AI_SECURITY // NETWORK_INFILTRATION // WEB_EXPLOITATION
MOBILE_PENTESTING // CLOUD_RECON
Penetration tester with 2+ years of active field experience targeting web applications, network infrastructure, mobile platforms, and emerging AI/LLM systems.
Specialization in AI/Chatbot security research — discovered multiple system prompt disclosure vulnerabilities in enterprise LLM deployments. Holds deep knowledge of OWASP Top 10, PTES, and modern red team methodologies.
Background in full-stack development (MERN) provides an attacker's edge: able to read source, understand logic flaws, and chain vulnerabilities from front-end to back-end with precision.
Currently pursuing OSCP and advancing cloud security expertise across AWS/GCP environments.
> Available for engagements
> Active bug bounty hunter
> OSCP prep in progress
> OWASP Top 10 // PTES
> MITRE ATT&CK Framework
> Bug Bounty (HackerOne, Bugcrowd)
> Web Application: ADVANCED
> Network Infrastructure: ADVANCED
> Mobile (Android/iOS): INTERMEDIATE
> AI/LLM Security: SPECIALIST
Engineering Degree // 2020–2024
> DECRYPTED: Grade A+ // Focus: Network DefensePre-University (12th) // 2017
> DECRYPTED: Distinction // SciencesFull Stack Development Certification // 2019
> DECRYPTED: MERN Stack ExpertiseComplete MERN Stack Development // 2019
> DECRYPTED: Certificate of CompletionSchooling // 2007–2015
> DECRYPTED: Foundational EducationACTIVE_MODULES_CONNECTED_TO_ARES_CORE
Burp Suite // SQLMap // XSStrike
OWASP ZAP // Nikto // ffuf
Prompt Injection // LLM Recon
RAG Attacks // Jailbreaks
Nmap // Metasploit // Nessus
Wireshark // Enum4linux
Frida // Objection // ADB
MobSF // apktool
Docker // CI/CD Review
SAST/DAST // Trivy
AWS IAM // S3 Misconfig
GCP Recon // CloudSploit
// AZURE
// AWS
// The SecOps Group
//UDEMY
How a specific query sequence exposed sensitive backend logic in a production AI assistant, allowing full system context extraction without jailbreak.
Exploiting weak redirect URI validation in a MERN stack application to steal authorization codes and fully take over any account without credentials.
A comprehensive walkthrough of evading signature-based WAFs using Unicode normalization tricks to deliver XSS and SQLi payloads undetected.