My Story

2024:

Playing Minecraft, installing more and more mods, with the goal of turning minecraft into “boss rush” game. However, as I find more mods, I keep looking for another that I would like more, that would make the game more of what I want.

It’s around April-May 2024, and I decide that I will create my own minecraft mod to make the game look how I want it to - fast forward, I find out that I gotta learn JavaScript to create a mod, so I decide that okay, I’ll learn JavaScript. However, almost at the same time, I start seeing some cybersecurity-related content on one particular social platform - most of that content was by an account nameded “LetsDefend”, and then another interest starts coming up in my head and I think “Maybe I should learn Cybersecurity?” - I spend a bit of time thinking it and discussing with other people, and one day I’m just walking back home, again talking how I want to learn cybersecurity - at one point in that conversation, I start feeling something that you cannot describe in words - it was some totally other kind of feeling, I felt as if it was my destiny to get into Cybersecurity.

So, I decide to go and check what that “LetsDefend” is - it turns out that it’s a platform to learn Cybersecurity, covering both basics of Cybersecurity and Blue Teaming.

Then I go and register on LetsDefend, and I start studying Cybersecurity on LetsDefend for hours almost every day - some days I spend 6 hours, some days I spend 3, some days I spend 2. On LetsDefend, I then finish some of their “Cybersecrutiy for Students”-related modules, then fully finish the SOC Analyst and Malware Analyst paths.

At the same time, I am watching Cybersecurity-related content on YouTube, a ton of it, as much as it can. The content I watched on YouTube was mostly red-team related, watching which I decide to transition into red teaming as well, it seems way more interesting for me.

So how do I get into Red Teaming 🌹? I go to TryHackMe, register there, take a look at their platform and decide to start there. Fast forward to July 2024, I finish some of THM’s path available (only red-team related modules). Learn something new, but alongside make one very huge mistake - I rush to finish everything, at some point I stopped even wanting to get knowledge but wanted to complete just another path faster - this is a critical mistake. Remember - patience is key and is one of the most important things in life.

Then it’s August 2024, I decide that now I’m good enough to go and do bug bounty 😌 I was wrong lol. Report 4 findings on HackerOne - all informational. Bck then I did not think: “What is the impact of this vulnerability?” Also, in August, I had some hard time, so I asked my friend who was working as an updater in a logistics company to help me get there as well - my friend helped me, I was invited to an interview at that company, which I thankfully passed succesfully, and was given a 2-week internship.

In logistics, I worked as an updater as well. I worked in that company for 7 days, starting to totally hate the job. That job also felt so heavy for me, that I just left it on the 7th day. However, thankfully even there I took advantage of an opportunity that was present - So there was a guy who had created an internal website for the company, and you know he looked like someone who does not like to communocate. I thought for some days, and finally decided to ask him if he wants the company’s internal website tested for security - he was so happy to agree, I did not expect it at ALL! So if I recall correctly I spent like 3 or 4 days on that assessment, finding SQL Injection, XXE, SSTI - that was my 1st ever penetration test.

After I left the logistics I understood something - I understood that I have to do something with my life, that I gotta start moving, so I decided t go serious in the field I was already one foot in - to go and get some certs in Cybersecurity, namely: eJPT and eWPT - I was planning to get just those two and that’s it. So I go there an buy the INE’s bundle that gave you both eJPT 2 exam attempts + access to eJPT’s course, and before I stat (it’s already September), one day I was using my phone to switch between two of my accounts, and I find my first valid bug on a huge platform - 2FA Bypass in its mobile version - I go and report it, to which the company ghosts me for a year, including all of my follow ups, and then just closes it without traiging anything (it wasn’t HackerOne! It was that platform’s own bug bounty triage platform). Now back to eJPT - as October 2024 begins, I start studying pentesting through eJPT’s course - it took me 3 months (October, November, December). I was studying the material with such interest - you know, how when you just start to learn cybersecurity you keep having this though “It is that easy??!” - it kept coming to me often too! Throughout the course, I keep taking notes, switch and discover newer applications for note-taking, and end up with Obsidian.

2025:

I pass eJPT, then rest a bit and start eWPT if I’m not mistaken in February.

