[ INITIALIZING PROFILE... ACCESS GRANTED ]
SAURABH TIWARI
// JUNIOR PENETRATION TESTER  ·  VAPT  ·  CEH MASTER  ·  SECURITY ANALYST
saurabh@kali:~$ whoami --verbose
name : Saurabh Sujeet Tiwari
role : Junior Penetration Tester | VAPT | Security Analyst
cert : CEH Master — EC-Council
location : Diva, Maharashtra, India
status : ACTIVELY HUNTING
20+
VULNS FOUND
10+
LAB ENVIRONMENTS
30+
PORTSWIGGER LABS
50+
NMAP TARGETS
6mo
FIELD EXPERIENCE
8.2
CGPA / 10
[ 01 ]
ABOUT

CEH Master-certified penetration tester with 6 months of hands-on internship experience in web application VAPT and vulnerability management at Mastermind Security Pvt. Ltd.

Identified and documented 20+ vulnerabilities (SQLi, XSS, IDOR, broken auth) across 10+ lab environments with CVSS severity ratings. Proficient in Burp Suite, Nmap, Metasploit, and Kali Linux.

Hands-on experience with Splunk for log analysis and security event monitoring. Actively hunting bugs on HackerOne and publishing detailed vulnerability write-ups on GitHub.

Sharpening skills daily on TryHackMe, HackTheBox and PortSwigger — all on dedicated lab setups, never production systems. The grind never stops. 🔐

