Foundations & Web Security Core
A complete foundation guide covering web application vulnerability assessment methodology, OWASP Top 10, and testing frameworks for security practitioners.
CEH v12 certified offensive security professional with 2+ years of hands-on VAPT experience. Author of 4 cybersecurity books under WhiteFox InfoSec. Committed to identifying real threats before attackers do.
I'm a Certified Ethical Hacker (CEH v12) with over two years of hands-on experience delivering end-to-end Vulnerability Assessment and Penetration Testing. My methodology is precise, evidence-based, and aligned with globally recognized standards including OWASP Top 10 and MITRE ATT&CK.
"Offense informs defense — and I've built a career mastering both sides of the equation."
My engagements span the full attack lifecycle — scoping, reconnaissance, exploitation, post-exploitation, and client debrief — with a strong emphasis on communicating risk clearly to both technical and executive stakeholders.
Beyond consulting, I author cybersecurity books under WhiteFox InfoSec, creating structured learning resources for the next generation of security professionals.
Published under WhiteFox InfoSec — practical, field-tested cybersecurity guides built from real-world penetration testing experience.
A complete foundation guide covering web application vulnerability assessment methodology, OWASP Top 10, and testing frameworks for security practitioners.
Advanced offensive techniques — exploiting SQL Injection, XSS, IDOR, broken authentication, and business logic flaws in real-world applications.
Foundations of Cyber Defense & Offensive Security — an 85-chapter comprehensive study guide for modern cybersecurity practitioners.
Offensive security, defense, automation, and incident response — a hands-on Kali Linux guide for security engineers and ethical hackers.
A full-spectrum offensive security toolkit refined through real-world engagements, research, and continuous learning.
Real-world security projects combining offensive research, tool development, and applied cybersecurity principles.
Designed and implemented a tamper-proof digital evidence management system using blockchain technology. Ensured data integrity, secure validation workflows, and transparent forensic chain-of-custody — applied at Riss Technologies.
Practiced exploitation of OWASP Top 10 vulnerabilities on DVWA and OWASP Juice Shop. Conducted manual testing using Burp Suite, simulated real-world attack scenarios, and documented complete findings with PoC and remediation guidance.
Conducted open-source intelligence reconnaissance using Shodan to identify exposed services and attack surfaces. Practiced threat profiling, attack pattern mapping against MITRE ATT&CK, and produced structured intelligence reports.
Authored 4 field-tested cybersecurity books translating real VAPT experience into structured learning resources — covering web application VAPT (Parts 1 & 2), ethical hacking foundations (Shadow Hunters), and Kali Linux security engineering.
Industry-recognised certifications, verified credentials, and formal academic qualifications across offensive security, threat intelligence, and cloud security.
BCA focused on CS fundamentals, networking, and cybersecurity. Reg. No: AVAUBCA012, Valayamkulam, Kerala.
IT Infrastructure · Network & Offensive Security · Cyber SOC · Application Security · ML for Cybersecurity · Cyber Kill Chain & Compliance
Hands-on labs, DVWA, OWASP Juice Shop, CTF competitions, OSINT research, and active threat intelligence study.
Available for VAPT engagements, security consulting, training sessions, speaking events, and collaboration opportunities.