π Security Researcher | Penetration Tester | Web Security | Active Directory Security | AI & LLM Security
I'm a cybersecurity professional with 3.5+ years of experience in offensive security and security research.
My interests include penetration testing, vulnerability research, exploit development and red teaming.
Currently building security tools, researching vulnerabilities and contributing to open-source security projects.
I also actively write blogs which can be found here.
π Security Engineer
π― Penetration Tester
π€ AI / LLM Security
π₯ Vulnerability Research & Exploit Development
π§ Linux & Active Directory
π οΈ Security Tool Development
π Continuous Learner
- π‘οΈ OSCP Certified
- π Interested in Web, API, Network & Active Directory Security
- π€ Experience with AI Security, Adversarial Testing & LLM Assessments
- π₯ Published conference/journal papers, vulnerability research and exploit PoCs
- π Open-source security contributor
- βοΈ Technical writer covering cybersecurity and vulnerability research
A collection of Python/Bash utilities for automating common penetration testing and reconnaissance tasks.
- Linux Pentesting Toolkit - Helper scripts for automating privilege escalation and enumeration in Linux [Repo]
A collection of vulnerability research and proof-of-concept exploit development projects.
- Server-side request forgery leading to local file inclusion in Planyo WordPress plugin (CVE-2026-3576) [Repo]
- Arbitrary file write leading to remote code execution in Wolf CMS (CVE-2026-67206) [Repo]
- Broken access control leading to mass user information disclosure in 4gaBoards (CVE-2026-53959) [Repo]
- Arbitrary file read in Welcart e-Commerce WordPress plugin (CVE-2022-4140) [Repo]
A list of my contributions to open source security tools.
- Metasploit
- A local file inclusion exploit module affecting Planyo WordPress plugin (CVE-2026-3576) [Merged]
- A mass user information disclosure module affecting 4gaBoards (CVE-2026-53959) [Under review]
- An arbitrary file read exploit module affecting Welcart e-Commerce WordPress plugin (CVE-2022-4140) [Under review]
- An arbitrary file read exploit module affecting Docmost (CVE-2025-57231) [Under review]
- Nuclei
- Authored a template for a file path traversal vulnerability affecting Docmost (CVE-2025-57231) [Merged]
My research has been published at top-tier security conferences and journals.
- An adversarial attack approach for eXplainable AI evaluation on deepfake detection models, Computers & Security, 2024 [Link]
- GateKeeper: Operator-centric Trusted App Management Framework on ARM TrustZone, IEEE Conference on Communications & Network Security, 2022 [Link]
- Designing a Text-based CAPTCHA Breaker and Solver by using Deep Learning Techniques, IEEE International Conference on Advances and Developments in Electrical and Electronics Engineering, 2021 [Link]
β If you find my scripts useful, consider giving them a star!