// NAME
Saurabh Sujeet Tiwari
// LOCATION
Diva, Maharashtra, India
// PHONE
+91-7400269686
// LINKEDIN
// HACKERONE
// DOMAIN
Cybersecurity / InfoSec
// STATUS
Open to Opportunities ✓
[ 02 ]
CERTIFICATIONS
★ MASTER
CEH Master
Certified Ethical Hacker Master
EC-Council
VERIFIED · ACTIVE
CEH
Certified Ethical Hacker
EC-Council
VERIFIED · ACTIVE
CAPT
Certified Associate Penetration Tester
Hackviser
IN PROGRESS
Python
Python Programming Certificate
TCRI
COMPLETED
[ 03 ]
ARSENAL
// PENETRATION TESTING & VAPT
Web App VAPTNetwork PentestingOWASP Top 10Manual TestingAPI TestingAuth TestingSession ManagementCVSS ScoringPentest Reporting
// EXPLOITATION
SQL InjectionXSSIDORAuth BypassBroken Access ControlParameter Tampering
// TOOLS
Burp SuiteMetasploitNmapWiresharkSQLmapSubfinderKali LinuxSplunk
// RECON & OSINT
Subdomain EnumerationService DetectionDirectory Brute-ForceBasic OSINTReconnaissance
// SIEM & MONITORING
SplunkSPL QueriesLog IngestionDashboard CreationAlert TriageSOC Concepts
// NETWORKING & OS
TCP/IPDNSHTTP/HTTPSSSL/TLSKali LinuxUbuntu/DebianWindows
// PROGRAMMING
Python (Scripting)BashCC++
// PLATFORMS
TryHackMeHackTheBoxPortSwiggerVulnHubHackerOne
[ 04 ]
FIELD EXPERIENCE
CYBER SECURITY INTERN
Mastermind Security Pvt. Ltd.
May 2025 – Oct 2025
[6 MONTHS]
[ 05 ]
OPERATIONS / PROJECTS
// OP-01 · WEB APP SECURITY
Web App VAPT Lab
Tested for SQLi, XSS, IDOR, and auth bypass using Burp Suite on PortSwigger labs (30+ completed) and local VMs. Intercepted and modified HTTP requests, analyzed cookies and session tokens.
Burp SuiteOWASP Top 10PortSwiggerDVWA
// OP-02 · NETWORK RECON
Network Scanning & Fingerprinting
Port scanning and service fingerprinting with Nmap across 50+ simulated targets — identified open ports, services, OS versions, and potential attack vectors for reporting.
NmapWiresharkTCP/IPService Detection
// OP-03 · PRIVILEGE ESCALATION
Linux PrivEsc Research
Practiced SUID abuse, cron job misconfigurations, and weak file permissions on TryHackMe and VulnHub. Documented escalation paths and built a personal cheatsheet for common vectors.
Kali LinuxTryHackMeVulnHubSUID
// OP-04 · SIEM
Splunk SIEM Lab
Ingested security logs into Splunk, wrote SPL queries to detect failed logins and unusual network traffic. Built basic security dashboards for event visualization and alert triage.
SplunkSPLLog AnalysisSOC
// OP-05 · BUG BOUNTY
HackerOne Bug Bounty
Active bug bounty hunter on HackerOne (saurabht004). Performing recon and vulnerability testing on in-scope web targets — subdomain enumeration, API endpoint discovery, and parameter fuzzing.
HackerOneSubfinderOSINTAPI Fuzzing
// OP-06 · HOME LAB
Self-Hosted Pentest Lab
Maintained a self-hosted penetration testing lab with DVWA, WebGoat, and custom VMs for hands-on vulnerability research and exploit practice — all on isolated, non-production systems.
DVWAWebGoatVirtualBoxKali Linux
[ 06 ]
VULNERABILITY PROGRESS
> DOCUMENTING EXPLOITATION TECHNIQUES, METHODOLOGY & REMEDIATION — github.com/saurabht004
// WU-01 · SQL INJECTION
SQL Injection — Exploitation & Bypass
Step-by-step write-up covering Union-based, Error-based, and Blind SQLi techniques. Includes payload crafting, WAF bypass methods, and remediation with parameterized queries.
SQLiBurp SuiteSQLmapOWASP
// WU-02 · XSS
Cross-Site Scripting (XSS) Techniques
Detailed methodology for Reflected, Stored, and DOM-based XSS. Covers payload obfuscation, cookie stealing PoC, and CSP bypass techniques with full remediation steps.
XSSJavaScriptBurp SuitePortSwigger
// WU-03 · IDOR
IDOR — Broken Access Control
Write-up on Insecure Direct Object Reference vulnerabilities — horizontal and vertical privilege escalation, parameter manipulation, and real-world exploitation scenarios with fix recommendations.
IDORAccess ControlBurp SuiteOWASP Top 10
// WU-04 · AUTH BYPASS
Authentication Bypass Techniques
Covers broken authentication — session token analysis, cookie manipulation, brute force with Hydra, and JWT weaknesses. Full PoC on DVWA and WebGoat environments.
Auth BypassHydraJWTDVWA
// WU-05 · LINUX PRIVESC
Linux Privilege Escalation
Documented SUID abuse, cron job misconfigurations, weak file permissions, and PATH hijacking. Practiced on TryHackMe and VulnHub with full escalation path write-ups.
LinuxSUIDTryHackMeVulnHub
// WU-06 · BUG BOUNTY
HackerOne Recon & Bug Reports
Active bug bounty write-ups on HackerOne in-scope targets — subdomain enumeration with Subfinder, API endpoint discovery, parameter fuzzing, and vulnerability reporting methodology.
HackerOneReconSubfinderAPI Testing
[ VIEW ALL WRITE-UPS ON GITHUB ]
[ 07 ]
EDUCATION
BCA — Bachelor of Computer Applications
Sahyog College of Management and IT, Thane
2025
CGPA: 8.2 / 10
HSC — Higher Secondary Certificate
Royal College of Commerce & IT, Dombivli
2022
SSC — Secondary School Certificate
S.R.P High School, Chembur
2020
[ 08 ]
CONTACT
> OPEN TO ENTRY-LEVEL OPPORTUNITIES IN PENETRATION TESTING / VAPT / SECURITY ANALYSIS
@
// EMAIL
tsaurabh163@gmail.com
#
// PHONE
+91-7400269686
in
// LINKEDIN
saurabhtiwari004
</>
// GITHUB
github.com/saurabht004
H1
// HACKERONE
saurabht004
THM
// TRYHACKME
Active Practitioner