A kind of situation happened when I bought eWPT - so I did not take a serious look and thought that $499 is both the course and 2 exam attempts, however it turns out that it’s just the exam attempts that I bought, and that the course + exam attempts was a separate bundle. Thankfully, it happened there, not at eCPPT - as I believe it’d be extremely challenging to prepare for eCPPT from other resources, whereas for eWPT you easily can. So I prep for eWPT using free resources, mainly PortSwigger Academy and YouTube - learn about XXE, IDOR, and other kinds of web vulns. Finally, it’s march - I go into the exam, pass it and think that now that’s it, I won’t do a new cert, that I am fully accomplished 😂

Then April comes - a guy texts me on LinkedIn, asking me if I’d be interested in a Paid Internship - I say yes, and a bit later I am invited to a an interview at that company, which I then leave on 4th week of working there, our paths did not align - what I liked at that company the most were its people - they felt really kind, they were good as humans.

After I leave the company I was working at in April, I went back to bug bount, finding 3 valid bugs - 2 of them were the coolest (HTML Injection and Reflected XSS). Then, as I already had 2 certificates from INE, I started thinking about eCPPT (I was already thinking about it in April as an intern at that company), so in May of 2025, I bought the bundle which included both the eCPPT course and 2 exam attempts, thankfully, just 1 attempt was enough.

Through eCPPT course, I learnt lots of new concepts, techniques, and topics - Offensive PowerShell, Active Directory Pentesting, Privilege Escalation techniques, Lateral Movement, etc. I prepared for eCPPT thoroughly, kept taking notes, solving the labs and CTFs present in the course, and so on. As I was again having some hard time in summer 2025, I was trying to spend as much time as it can on eCPPT’s course. Also, by late June/early July, I created my own GitHub and Medium pages, and created my first repos/posts. So then it’s July 11th - I start the exam, and finish it when like 3 hours were remaining. Was the exam tough? Definentely - check out my eCPPTv3 review here.

After passing eCPPT, and a bit before it as well, I started applying for jobs both inside and outside Uzbekistan (remote globally), I also started posting on GitHub, Medium, LinkedIn. First posts weren’t so fire, and it’s okay - I was just a beginner in posting, some of those repos, posts and stories are deleted now for good. I applied to more then 30 jobs overall, and heard back from 3, and finally in August I So I was invited to an interview to one of the best cybersecurity companies in Uzbekistan - some of the best cybersecurity specialists/experts interviewed me, asking me professional questions around different topics. Thankfully at that interview itself in my gut I felt as I have successfully passed, and even more thankfully that feeling was correct - a bit later, I get a happy follow-up, inviting me to work there, and I of course accept immediately.

At first I was feeling like a junior at that company, and by my experience you’d say that’s how it should be - maybe you are right. Most importantly, I had a great mentor there who was always eager to respond to any of my question, review and recommend improvements for my reports, and so on.

2026:

I keep working there, producing great results and finding many, many great findings - I’ve been there for almost a year as of writing this (July 16th, 2026), and stopped feeling like a Junior after April, and started feeling like a part of the team after getting my COAE.

In May of 2026, I participated as a staff member in one wonderful event organized by the company I work in and 2 others, I had developed one of the web tasks. The atmosphere of the event, people, and everything there was amazing, 10/10.

Furthermore, I did not abandon bug bounty - I found an LLM Sensitive Information Disclosure: after achieving prompt injection, the LLM leaking the full JSON descriptions and names of the tools it used. Furthermore, I also found a Prompt Injection on one very popular mobile app.

In between, I also got COAE - started the AI Red Teamer path on 6th of April, finished by 3rd or 4th of June, then took the exam on the 5th of June, finished on the 10th, and waited for the results until the 29th of June - what I was surprised with is that Pandast0rm himself review my report (if I ain’t mistaken he’s the guy behind some of the modules in the AI Red Teamer path on HackTheBox).

COAE is my first expert-level certificate, and its exam is truly challenging. I cannot share what was inside the exam, but I can share my experience: So, day 1, thankfully I loot some flags, but can’t get one I am trying to. At some point this little voice starts coming to me and saying “Give up” - Thankfully, I refuse. I go and get enough sleep, come back and loot some more flags, including that one, just in an hour. Then, I am just a flag away from passing, but this last one was a little tricky, man! I spent like 1.5 days on it - that little voice again kept coming, saying “Give up” - Thankfully, I refused again, got that flag on that day and sat to write a report - I used SysReptor, and here is how I did it (it took me 2 days to write it):

  • 2 hours for report
  • 1 hour to rest

And repeat - for me it worked pretty well, this is not a recommendation but just my personal experience.

Key advice: Never give up. Whether you are in cyber or outside of it. I think it’s one of the most important things in life. Whether you are solving a lab or passing the exam, always push past that “I can’t” - usually you are way stronger than you think you are. Train your mind. Mindset is everything. Remember, hard is just another word for achievable.