Computer Engineering student with a software development background, experienced in web application security and vulnerability assessment through hands on projects and security research. Comfortable working across development and security layers, with a practical approach to identifying issues and improving application security.
Strong grounding in Python, data structures, networking, and secure software development practices.
Independent Security Researcher (Hacker One & Responsible Disclosure X (formerly Twitter)
Remote
Conducted real-world web application security testing, identifying vulnerabilities such as session token exposure, Open Redirect. Submitted structured bug bounty reports on Hacker One, including security report for X (formerly Twitter). Strengthened understanding of vulnerability severity assessment by mapping findings to CIA triad, OWASP Top 10, and real world exploitation scenarios.
Indian Cyber Club Technologies
Identified missing security headers leading to clickjacking and client side attack vectors. Audited Word Press applications for outdated plugins, exposed endpoints, weak access controls, and configuration weaknesses.
Shadow Fox
Remote
Performed hands on cybersecurity tasks including port scanning, directory enumeration, and network traffic analysis using Nmap, Gobuster, and Wireshark. Worked on practical penetration testing exercises involving Metasploit, Vera Crypt, PE Explorer, and wireless security in controlled lab environment.
Completed advanced security challenges on Try Hack Me and testasp.vulnweb, strengthening skills in vulnerability assessment, exploitation, and security reporting.
Bachelor of Engineering
CGPA: 7. Relevant Coursework: Data Structures and Algorithms, Operating Systems, Computer Networks, Distributed Systems
Performed security assessment of Word Press based website and identified multiple security issues including outdated plugins, exposed endpoints, weak access controls, missing security headers, and clickjacking risks. Conducted PHP and Word Press security analysis by researching CVE references, validating potential impact, and preparing detailed vulnerability reports with remediation recommendations.
Created follow up security recommendations and incident response guidance after observing signs of compromise, highlighting the importance of timely vulnerability remediation.
Submitted vulnerability report on Hacker One identifying potential session token exposure through URL query parameters and analyzed the risk of session hijacking. Gained practical experience in vulnerability validation, POC creation, and improving security report quality based on triage feedback.
Built an automated bug bounty hunting agent for Kali Linux that performs end to end security assessments including subdomain discovery, crawling, vulnerability scanning, AI-based analysis, and report generation. Developed modular security engine integrating 17+ open-source tools such as Subfinder, Nuclei, SQLMap, Katana, FFUF, and Nmap for reconnaissance and vulnerability detection.
Implemented a multi-provider AI analysis system supporting Ollama, OpenAI, Claude, Gemini, Groq, and Deep Seek for finding validation, attack chain analysis, severity estimation, and automated bug bounty report creation. Designed a Flask-based SOC-style dashboard with Web Socket communication for real-time scan updates, AI chat, findings tracking, and automated security reporting.
Built an AI-powered network intrusion detection system that captures live traffic, analyzes packet behavior, detects anomalies, and visualizes security events through a real time SOC dashboard. Developed a deep learning anomaly detection pipeline using Autoencoder models trained on CICIDS 2017 dataset to identify abnormal network patterns and classify potential attacks.
Implemented real time packet monitoring, feature extraction, threat scoring, severity classification, and automated security event logging for continuous network analysis and remote access support using Cloudflare Tunnel.
Developed Python based security tool to demonstrate and analyze IDN homograph attacks by detecting visually similar Unicode characters used in malicious domain impersonation. Implemented domain character analysis logic to identify suspicious Cyrillic and Unicode substitutions that can bypass human visual inspection.
Built command line security utility with automated URL comparison and detection features to help users understand phishing risks caused by lookalike domains.
(CEH v 13 – AI)