Web Application VAPT
Authentication, authorization, session management, input validation, injection, XSS, CSRF, SSRF, business logic, and security misconfiguration.
> scope --primary
I test web applications, APIs, and mobile applications to uncover exploitable vulnerabilities, validate real-world impact, and provide actionable remediation guidance.
A working security practice
I approach security assessments as an investigation: start with reconnaissance, understand how the application behaves, then test the boundaries where trust can fail.
My work combines manual validation, authorized exploitation, evidence collection, risk assessment, and professional reporting. The result is a finding a development team can reproduce, prioritize, and fix.
Application security / VAPT
Focused testing across the application layers that carry identity, data, and business value.
Authentication, authorization, session management, input validation, injection, XSS, CSRF, SSRF, business logic, and security misconfiguration.
Authentication, authorization, BOLA / IDOR, rate limiting, input validation, API abuse, sensitive-data exposure, and business logic vulnerabilities.
Android assessment, static and dynamic analysis, API testing, authentication, local data storage, reverse engineering, and runtime instrumentation.
Asset discovery, subdomain enumeration, endpoint discovery, technology fingerprinting, exposure analysis, and attack-surface mapping.
Reproduction, exploit validation, impact assessment, evidence collection, and severity classification grounded in observed behavior.
Executive summary, technical findings, proof of concept, business impact, severity, remediation, and retest validation.
Independent vulnerability research
Selected responsible-disclosure work and attack-surface research, presented as concise security case studies.
Recognised after responsibly disclosing validated security findings to help strengthen platform security.
Reported a validated vulnerability through a responsible disclosure programme.
Responsible disclosure of a production mobile-app security issue involving sensitive-data exposure.
Independent assessment of web applications and APIs, with emphasis on reconnaissance, misconfiguration, and access-control issues.
A finding validated by the Infosec team through responsible disclosure.
A repeatable process
Map the attack surface and identify exposed assets.
Discover endpoints, technologies, parameters, APIs, and authentication boundaries.
Systematically test security controls and application behavior.
Manually reproduce and validate vulnerabilities.
Demonstrate realistic impact within authorized testing boundaries.
Document evidence, severity, business impact, and remediation.
Verify that remediation actually resolves the vulnerability.
Applied security work
Gaining full-time, hands-on office experience alongside security professionals on live client engagements and day-to-day Information Security operations.
Conducting independent security research across web applications and APIs through ethical, coordinated disclosure programmes.
Contributed to Flutter-based mobile application development within an AI-driven communication platform.
Supporting evidence
A record of completed certifications and technical learning. The practice remains VAPT-led.
SOC Level 1 · SOC Level 2 · Security Engineer · DevSecOps · Jr Penetration Tester · AI Security · Web Fundamentals · Pre Security · Advanced Endpoint Investigations
Certified Ethical Hacker (CEH) · Python Essentials 1 · Python Essentials 2
Cloud Security · Compute · Introduction to Cloud
Certified Red Team Operations Management (CRTOM) · Foundations of Log Analysis for Cyber Defense · Certified LLM Security Expert (CLLMSE)
SQL Injection Attacks — Code Red · Python Programming Fundamentals · Fundamental Cloud & DevOps
Tools serve the method
Burp Suite · OWASP ZAP · Nmap · Nuclei · ffuf · Gobuster · SQLmap · Metasploit · Nikto · WPScan
Subfinder · Amass · httpx · Katana · gau · Wayback · Arjun
MobSF · Frida · Objection · JADX · Apktool · ADB
Python · Bash · Linux
SOC / Threat Detection · Cloud Security
Working with teams
A short briefing on how I approach assessments and responsible disclosure.
Scope alignment, reconnaissance, testing, evidence collection, risk context, and a clear report with practical remediation guidance.
By manually reproducing the behavior, documenting evidence, assessing realistic impact, and communicating the conditions required to reproduce it.
Yes. I have reported validated findings through coordinated disclosure programmes and can help teams understand, reproduce, and remediate issues.
Education
B.A. English Language and Literature, General · 7.81 CGPA
Secondary Education (ICSE) and Higher Secondary Education (ISC), Arts