I build tooling that turns raw reconnaissance into findings someone can actually act on — and I write the report that proves it. Most of my work sits at the seam between automation and evidence: collect broadly, validate ruthlessly, document so it reproduces on the first try.
- Break it — web exploitation, auth/authz logic, API surface, misconfiguration, Linux privesc.
- Automate it — recon pipelines, enrichment, triage, and reporting that survive being run twice.
- Prove it — reproduction steps, captured evidence, false-positive elimination, severity that holds up.
- Fix it — findings translated into config, code, and process changes, not just a ticket.
Scoped, authorized testing only. Every tool here exists to make defensive work faster.
| Phase | What actually happens |
|---|---|
| Scope | Confirm boundaries, permission, and assumptions in writing before a single packet leaves. |
| Recon | Passive and active collection — WHOIS, DNS, certificate transparency, archives, exposed surface. |
| Enumerate | Map services, endpoints, parameters, auth flows, and trust relationships into something queryable. |
| Exploit | Bounded, non-destructive validation. Confirm the path, never wander outside the agreed blast radius. |
| Validate | Reproduce twice, strip false positives, capture the evidence that makes it undeniable. |
| Document | Steps to reproduce, impact, affected assets, severity rationale, and the raw artifacts. |
| Report | Written for two audiences at once: the engineer who fixes it and the person who funds the fix. |
| Harden | Turn each finding into a concrete configuration, code, or process change — then re-test it. |
|
|
|
|
|
|
▸ SUPPORTING REPOSITORIES
| Repository | What it is | Domain |
|---|---|---|
| Linux-CIS-Hardening-Auditor | Bash CLI auditing Linux against 104 CIS Benchmark controls — filesystems, services, networking, logging, SSH, accounts. | Hardening |
| Secure-QR-Code-Generator | Input-validated QR generator for text, URL, phone, SMS, email, WhatsApp, Wi-Fi, vCard and UPI payloads. | Tooling |
| Port-Swigger-Labs-Solved | Solved PortSwigger Web Security Academy labs, each with the reasoning — not just the payload. | Web Security |
| RingZero-CTF-Writeups | Deep, step-by-step RingZer0 CTF writeups covering the dead ends as well as the solution. | CTF |
| Pico-CTF-Writeups | picoCTF challenge writeups across web, crypto, forensics and reversing. | CTF |
| LANGUAGES |
|
| WEB & API |
|
| INFRA & DATA |
|
| PLATFORMS |
|
| RECON & OSINT |
|
| WEB SECURITY |
|
| EXPLOITATION |
|
| FORENSICS & RE |
|
| BLUE TEAM |
|
| LABS |
|
$ tail -f ~/ops/NOW.log
[ACTIVE] ReconTitan :: confirmed-exploitation engine + richer PDF reporting
[ACTIVE] HexForge :: widening PE/ELF structure coverage and entropy triage
[ACTIVE] OSCP path :: AD attack paths, pivoting, Linux & Windows privesc
[QUEUED] Dork-Ripper :: automated validation pass over every operator set
[ONGOING] Web security :: authz logic, API abuse, cache and CORS edge cases
[ONGOING] Writeups :: PortSwigger, picoCTF and RingZer0 — reasoning included|
Open to collaborate on
|
How I work best
|
