π Security Researcher | Penetration Tester | Web Security | Active Directory Security | AI & LLM Security
I'm a cybersecurity professional with 3.5+ years of experience in offensive security and security research.
My interests include penetration testing, vulnerability research, exploit development and red teaming.
Currently building security tools, researching vulnerabilities, contributing to open-source security projects, and documenting my work.
π Security Research Engineer
π― Penetration Tester
π€ AI / LLM Security
π₯ Vulnerability Research & Exploit Development
π§ Linux & Active Directory
π οΈ Security Tool Development
π Continuous Learner
- π‘οΈ OSCP Certified
- π Interested in Web, API, Network & Active Directory Security
- π€ Experience with AI Security, Adversarial Testing & LLM Assessments
- π₯ Published conference/journal papers, vulnerability research and exploit PoCs
- π Open-source security contributor
- βοΈ Technical writer covering cybersecurity and vulnerability research
A collection of Python/Bash utilities for automating common penetration testing and reconnaissance tasks.
- Linux Pentesting Toolkit
- Helper scripts for automating Linux pentesting tasks
- Bash
A collection of vulnerability research and proof-of-concept exploit development projects.
-
CVE-2026-3576 β Planyo Wordpress Plugin
- Server-side request forgery leading to local file inclusion
- Python β’ PHP β’ Docker
-
- Arbitrary file write leading to remote code execution
- Python β’ PHP β’ Docker
-
- Broken access control leading to mass user information disclosure
- Python β’ JavaScript β’ Docker
A list of my contributions to open source security tools.
- Metasploit
- Exploit module for local file inclusion vulnerability in a WordPress plugin (CVE-2026-3576)
- Upstream PR . Under Review
- **Ruby β’ Metasploit **
I write about:
- π Vulnerability Research
- π₯ Exploit Development
- π Web Application Security
- π’ Active Directory
- π§ͺ Capture The Flag Challenges
- π οΈ Security Tool Development
My blogs can be found here
My research has been published at top-tier security conferences and journals.
- An adversarial attack approach for eXplainable AI evaluation on deepfake detection models, Computers & Security, 2024 Link
- GateKeeper: Operator-centric Trusted App Management Framework on ARM TrustZone, IEEE Conference on Communications & Network Security, 2022 Link
- Designing a Text-based CAPTCHA Breaker and Solver by using Deep Learning Techniques, IEEE International Conference on Advances and Developments in Electrical and Electronics Engineering, 2021 Link
Windows Internals
Advanced Web Exploitation
Cloud Security
LLM Security
Malware Analysis
Advanced Active Directory Attacks
β If you find my scripts useful, consider giving them a star!