Portfolio · Uzbekistan

Kamron Saparbaev

composition · security · engineering · film · photography.

  • Music
  • Pentesting
  • Engineering
  • IoT
  • Filmmaking
  • Photography
  1. 01music school learning piano
  2. 02Stepped away from formal music, kept it quietly
  3. 03Discovering programming in high school
  4. 04Obsessed with offensive security & CTFs
  5. 05Building backend tools, NLP pipelines, open source
  6. 06Submitting bug bounty reports to major platforms
  7. 07Earning CRTOM & offensive security certifications
  8. 08Publishing ShadowImageExec research with MITRE ATT&CK
  9. 09Returning to piano — composing original instrumentals
  10. 10Shooting architecture, portraits, cinematic frames
  11. 11Directing short films and editing in DaVinci Resolve
  12. 12Preparing for university, undergraduate in Software Engineering
Kamron Saparbaev

“Do not follow where the path may lead. Go instead where there is no path and leave a trail.”

— Ralph Waldo Emerson

Composer, software engineer, cybersecurity researcher, filmmaker, and photographer. Music taught me emotion. Code taught me systems. Security taught me to question everything. Film taught me to see.

Principles I build by

Philosophy

01

Show, don't tell

A working prototype beats a slide full of promises. Making is my way of storytelling — from compositions to security research to code.

02

Cross every boundary

Music, code, security, film — each discipline feeds the others. The best ideas live at the intersection, not inside one box.

03

Leave a trail

Build in public, share your research, and create paths where none existed before. Don't wait for permission to start.

Academic background

Education

01

Public School №58

Secondary Education · General Education

Sep 2021Jun 2026

Grade 9: GPA 3.73 / 4.0 · Grade 11: GPA 3.75 / 4.0

  • National English Exam (CEFR, Uzbekistan) – B2
02

Private PDP School

Certificate in Backend Development · Web Development · Python · Django · SQL · APIs

Sep 2024Jun 2025

Grade 10: GPA 3.91 / 4.0

  • Completed a full-year certificate program focused on backend development
  • Gained hands-on experience with Python, SQL, Django, and Django REST Framework (DRF)
  • Built full backend architectures, implemented REST APIs, and managed relational databases
03

Children's School of Music and Arts No. 4

Music Theory and Composition · Classical Music · Piano

Jan 2015May 2017

  • My path as a pianist in 2015–2017

Who I am

About

GitHubOpen-source projects & research
HackerOneBug bounty & security reports
Red Team LeadersCRTOM & offensive AI certs
IBM SkillsBuildCybersecurity fundamentals
SoundCloudOriginal compositions
Name
Kamron Saparbaev
City
Tashkent, Uzbekistan
Languages
Uzbek · English · Russian · Turkish
Philosophy
Leave a trail
Main Idea of Life
Build across disciplines · leave a trail
Music
Piano · composition · SoundCloud originals
Security
CRTOM · HackerOne · Red Team research
Software Engineering
Python · C++ · backend · NLP · AI pipelines · etc.·
Film
DaVinci Resolve · direction · cinematography · etc.
Photography
Architecture · Portraits · Cinematic frames
Sports
Five years of competitive swimming · competitive chess · etc.

Proof, not promises

Selected Work

All projects

  • PentestingResearch

    ShadowImageExec

    Experimental concept exploring execution potential of commands through downloaded media-related content.

  • PentestingPentest

    USB Steal

    USB-based data extraction and security testing tool.

  • PentestingBug Bounty

    HackerOne

    Reports on programs including Coinbase, Figma, and Kahootz VDP.

  • PentestingHTB

    Hack The Box

    Offensive security lab achievements and continuous practice.

  • PentestingCert

    Ethical Hacking

    Certified in ethical hacking and offensive security fundamentals.

  • EngineeringData

    CEFR Dataset

    Language proficiency dataset for CEFR-level classification and NLP training.

  • EngineeringGenerator

    CEFR Dataset Generator

    Automated pipeline for generating and labeling CEFR training data.

  • EngineeringEdTech

    MasterTeach

    Teaching platform exploring language learning through films and subtitles.

  • EngineeringMobile

    PhramGo

    Pharmacy and medication management application.

  • EngineeringData

    DataForge

    Data processing and transformation toolkit for structured datasets.

