Hands-on experience in live bug bounty programs. Skilled in OWASP Top 10, Burp Suite, and API security. Looking for a remote junior VAPT role to identify and report web vulnerabilities.
Tools, languages and frameworks I use daily
Burp Suite, parameter abuse, BOLA, excessive data exposure, authentication bypass.
HTTP/HTTPS, TCP/IP, DNS, Linux (Kali, Ubuntu), Windows environment.
Python, JavaScript, automation scripts, custom security tooling.
Open-source tools and dashboards I built
WordPress security scanner that detects known vulnerabilities, misconfigurations and outdated plugins.
View on GithubVulnerability assessment dashboard for SQLi, XSS, CSRF with live tracking of bug bounty progress.
Live DemoTool to detect CORS misconfigurations in web applications and assess potential data leakage.
View on GithubI document real-world bug bounty findings, API hacking techniques and PortSwigger lab solutions. Read my latest research on dev.to and personal blog.
Explore All Writeups