Skip to content
View SagarBiswas-MultiHAT's full-sized avatar
🇧🇩
ʟᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴛʀɪx ᴡʜᴇʀᴇ 0 & 1 ᴛᴜʀɴs ᴛᴏ ɢᴏʟᴅ. ᴄᴏᴅᴇ ɪꜱ ᴡᴇᴀᴘᴏɴ, ᴄʜᴀᴏꜱ ɪꜱ ᴀʀᴛ.
🇧🇩
ʟᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴛʀɪx ᴡʜᴇʀᴇ 0 & 1 ᴛᴜʀɴs ᴛᴏ ɢᴏʟᴅ. ᴄᴏᴅᴇ ɪꜱ ᴡᴇᴀᴘᴏɴ, ᴄʜᴀᴏꜱ ɪꜱ ᴀʀᴛ.

Highlights

  • Pro

Block or report SagarBiswas-MultiHAT

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Sagar Biswas: security engineer, full-stack developer, and founder of MultiHAT, based in Dhaka, Bangladesh

Build status   License   Last commit  

e-Portfolio   Profile views   GitHub followers   GitHub stars  

Field File

I work both sides of the same problem: breaking web applications to understand how they fail, then building and hardening them so they don't. That split is the whole job (web application security and ethical hacking on one side, full-stack engineering on the other), and I run both under MultiHAT, the software and security studio I founded in Dhaka, Bangladesh.

Sagar Biswas: Operator Field Photo

Callsign Sagar Biswas · SagarBiswas-MultiHAT
Role Founder, MultiHAT · Web Application Security Engineer · Full-Stack Developer · AI Integrator
Studying BSc in Computer Science & Engineering, American International University-Bangladesh (AIUB)
Stack Python, C/C++/C#, Bash · Next.js, React, Node.js, NestJS · PHP · Docker
Focus Web app penetration testing, OSINT, and production-grade engineering with Next.js/NestJS
Status Open to security-tooling collaborations and technical roles

The long-form version of this (verified evidence, no inflated metrics) lives in the operator dossier.


Live Systems

Production work under the MultiHAT name.

System What it is Link
MultiHAT Software, AI & security engineering studio: the agency behind everything here multihat.dev
Operator Dossier Recruiter-first security & software portfolio: evidence across Assess, Harden, Govern sagarbiswas-multihat.github.io
MultiHAT Academy Full-stack e-learning platform turning technical notebooks into verifiable micro-credentials (Next.js 15 + NestJS 11) academy.multihat.dev
Sydney Wheels & Tyres Client project: premium marketing site with local business schema, built for SEO discoverability sydneywheelsandtyres.com.au

Public Ops Ledger

Open-source tools, all client-side or self-hosted where it matters.

Project Description Link
PromptVault Offline-first, PIN-protected library for AI prompts with a built-in AI librarian, categories, and fill-in-the-blank variables promptvault.multihat.dev
PhishGuard A 10-second phishing-detection game powered by a dual-AI consensus engine (OpenRouter + Groq) generating unique scenarios in real time phishguard.multihat.dev
WiFi-QR-Generator Browser-only Wi-Fi QR codes: WPA/WPA2/WEP, hidden SSIDs, PNG/SVG export, nothing leaves the device wifi.multihat.dev/qr
Password-Strength-Checker Accessible, fully offline entropy estimator with weak-pattern detection and a built-in generator psc.multihat.dev
SharpLink-URL-Allies Flask URL shortener with custom aliases, expiration, SQLite persistence, and a REST API sharplink.onrender.com

More on GitHub: github.com/SagarBiswas-MultiHAT


Field Manuals & Research

Longer-form technical writing and study vaults: recent entries cover post-quantum cryptography and RSA's exposure to Shor's algorithm, mapping real attacks to OSI layers, and a complete Google Dorks handbook for OSINT.

→ Browse all field manuals · → Read the research transmissions


Clearance

Verified credentials

Certified Phishing Prevention Specialist (CPPS) Track: Social Engineering Defense

Certified Phishing Prevention Specialist (CPPS)

Certified Red Operations Certificate Track: Adversarial Operations

Certified Red Certificate

Full provenance and verification links: → Credential Vault


Now

  • Active: sharpening offensive/defensive web security instincts through PortSwigger Academy, TryHackMe, and Hack The Box
  • Building: production systems in Next.js and NestJS under the MultiHAT banner
  • Open to: open-source collaboration on cybersecurity and web-security tooling
  • Ask me about: web app security, OSINT, Linux tooling, or the Next.js/NestJS stack

GitHub Analytics

Status Most Used Languages
Sagar Biswas's GitHub stats Most used languages
Weekly Streak
GitHub streak stats
GitHub Activity
Contribution activity graph


Direct Channel

LinkedIn   YouTube   X

Facebook Community   Email

Founder-to-founder, recruiter, or fellow researcher: the fastest path in is email. For scope-defined security work, see the Responsible Disclosure note below.


Responsible Disclosure

If you find a security issue in any project here, report it privately first: sagarbiswas@multihat.dev or via Facebook, with enough detail to reproduce it. Please hold public exploit details until we've agreed on a remediation timeline (standard coordinated disclosure, nothing more).


Agency · Operator Dossier · Field Manuals · Résumé · AIUB CyberSecurity & Programming Society

© 2026 Sagar Biswas · MultiHAT Field Node // ᴄᴜʀɪᴏꜱɪᴛʏ ɪꜱ ᴍʏ ᴘᴀʏʟᴏᴀᴅ

Pinned Loading

  1. The-BlackHAT-roadmap The-BlackHAT-roadmap Public

    The definitive zero-to-operator offensive engineering curriculum and operational security compendium. From C, Assembly, and kernel exploitation to modern EDR evasion (sleep obfuscation, indirect sy…

    C 9 1

  2. awesome-cybersecurity-paths awesome-cybersecurity-paths Public

    A comprehensive cybersecurity career roadmap and handbook covering 35 roles across Offensive, Defensive, and GRC, 100+ tools, cert paths, and 10 architectures.

    13

  3. awesome-cybersecurity-books awesome-cybersecurity-books Public

    A curated collection of 70+ free cybersecurity books organized by domain and difficulty (🟢 Beginner → 🟡 Intermediate → 🔴 Advanced). Structured learning paths for ethical hacking, penetration testin…

    46 4

  4. A-Pythonic-Keylogger A-Pythonic-Keylogger Public

    Lightweight Python keylogger featuring real-time keystroke interception, instant file backup, and automated SMTP email dispatch with 3x retry logic. Includes ESC-key log sanitization and dual OS au…

    Python 29 2

  5. penetration-testing-roadmap penetration-testing-roadmap Public

    🎯 A structured 60-week penetration testing curriculum with 500+ free TryHackMe labs, OWASP Top 10 deep dives, tool mastery guides, and certification roadmaps. Three learning paths from zero to prof…

    53 6

  6. Impress-Crush-Cpp-ASCII Impress-Crush-Cpp-ASCII Public

    C++ console application that converts images into detailed ASCII art by mapping pixel brightness and local shapes to characters. Supports gamma correction, filtering, multi-region shape matching, r…

    C 31