Skip to content
View ghostbit11's full-sized avatar

Block or report ghostbit11

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ghostbit11/README.md

Rahul Parmar — Application & Product Security · DevSecOps · VAPT · Vulnerability Research

Portfolio Résumé LinkedIn Email

👋 About

Product security & DevSecOps at IBM — secure-release reviews for IBM Maximo Application Suite, running SAST, DAST, SCA and container scanning (Mend, OWASP ZAP, Twistlock) with hands-on remediation of open-source and container findings. Before IBM I was the founding security hire at Zarca Interactive, where I built the security function from nothing: the process, the tooling stack and a five-person team. Earlier, red-team and VAPT delivery at PwC across banking, financial services and oil & gas. On my own time I hunt bugs and report them responsibly.


🎯 Featured Project

A cybersecurity training range that looks like a real SaaS product — 11 realistic target apps, 48 hands-on challenges, flags & scoring, cross-app attack campaigns, a role-based admin console, and an auto-detecting blue-team SOC. One docker compose up and it runs.

Covers the OWASP Web Top 10, API Top 10 and LLM Top 10 — SQLi, XSS, SSRF, SSTI, IDOR/BOLA, JWT alg:none, GraphQL abuse, OAuth redirect_uri, PHP object injection, prompt injection & RAG poisoning — each scalable across four difficulty levels from textbook-vulnerable to a hardened reference fix.

PHP Docker Challenges OWASP Apps


🧪 Security Research

Published CVEs

CVE-2023-3074 CVE-2023-1975 CVE-2023-1704 CVE-2023-1703

🏆 Hall of Fame — responsible disclosure Apple · United Nations · Dell · Deutsche Telekom · eBay · FitBit · HubSpot · Springer Nature · Inflectra · Electro Rent · Worldline Global · APNIC

📜 Letters of acknowledgement Harvard University · Intuit · ESET · Avast · Huawei · Intel · HumanFirst

🥇 Recognition — ranked among the Top 15 researchers for reporting vulnerabilities in Government of India websites — NCIIPC India (a unit of NTRO), April 2021 newsletter.

✍️ Writing"Hashcat for Forensics", National Journal of Anti Cyber Crime Research & Studies (ACCRS) · Google Dorks published on Exploit-DB.


🧰 Skills

Area Coverage
Offensive VAPT · Web / API / Mobile Pentesting · Red & Purple Teaming · Breach & Attack Simulation · VPN Testing · OWASP Top 10 · JWT / OAuth / Rate-Limit Bypass
Product Security / DevSecOps SAST · DAST · SCA · Container Scanning (Twistlock / Prisma Cloud) · Mend · OWASP ZAP · Secure SDLC · CI/CD Security · SBOM · OSS Remediation · Secure Release Review
Vulnerability Management CVE Analysis · CVSS Scoring · PSIRT / PVR Workflows · Remediation Tracking · Executive Reporting
Detection & Response Threat Hunting · SIEM (Sentinel) · Defender for Endpoint · Sophos XDR · Azure WAF · Dark-Web Monitoring
Cloud & GRC AWS · Azure · Cloud Security Audits · ISO 27001 · SOC 2 · DPDP Act 2023

Tooling Burp Suite OWASP ZAP Mend Twistlock Metasploit Nmap Nuclei Nessus Sentinel Azure WAF


🎖 Certifications

ISO/IEC 27001 Lead Auditor · CEH v11 (EC-Council) · CCEP · CNSS (ICSI UK) · Autopsy · OSForensics Triage · DPDP Act 2023 — 96%


Open to product security, application security, DevSecOps and VAPT roles.

Popular repositories Loading

  1. bugbountyDorks bugbountyDorks Public

    Forked from shifa123/bugbountyDorks

    This repo contains all the Bug Bounty Dorks sourced from different awesome sources and compiled at one place

    3

  2. BurpSuite_403Bypasser BurpSuite_403Bypasser Public

    Forked from sting8k/BurpSuite_403Bypasser

    Burpsuite Extension to bypass 403 restricted directory

    Python 2

  3. bug-bounty-dorks bug-bounty-dorks Public

    Forked from sushiwushi/bug-bounty-dorks

    List of Google Dorks for sites that have responsible disclosure program / bug bounty program

  4. The-Bounty-Dorks The-Bounty-Dorks Public

    Forked from shauryasharma-05/The-Bounty-Dorks

    Now use your favorite Google Dorks techniques to find vulnerabilities and earn Bounties.

  5. Gophish-Template Gophish-Template Public

    Gophish landing-page templates for authorised phishing-simulation and security-awareness exercises

    HTML

  6. Zoom-Meeting-Archive-URL-Fetcher Zoom-Meeting-Archive-URL-Fetcher Public

    OSINT recon tool: surfaces password-bearing Zoom meeting URLs from Wayback Machine archives

    Python