQL injection candidate, and a remediation roadmap the board could actually fund. Elsewhere that work looks like CVSS 10.0 RCE chains, an AWS IAM risk analyser, peer-reviewed adversarial ML research presented at ICETCS, and 1st place at a hackathon for a privilege-escalation detection platform. I want to find the critical things before anyone else does, and leave the organisation able to defend itself after I've gone.

📝 SECURITY BLOG ↗
0
Certifications
0/10
CVSS Max RCE
0%
DDoS Detection
0
Live Projects
CEH MASTERCPENTCHFI · 90.7% ISO 27001 + 27701 LACEH PRACTICAL · 180/200 CVSS 10.0 RCE OPSRED TEAM OPS GenAI-AUGMENTED TOOLINGMSc CYBER SEC · BCU INDIAN-ORIGIN · UK BASED
SCROLL
HEAVEN
>_ ACCESSING: operator_profile.json... DECRYPTED
// 01 · ABOUT
OPERATOR PROFILEOPERATOR PROFILE
// CLASSIFIED SUMMARY
I'm Nisarg Chasmawala, codename HEAVEN: an award-winning Offensive Security Engineer, Penetration Tester and Red Team Operator working across enterprise and cloud environments. Indian-origin, now UK-based as an international postgraduate, studying for an MSc in Cyber Security at Birmingham City University, England, UK (expected March 2027). Most of what I do sits where vulnerability assessment meets AI and Machine Learning threat intelligence, and most of it involves writing the offensive tooling myself so the assessment can run on its own.

// LIVE ENGAGEMENT. As Lead Security Consultant to Nehemiah Housing Association, a £9.1M UK social housing provider holding data on 4,000 residents, I ran a full security posture assessment and Cyber Essentials v3.3 gap analysis. HEAVEN executed 1,800+ non-disruptive checks across live cloud platforms, public web applications and internal networks, surfacing 167 vulnerabilities including an unauthenticated SQL injection candidate and severe architectural exposures. NIST SP 800-115 methodology confirmed which historical fixes had actually held. The output was a finance-aligned remediation roadmap presented to the board, plus an 11-part compliance toolkit covering patch management, MFA enforcement and runbooks, written so the certification survives past the audit.

// OFFENSIVE TRADECRAFT. CPENT-certified across the full attack chain: external and internal infrastructure testing, network exploitation, Active Directory abuse, web and REST API attacks, cloud (AWS IAM) privilege escalation, OSINT, and digital forensics. In live MSc engagements I chained CVSS 10.0 RCE exploits against Redis, Openfire and Gitea, pivoting from replication abuse and admin console exploitation through Git Hooks weaponisation to system-level access.

// GenAI-AUGMENTED TOOLING. I use Large Language Models and Generative AI to design, script and ship custom offensive tools quickly. The flagship is HEAVEN, an autonomous penetration testing framework: extensible specialised modules, deterministic false-positive suppression, an AI attack-chain planner running an observe-plan-act loop with an offline credential-free fallback, a multi-feature ExtraTreesRegressor that prioritises CVSS v3.1 findings through EPSS and CISA KEV, mapping to MITRE ATT&CK, the Cyber Kill Chain and OWASP, and a PostgreSQL backend. Next to it sits HEAVEN-GeoIntel, an offline-first Next.js OSINT platform that unifies 7 identifier types, correlates bundled datasets with free-tier intelligence, and automates credential breach and info-stealer analysis with full OPSEC and no commercial API keys.

// CLEARANCE. CPENT · CEH Master · CHFI (90.7%) · ISO 27001:2022 & 27701:2025 LA · CRTOM · CLLMSP · 23 certifications in total · 8 live offensive and ML projects on GitHub. 🏆 1st Place at the BCU Cyber Security Society Hackathon (STEAMhouse, UK) · 🥈 Runner-Up at the BCU AI Hackathon 2026 · 🏅 Top 5 Finalist at Unihack 2026.
23
Certifications
8
Live Projects
R²=0.9999
IoT R² Score
10
CVSS Max
// LANGUAGES
EnglishTOEFL 91/120 · Professional
HindiNative
GujaratiNative
HEAVEN
>_ ACCESSING: capability_matrix.db... DECRYPTED
// 02 · CAPABILITIES
SKILL MATRIXSKILL MATRIX
// OFFENSIVE ARSENAL · AI/ML + FORENSICS STACK · GenAI-AUGMENTED TOOLING
HEAVEN
>_ ACCESSING: mission_log.enc... DECRYPTED
// 03 · MISSION LOG
EXPERIENCEEXPERIENCE
>_ ACCESSING: education_record.dat... DECRYPTED
// 04 · EDUCATION
ACADEMIC HISTORYACADEMIC HISTORY
>_ ACCESSING: training_records.bin... DECRYPTED
// 05 · FIELD SIMULATIONS
JOB SIMULATIONSJOB SIMULATIONS
HEAVEN
>_ ACCESSING: clearance_credentials.vault... DECRYPTED
// 06 · CLEARANCE CREDENTIALS
CERTIFICATIONSCERTIFICATIONS
HEAVEN
>_ ACCESSING: live_operations.classified... DECRYPTED
// 07 · LIVE OPERATIONS
REAL WORLD PROJECTSREAL WORLD PROJECTS
>_ ACCESSING: field_operations.enc... DECRYPTED
// 08 · FIELD OPERATIONS
ACADEMIC PROJECTSACADEMIC PROJECTS
>_ ACCESSING: research_archive.idx... DECRYPTED
// 09 · RESEARCH
MY RESEARCHMY RESEARCH
>_ ACCESSING: hackathon_victories.log... DECRYPTED
// 10 · VICTORIES
HACKATHONSHACKATHONS
HEAVEN
>_ ACCESSING: intel_dispatch.blog... LIVE
// 11 · INTEL DISPATCH
SECURITY BLOGSECURITY BLOG
A living knowledge base from the field: 40 in-depth dispatches across 6 operational tracks. Every post comes out of lab work, live engagements and proof-of-concept code, so nothing here is theory without a payload behind it. Follow the roadmap from foundational methodology all the way to frontier AI research.
40DISPATCHES
6TRACKS
LIVESTATUS
>_ INITIALISING: offensive_shell.v1.0... READY
// 12 · INTERACTIVE SHELL
LIVE TERMINALLIVE TERMINAL
heaven@kali:~$ · offensive-shell v1.0 · England, UK FULL-SCREEN FX: breach · override · nuke · ransom · matrix · type "help" for all
heaven@kali:~$
HEAVEN
>_ ACCESSING: operator_contact.secure... DECRYPTED
// 13 · ESTABLISH CONNECTION
CONTACTCONTACT
cat /root/heaven/operator.profile
# ══ CLASSIFIED OPERATOR PROFILE ══
ALIAS="HEAVEN"
NAME="Nisarg Chasmawala"
ROLE="Offensive Security Engineer | Penetration Tester | Red Team Operator"
CLEARANCE="CEH_MASTER | ISO_27001 | CPENT | CHFI"
BASE="England, UK"
EDU="MSc Cyber Security, BCU (Expected 2027)"
GOAL_1="Secure pentest placement / full-time red-team role"
GOAL_2="Architect AI-driven autonomous pentesting frameworks"
GOAL_3="Global Cybersecurity Adviser · shape intl. policy"
STATUS="ACTIVELY_SEEKING_OPPORTUNITIES"