  • FilmmakingIn Progress

    Short Film

    Psychological thriller short — pre-production and visual development.

  • FilmmakingEssay

    Visual Essay

    Cinematic exploration of mood, atmosphere, and narrative tension.

  • FilmmakingFragment

    Documentary Fragment

    Observational piece capturing place, detail, and human rhythm.

Original compositions

Music

The Greatest Gift of My Childhood cover art

The Greatest Gift of My Childhood

Original · Piano

0:00
Meaningless cover art

Meaningless

Original · Piano

0:00
Enough cover art

Enough

Original · Piano

0:00
The Stain on the Window No.1 cover art

The Stain on the Window No.1

From the Window series

0:00
The Stain on the Window No.2 cover art

The Stain on the Window No.2

From the Window series

0:00

Frames & atmosphere

Photography

Security · engineering · proof

Research & Credentials

  • Certified Red Team Operations Management (CRTOM)
    Dec 2025certification
    Certified Red Team Operations Management (CRTOM)

    Red Team Leaders

    Passed the full exam covering red team operations management and leadership.

    Cert
  • Offensive Agent AI Course
    Dec 2025certification
    Offensive Agent AI Course

    Red Team Leaders

    Completed coursework on AI-driven offensive security techniques and agent workflows.

    Cert
  • Cybersecurity Fundamentals
    Jul 2025certification
    Cybersecurity Fundamentals

    IBM SkillsBuild

    IBM-issued credential covering core cybersecurity principles and defensive fundamentals.

    Cert
  • Ethical Hacker
    Jul 2025certification

    Ethical Hacker

    Cisco Networking Academy

    Completed the Cisco Networking Academy Ethical Hacker program.

    Cert
  • Ethical Hacker — Course Update
    Jul 2025certification

    Ethical Hacker — Course Update

    Cisco Networking Academy

    Updated completion certificate for the Ethical Hacker specialization track.

    Cert
  • Ethical Hacking Participation
    2025hackathon
    Ethical Hacking Participation

    Unstop

    Hackathon participation certificate in ethical hacking and offensive security.

    Hackathon
  • CS107: C++ Programming
    Jul 2025course

    CS107: C++ Programming

    Course Certificate

    40 hours · Score 92.50 — structured C++ programming fundamentals and practice.

    Course
  • CS105: Introduction to Python
    Jul 2025course

    CS105: Introduction to Python

    Course Certificate

    36 hours · Score 70.20 — Python fundamentals, syntax, and applied exercises.

    Course
  • Coinbase API — Arbitrary Currency Values
    Mar 2025report
    Coinbase API — Arbitrary Currency Values

    Coinbase · #3050509

    Reported that the Coinbase API accepts arbitrary currency values, enabling potential data manipulation. Closed as Informative.

    HackerOne
  • Figma Subdomain Takeover — S3 Misconfiguration
    Mar 2025report
    Figma Subdomain Takeover — S3 Misconfiguration

    Figma · #3053152

    Demonstrated subdomain takeover on support-chat.figma.com via AWS S3 bucket misconfiguration. Closed as Informative after thorough investigation.

    HackerOne
  • Kahootz VDP — CAPTCHA Bypass
    Mar 2026report
    Kahootz VDP — CAPTCHA Bypass

    Kahootz · #3594623

    Client-side CAPTCHA answer exposure on vdp.kahootz.com/system/forgotPassword enabling automated abuse. Closed as Informative.

    HackerOne
  • Kahootz VDP — Internal IP Disclosure
    Mar 2026report
    Kahootz VDP — Internal IP Disclosure

    Kahootz · #3593889

    Internal IP disclosure via Served-By meta tag on kahootz.com leading to infrastructure reconnaissance. Closed as Informative.

    HackerOne
  • MITRE ATT&CK — ShadowImageExec Correspondence
    Nov 2025research
    MITRE ATT&CK — ShadowImageExec Correspondence

    MITRE ATT&CK Team

    Submitted ShadowImageExec research on steganographic payload delivery and automated execution. Added to MITRE's research queue with technical discussion on T1001.002 mapping.

    Research

Let's build something

Contact

Currently

Available for collaborations

Cybersecurity research · Software engineering · Music composition · Visual storytelling

Open to

  • Security research & bug bounty
  • Backend & AI engineering
  • Music composition
  • Film & photography projects