π Mumbai, India Β· π― Open to Penetration Testing & Red Team Roles
PJPT-certified penetration tester with hands-on experience in Active Directory exploitation (17 documented attack techniques) and web application security testing (32 OWASP Top 10 findings). Proven ability to build realistic enterprise attack scenarios, document complete kill chains, and provide actionable remediation recommendations.
What I Bring to Your Team:
- β Real-world penetration testing methodology (PTES, OWASP Testing Guide)
- β Complete attack documentation from reconnaissance to post-exploitation
- β MITRE ATT&CK framework mapping for threat intelligence alignment
- β Professional-grade security reports with CVSS scoring and business impact analysis
- β Defensive mindset β every attack paired with detection and mitigation strategies
| Certification | Issuer | Year | Verification |
|---|---|---|---|
| β PJPT (Practical Junior Penetration Tester) | TCM Security | 2026 | Verify Certificate |
Enterprise-grade AD penetration testing lab simulating realistic attack chains from initial access to Domain Admin compromise.
Key Achievements:
- π― 17 documented attack techniques across full kill chain
- π’ 3-machine Windows domain (BATMAN.local) β DC + 2 workstations
- π Complete credential access chain β LLMNR poisoning β Kerberoasting β Golden Ticket
- π‘οΈ Defense-aware β every attack paired with Event ID detection and GPO hardening
- π MITRE ATT&CK mapped β 15+ TTP IDs documented
Attack Coverage:
| Technique | MITRE ID | Impact |
|---|---|---|
| LLMNR/NBT-NS Poisoning | T1557.001 | NTLMv2 hash capture |
| SMB Relay | T1557.001 | SAM/LSA dumping |
| Kerberoasting | T1558.003 | Service account compromise |
| Pass-the-Hash | T1550.002 | Lateral movement |
| Mimikatz / LSASS Dumping | T1003.001 | Credential extraction |
| Golden Ticket | T1558.001 | Persistent DA access |
| ZeroLogon (CVE-2020-1472) | CVE-2020-1472 | DC takeover |
| PrintNightmare (CVE-2021-1675) | CVE-2021-1675 | SYSTEM escalation |
Tools Used: Responder, Impacket Suite, Bloodhound, Mimikatz, Hashcat, NetExec, mitm6
Comprehensive web security testing across DVWA and PortSwigger Web Security Academy with professional pentest reporting.
Key Achievements:
- π― 32 documented vulnerabilities with full exploitation walkthroughs
- π΄ 9 Critical findings β SQL injection, command injection, unrestricted file upload β RCE
- π 19 High severity β XSS (reflected, stored, DOM), authentication bypass, CSRF, IDOR
- π Enterprise report β CVSS v3.1 scoring, remediation recommendations, Burp Suite evidence
- β 100% OWASP Top 10 (2021) coverage
Vulnerability Classes:
| Category | Findings | Severity |
|---|---|---|
| A03: Injection | SQL Injection (6), XSS (6), Command Injection (2) | Critical/High |
| A01: Broken Access Control | CSRF, IDOR, Unprotected Admin (4) | Critical/High |
| A07: Authentication Failures | 2FA bypass, Brute-force, Session fixation (5) | Critical/High |
| A04: Insecure Design | File Upload RCE, API flaws (5) | Critical/High |
| A05: Security Misconfiguration | LFI, Info disclosure (2) | High/Medium |
Tools Used: Burp Suite, sqlmap, Nmap, Hydra, netcat, msfvenom
| Platform | Machine/Challenge | Type | Key Techniques |
|---|---|---|---|
| HTB | Cyber Apocalypse 2026: Gatery | Web CTF | Session management bypass, broken authorization |
| TCM | BlackPearl | Linux | Web exploitation, privilege escalation |
| TCM | Butler | Windows | Jenkins RCE, unquoted service path β SYSTEM |
| TCM | Dev | Linux | Boltwire LFI, NFS enumeration, sudo abuse |
| TCM | Academy | Linux | FTP disclosure, file upload, cron job abuse β root |
| VulnHub | Kioptrix Level 1 | Linux | Samba trans2open exploit, mod_ssl buffer overflow |
- Credential Access: LLMNR poisoning, SMB relay, Kerberoasting, LSASS dumping, NTDS.dit extraction
- Lateral Movement: Pass-the-Hash, PSExec, WMIExec, SMBExec
- Privilege Escalation: Token impersonation, Golden Ticket, ZeroLogon, PrintNightmare
- Enumeration: Bloodhound, ldapdomaindump, NetExec, PingCastle
- Tools: Responder, Impacket, Mimikatz, Hashcat, mitm6, Metasploit
- OWASP Top 10: SQL injection (UNION, blind, auth bypass), XSS (reflected, stored, DOM), command injection
- Access Control: CSRF, IDOR, authentication bypass, session management flaws
- File Security: Unrestricted upload β RCE, LFI/RFI, path traversal
- API Security: Mass assignment, parameter pollution, SSRF, endpoint enumeration
- Tools: Burp Suite, sqlmap, Nmap, Hydra, ffuf, Nikto
- Linux PrivEsc: SUID abuse, sudo misconfiguration, cron jobs, kernel exploits
- Windows PrivEsc: Unquoted service paths, weak service ACLs, registry exploitation
- CVE Research: Exploit-DB, GitHub PoCs, Metasploit modules
- Reverse Shells: bash /dev/tcp, PHP, Groovy, netcat, msfvenom payloads
- Tools: LinPEAS, winPEAS, GTFOBins
- Python 3: pwntools, Paramiko, custom exploitation scripts
- Bash: Automation, enumeration scripts, reverse shell one-liners
- PowerShell: Windows post-exploitation, service manipulation
- MITRE ATT&CK: 15+ techniques mapped with detection strategies
- OWASP Testing Guide: Web application testing methodology v4.2
- PTES: Penetration Testing Execution Standard
- CVSS v3.1: Vulnerability severity scoring and risk assessment
π― Active Directory Attacks Documented: 17
π Web Vulnerabilities Found: 32
π Machines Compromised: 6
π Technical Writeups Published: 9
π οΈ Tools Mastered: 30+
π Professional Reports Generated: 2
π΄ Critical Findings: 9
π High Severity Findings: 19
Open to roles in: Penetration Testing, Red Team Operations, Security Assessment, Application Security Testing
Preferred location: Mumbai, India (open to remote opportunities)
Why hire me?
- β Production-ready penetration testing skills backed by 50+ documented vulnerabilities
- β PJPT certification validating real-world AD and network pentesting ability
- β Strong documentation skills β every attack includes methodology, evidence, and remediation
- β Defensive mindset β understand both offensive techniques and detection/mitigation strategies
- β Continuous learner β active on HTB, THM, and TCM platforms with ongoing CTF participation