Penetration Tester | Web & API Security | Cybersecurity Trainer

Vishal
Kumar.

Testing production applications, discovering vulnerabilities, validating exploitation, and delivering professional security reporting.

Vishal Kumar

Security Proof System

Proof > Claims. Real-world validation of security posture across modern architectures.

114

Vulnerabilities Identified

In production multi-tenant SaaS environments

34

CVSS 10.0 Critical Findings

High-impact authorization and logic flaws

34

API Endpoints in BOLA Chain

Demonstrated cross-tenant unauthorized access

~40%

Manual Effort Reduced

Through Python and Bash automation

01 — Profile

I Learn Systems By Breaking Them.

Understanding how systems fail in order to build them better.

I got into offensive security because I wanted to understand how things actually work under the surface — not just how they're supposed to work.

There is a significant difference between reading about a vulnerability and finding one yourself in a live application. My focus is on web application and API security — testing authentication flows, probing authorization boundaries, and chaining small weaknesses into meaningful attack paths.

Beyond manual testing, I build security automation tools to streamline the repetitive phases of penetration testing. The goal isn't just finding vulnerabilities — it's understanding why they exist and communicating their real-world impact clearly.

Global Ranking

TryHackMe
Top 1%

Consistent performance across offensive security paths and CTF challenges.

OFFENSIVE SECURITY

Penetration Testing

Systematic enumeration and exploitation of infrastructure and application vulnerabilities to identify attack paths.

Relevant Tools

NmapMetasploitBurp SuiteNessus
WEB SECURITY

Web App Exploitation

Deep diving into authentication bypasses, SQL injection, XSS, and SSRF vulnerabilities within modern web architectures.

Relevant Tools

Burp Suite ProOWASP ZAPffufsqlmap
INFRASTRUCTURE

Active Directory Attacks

Simulating lateral movement, privilege escalation, and domain dominance in Windows enterprise environments.

Relevant Tools

BloodHoundImpacketMimikatzResponder
AUTOMATION

Security Tooling

Developing custom scripts and automation frameworks to accelerate reconnaissance and streamline vulnerability assessment workflows.

Relevant Tools

PythonBashGoDocker
01 — CATEGORY

Offensive Security

VAPT
Web Application Pentesting
API Security
OWASP Top 10
BOLA/IDOR
SSRF
XSS
Authentication Bypass
Privilege Escalation
Business Logic Testing
JWT Security
CORS
Host Header Attacks
02 — CATEGORY

Tools

Burp Suite Pro
Nmap
SQLMap
Gobuster
Metasploit
Wireshark
Netcat
Hydra
Shodan
TheHarvester
Maltego
03 — CATEGORY

Programming

Python
Bash/Shell
C++
SQL
04 — CATEGORY

Defensive Security

SOC L1
SIEM
Log Analysis
Alert Investigation
Threat Detection
Incident Response
Security Monitoring
05 — CATEGORY

Frameworks

CVSS v4.0
CWE
MITRE ATT&CK
OWASP
SOC 2
ISO 27001
GDPR
PCI DSS
02 — Methodology Origin

Real-World Application Security

Security testing performed across diverse production platforms, establishing the foundation for structured testing methodologies.

HOA Platform

Application Security Testing

Academy Platform

Web Application Security Testing

Blog Website

Web Security Testing

HRMS Platform

Application / API Security Testing

Learned recurring workflows

Automation & Methodology

Built structured testing workflows
03 — Experience

Professional Experience

Practical security experience through hands-on engagements.

Jan 2026 – Present

Botmartz AI Solutions

Penetration Tester

Indore, India

About Botmartz AI Solutions

Botmartz AI solutions is a forward-thinking technology and cybersecurity firm specializing in securing enterprise infrastructure, web applications, and cloud environments against modern cyber threats.

My Role & Responsibilities

As a Penetration Tester, I was responsible for leading offensive security engagements, conducting comprehensive vulnerability assessments, and executing penetration testing on client platforms. I focused on identifying critical security flaws, building attack chains, and providing actionable remediation strategies.

What I Learned

I developed a deep understanding of complex authorization vulnerabilities, business logic flaws, and enterprise-grade security reporting. I also honed my skills in automating repetitive reconnaissance and security testing workflows using custom Python and Bash scripts, significantly increasing testing efficiency.

What I Tested

  • [01]Multi-tenant SaaS Platforms
  • [02]Complex Authorization Flows (BOLA/IDOR)
  • [03]Role-Based Access Control (RBAC) Systems
  • [04]API Endpoints and Integrations
  • [05]Cloud Infrastructure (AWS IAM/IMDSv1)

Key Engagements

  • [01]Identified 114 vulnerabilities including 34 CVSS 10.0 Critical findings.
  • [02]Discovered a system-wide BOLA attack chain across 34 API endpoints, demonstrating cross-tenant access.
  • [03]Identified a complete privilege escalation path from Tenant Admin to Platform Super-Admin.
  • [04]Chained SSRF to AWS IMDSv1, resulting in exposure of cloud credentials.
  • [05]Prepared enterprise-grade VAPT reports containing PoCs, attack-chain analysis, and CVSS v4.0 scores.
  • [06]Automated reconnaissance and repetitive security-testing workflows using Python and Bash, reducing manual effort by approximately 40%.
Burp Suite ProPythonBashAWSCVSS v4.0MITRE ATT&CKWeb & API Security
05 — Research

Security Laboratory

An interactive visualization of typical attack vectors, vulnerabilities, and the methodologies used to exploit and secure them.

