I work both sides of the same problem: breaking web applications to understand how they fail, then building and hardening them so they don't. That split is the whole job (web application security and ethical hacking on one side, full-stack engineering on the other), and I run both under MultiHAT, the software and security studio I founded in Dhaka, Bangladesh.
| Callsign | Sagar Biswas · SagarBiswas-MultiHAT |
| Role | Founder, MultiHAT · Web Application Security Engineer · Full-Stack Developer · AI Integrator |
| Studying | BSc in Computer Science & Engineering, American International University-Bangladesh (AIUB) |
| Stack | Python, C/C++/C#, Bash · Next.js, React, Node.js, NestJS · PHP · Docker |
| Focus | Web app penetration testing, OSINT, and production-grade engineering with Next.js/NestJS |
| Status | Open to security-tooling collaborations and technical roles |
The long-form version of this (verified evidence, no inflated metrics) lives in the operator dossier.
Production work under the MultiHAT name.
| System | What it is | Link |
|---|---|---|
| MultiHAT | Software, AI & security engineering studio: the agency behind everything here | multihat.dev |
| Operator Dossier | Recruiter-first security & software portfolio: evidence across Assess, Harden, Govern | sagarbiswas-multihat.github.io |
| MultiHAT Academy | Full-stack e-learning platform turning technical notebooks into verifiable micro-credentials (Next.js 15 + NestJS 11) | academy.multihat.dev |
| Sydney Wheels & Tyres | Client project: premium marketing site with local business schema, built for SEO discoverability | sydneywheelsandtyres.com.au |
Open-source tools, all client-side or self-hosted where it matters.
| Project | Description | Link |
|---|---|---|
| PromptVault | Offline-first, PIN-protected library for AI prompts with a built-in AI librarian, categories, and fill-in-the-blank variables | promptvault.multihat.dev |
| PhishGuard | A 10-second phishing-detection game powered by a dual-AI consensus engine (OpenRouter + Groq) generating unique scenarios in real time | phishguard.multihat.dev |
| WiFi-QR-Generator | Browser-only Wi-Fi QR codes: WPA/WPA2/WEP, hidden SSIDs, PNG/SVG export, nothing leaves the device | wifi.multihat.dev/qr |
| Password-Strength-Checker | Accessible, fully offline entropy estimator with weak-pattern detection and a built-in generator | psc.multihat.dev |
| SharpLink-URL-Allies | Flask URL shortener with custom aliases, expiration, SQLite persistence, and a REST API | sharplink.onrender.com |
More on GitHub: github.com/SagarBiswas-MultiHAT
Longer-form technical writing and study vaults: recent entries cover post-quantum cryptography and RSA's exposure to Shor's algorithm, mapping real attacks to OSI layers, and a complete Google Dorks handbook for OSINT.
→ Browse all field manuals · → Read the research transmissions
Verified credentials
Certified Phishing Prevention Specialist (CPPS) Track: Social Engineering Defense
Certified Red Operations Certificate Track: Adversarial Operations
Full provenance and verification links: → Credential Vault
- Active: sharpening offensive/defensive web security instincts through PortSwigger Academy, TryHackMe, and Hack The Box
- Building: production systems in Next.js and NestJS under the MultiHAT banner
- Open to: open-source collaboration on cybersecurity and web-security tooling
- Ask me about: web app security, OSINT, Linux tooling, or the Next.js/NestJS stack
Founder-to-founder, recruiter, or fellow researcher: the fastest path in is email. For scope-defined security work, see the Responsible Disclosure note below.
If you find a security issue in any project here, report it privately first: sagarbiswas@multihat.dev or via Facebook, with enough detail to reproduce it. Please hold public exploit details until we've agreed on a remediation timeline (standard coordinated disclosure, nothing more).
Agency · Operator Dossier · Field Manuals · Résumé · AIUB CyberSecurity & Programming Society
© 2026 Sagar Biswas · MultiHAT Field Node // ᴄᴜʀɪᴏꜱɪᴛʏ ɪꜱ ᴍʏ ᴘᴀʏʟᴏᴀᴅ




_page-0001.jpg)
