Web Application
Pentester.
Self-taught security researcher focused on web application vulnerabilities, recon automation, and OWASP Top 10 methodology. Building practical skills through real-world testing and open-source tooling.
Reconnaissance
Web App Testing
Tools
Scripting
SubFinder-Tool
Bash-based subdomain enumeration tool integrating subfinder, assetfinder, crt.sh, and httpx. Produces timestamped, deduplicated, and live-validated output organized per source.
Cybersecurity Vault
Open-source curated reference covering payloads, tools, and techniques for web application pentesting. Includes XSS, SQLi, LFI, command injection, and subdomain takeover references.
The Logout That Wouldn't Die
Replay attack on session logout — logic flaw analysis and remediation walkthrough.
Write-up coming soon
Methodology post on subdomain enumeration and asset discovery workflow.
PortSwigger Web Security Academy
SQLi, XSS, CSRF, IDOR, Authentication, Path Traversal, Access Control — Apprentice + Practitioner levels
OWASP Juice Shop
Hands-on exploitation of intentionally vulnerable web application across multiple vuln categories
Blockchain Security & Smart Contract Auditing
EVM, DeFi protocol vulnerabilities, reentrancy, flash loans, access control flaws — self-study
Let's work together.
Open to entry-level VAPT and application security roles. Based in India, open to relocation.
Aman.Singh.Pentest@gmail.com