OWASP Testing Guide

Web Application Pentesting

Hands-on testing of authentication, authorization, injection, and business logic vulnerabilities in web applications.

Arsenal & Tooling

Burp Suite
OWASP ZAP
Browser DevTools

OWASP API Security Top 10

API Security Testing

Assessing REST and GraphQL APIs for broken access control, injection, and data exposure vulnerabilities.

Arsenal & Tooling

Burp Suite
Postman
Custom Scripts

PTES Reconnaissance

Network Reconnaissance

Active and passive reconnaissance including port scanning, service enumeration, and vulnerability identification.

Arsenal & Tooling

Nmap
Gobuster
Wireshark

MITRE ATT&CK

Active Directory Exploitation

Practicing AD attack paths including Kerberoasting, credential harvesting, and lateral movement techniques.

Arsenal & Tooling

Impacket
Mimikatz
BloodHound

Systematic Enumeration

Privilege Escalation

Linux and Windows privilege escalation through misconfigurations, SUID binaries, kernel exploits, and service abuse.

Arsenal & Tooling

LinPEAS
WinPEAS
GTFOBins

Workflow Automation

Security Automation

Building Python and Bash scripts to automate repetitive security testing tasks and chain tool outputs.

Arsenal & Tooling

Python
Bash
Custom Frameworks
06 — Projects

BugHunterLab

Developing advanced offensive security platforms and automation tools.

Professional Bug Bounty & VAPT Platform

Scope
Recon
Attack Surface
Testing
Findings
Evidence
PoC
Report

01. Overview & Problem

BugHunterLab is a professional Bug Bounty and VAPT platform designed to organize the complete security testing workflow from scope analysis and reconnaissance to vulnerability testing, proof-of-concept generation, evidence management, and professional reporting.

Security testing workflows often suffer from fragmented tooling, lost evidence, and manual reporting. BugHunterLab solves this by unifying the entire lifecycle into a structured, methodology-driven platform.

02. Architecture Stack

Frontend Next.js
Backend FastAPI
Database PostgreSQL
Task Processing Celery + Redis
Monitoring Flower
Infra Docker Compose
03. Core Engine

The Security Workflow

A structured pipeline tracking targets from initial discovery to final validation.

PHASE 01

SCOPE

PHASE 02

RECON

PHASE 03

ATTACK SURFACE

PHASE 04

TESTING

PHASE 05

FINDING

PHASE 06

EVIDENCE

PHASE 07

PoC

PHASE 08

REPORT

04. Capabilities

Platform Features

Professional security orchestration and vulnerability management.

01

Scope Analyzer

Analyze attack surface difficulty based on program domains and scope. Categorizes into Beginner, Intermediate, and Expert.

02

Automated Recon Pipeline

Live automated discovery via subfinder & httpx. Integrates live host detection, technology fingerprinting, and WebSocket logs.

03

Attack Surface Map

Interactive security intelligence mapping subdomains, live hosts, and technologies automatically post-reconnaissance.

04

Testing Methodology

Endpoint-level testing checklists based on HTTP methods (GET, POST, PUT, DELETE, FILE) and target features.

05

Vulnerability Findings

Professional vulnerability management interface capturing title, severity, class, and detailed descriptions.

06

Evidence Manager

Secure storage for screenshots, logs, and HTTP dumps (up to 20MB per file) for finding validation.

07

Proof of Concept Generator

Auto-generate PoCs in cURL, Python, and Burp Suite formats directly from validated findings.

08

Report Builder

Generate styled Markdown and PDF reports linking findings, evidence, PoCs, impact, and remediation.

09

Security Automation

Orchestrate nuclei, nmap, ffuf, gau, and katana via Celery workers with live WebSocket execution monitoring.

05. Security Automation

Orchestrated Testing

BugHunterLab integrates industry-standard security tools directly into the platform workflow. Tasks are executed asynchronously via Celery workers, allowing testers to run intensive scans while analyzing other targets.

subfinderhttpxnucleinmapffufgaukatana
Live Execution Log (WebSocket)

[+] Task started: nuclei -t vulnerabilities/ -u target.com

[*] Loading templates...

[*] Execution active: 45 workers

[!] Found CVE-2023-XXXX on target.com/api/v1

[*] Saving output to database...

06. Outcomes & Challenges

Building BugHunterLab required overcoming complex challenges in real-time task orchestration, managing large evidence payloads securely, and normalizing output from diverse CLI security tools into a unified PostgreSQL schema.

View Source on GitHub
04 — Knowledge Sharing

Cybersecurity Training

Connecting security theory with real-world exploitation and defense.

Cybersecurity
Trainer

~July 2025 – Present

College & Professional Training | India

I don't just find vulnerabilities; I teach others how to find them. I design and conduct hands-on labs, demonstrations, and practical exercises that take students from IT fundamentals to advanced penetration testing and SOC L1 analysis.

Foundations

IT & Computer Fundamentals
Linux Administration
Windows Security
Networking & TCP/IP
Python Scripting

Offensive Security

Ethical Hacking (CEH-level)
Advanced Penetration Testing
Web Application Security
API Security
Exploitation Concepts

Defensive Security

SOC L1 Training
SIEM Fundamentals
Log Analysis
Threat Detection
Incident Response

Location

India

Available for remote opportunities.

Let's Secure
Systems

Open to freelance contracts, full-time roles, and collaboration on ambitious, security-focused systems.