Web Application VAPT Labs
Hands-on testing across access control, JWT attacks, unrestricted file upload, CORS, XSS, SQL injection, SSRF, CSRF, clickjacking and related web security classes.
Open Web Testing Labs →Results-driven cybersecurity professional focused on offensive security, vulnerability research, web and API security, Android assessment, red-team operations, and security monitoring.
I'm a final-year BS Cybersecurity student with a practical focus on penetration testing, VAPT, vulnerability research, and SOC operations.
My security work spans web applications, APIs, Android applications, vulnerable machines, reverse engineering, and red-team simulations. I approach assessments through reconnaissance, attack-surface mapping, manual validation, controlled exploitation, impact assessment, and professional reporting.
My portfolio is intentionally organized around the work itself: every lab below links directly to its corresponding GitHub folder, so visitors can move from a high-level portfolio summary to the actual methodology, PoC evidence, and remediation guidance.
Selected work from my security research portfolio. Each category opens the relevant GitHub repository or project so recruiters and technical reviewers can inspect the underlying work.
Hands-on testing across access control, JWT attacks, unrestricted file upload, CORS, XSS, SQL injection, SSRF, CSRF, clickjacking and related web security classes.
Open Web Testing Labs →OWASP API Top 10 testing using Burp Suite and Postman, including BOLA, BFLA, JWT mismanagement, mass assignment and authorization weaknesses.
Open API Testing Labs →Static and dynamic mobile testing with JADX, Ghidra and Frida, including SSL pinning and root-detection bypass, insecure storage, weak encryption and insufficient obfuscation.
Open Android Labs →Boot-to-root exploitation, credential attacks, network sniffing, reconnaissance, social-engineering simulations, privilege escalation and adversarial techniques across lab environments.
Open Red Team Labs →A custom reconnaissance automation tool designed to streamline information-gathering workflows before web application penetration testing and reduce repetitive manual setup.
Open Recon-Master →The central repository containing structured penetration-testing write-ups, methodology, proof-of-concept material and remediation guidance across web, API, Android and red-team labs.
Open Poc-labs Repository →A direct, recruiter-friendly index of the labs currently represented in Poc-labs. Clicking a lab opens its specific GitHub directory, not just the repository homepage.
Web-Testing/
API-Testing/
APK-Testing/
Red-Team/
Boot-to-Root exploitation and privilege escalation.
Credential attack lab and password-recovery workflow.
Traffic analysis and packet inspection.
Human-layer attack simulation in an authorized lab context.
Reconnaissance and attack-surface discovery.
Burp Suite · Nmap · Nuclei · SQLMap · Nikto · WPScan · Gobuster · Postman
Wireshark · Metasploit · Hydra · Linux · LOLBAS
Frida · JADX · Ghidra · Binary Ninja · Android Pentesting
Elastic SIEM · Sirp · Trend Micro Apex One · CTM360 · Nipper ·
Podium finish on a first competitive CTF appearance, competing against 40+ teams across web exploitation, binary exploitation and reverse engineering.
Competed in advanced challenges spanning digital forensics, cryptography and application security.
Interested in penetration testing, vulnerability research, application security, or security collaboration? Let's talk.