class KrishanuKaundilya:
role = "CEH Master | VAPT Specialist | AI Security Researcher"
location = "Indore, MP, India ๐ฎ๐ณ"
experience = "2+ years hands-on VAPT"
focus = [
"Web App & API Penetration Testing",
"AI / LLM Security & Prompt Injection",
"DAST Scanner Rule Development",
"Agentic Security Automation",
]
certifications = [
"CEH Master โ EC-Council #ECC0285763419",
"Certified Ethical Hacker v13 (CEH)",
"CEH Practical",
]
currently_learning = [
"Active Directory Exploitation",
"AI Red Team Methodology",
"Network Pivoting & Lateral Movement",
]
fun_fact = "I delivered VAPT training to law enforcement officers at CAPT Bhopal ๐ฎ"| Tool | Description | Stack | Stars |
|---|---|---|---|
| ๐ฏ nuclei-template-library | Custom Nuclei YAML templates from real VAPT engagements โ IDOR, Business Logic, XSS, Missing Headers | YAML ยท Nuclei | โญ |
| ๐ recon-automation-tool | Full recon pipeline: Subfinder โ httpx โ Nuclei โ HTML Report | Python ยท BeautifulSoup4 | โญ |
| ๐ vapt-report-generator | JSON findings โ Professional PDF + HTML VAPT reports | Python ยท ReportLab | โญ |
| ๐ง prompt-injection-toolkit | 31 payloads for AI/LLM security โ OWASP LLM Top 10 mapped | Python ยท requests | โญ |
- ๐ด IDOR โ Independently identified unauthorized P2P trading history access via userId parameter manipulation on a cryptocurrency exchange platform (confirmed valid)
- ๐ Business Logic Flaw โ Exchange API accepting negative/zero amounts returning HTTP 200 with invalid conversion results (confirmed valid)
- ๐ฌ Both findings confirmed real-world exploitability via HackerOne
| Event | Topic | Audience |
|---|---|---|
| ๐ CAPT Bhopal | Ethical Hacking & Attacker Methodology | Law Enforcement Officers |
| ๐ผ Crawl Digitally | Phishing Attack Awareness | Corporate Team |