HarikrishnanVJ
I break systems to prove how they hold — mapping attack surface, validating exploitability, and engineering the defenses that close the gap.
An adversary's instinct. A defender's discipline.

Adversarial Mindset
Every system is a hypothesis waiting to be tested. I assume breach and work backward to the weakest link.
Evidence Over Assumption
Findings are proven with reproducible exploitation, captured artifacts, and verifiable impact — never speculation.
Defense by Design
Offense without remediation is just noise. Each finding ships with a concrete, prioritized path to resolution.
In the field, right now.
Where the methodology meets a live environment — applying offensive testing against real production infrastructure.
VAPT Intern
CurrentBima Sugam India Federation
Internship
Hands-on vulnerability assessment and penetration testing across the digital insurance infrastructure of India's national insurance-platform federation.
- Run end-to-end VAPT engagements against web applications and network services, mapping attack surface and validating real exploitability.
- Test against the OWASP Top 10 and document findings with reproducible proof-of-concept and risk-rated severity.
- Translate findings into clear, prioritized remediation guidance for engineering teams — closing the loop from offense to defense.
Full-spectrum security expertise
Six core domains spanning offense, defense, and the infrastructure in between — each backed by hands-on practice and industry certification.
Vulnerability Assessment & Penetration Testing
End-to-end VAPT — from automated discovery to manual exploitation and risk-rated reporting.
Network Security
Mapping topology, hunting exposed services, and validating segmentation under real attack conditions.
Digital Forensics
Disk, memory, and network forensics with rigorous evidence preservation and chain of custody.
Threat Detection & Modeling
Purple-team detection engineering mapped to MITRE ATT&CK, closing the loop between attack and alert.
Application & Web Security
OWASP-driven testing of web surfaces — source review, injection, and logic-flaw hunting.
Systems & Infrastructure
Linux administration and automation that bakes security into the operational baseline.
continuous attack-surface monitoring
Engagements, decoded.
Tooling and CTF work presented the way real assessments are reported — challenge, methodology, findings, and measurable impact.
Manual recon is slow and inconsistent. Analysts need a portable, repeatable way to map a target and instantly surface known exploits for discovered services.
Built a Dockerized pipeline orchestrating Nmap service/version detection, then piping enumerated services into SearchSploit to correlate live exploit availability — fully scripted in Bash for one-command deployment.
Reduced the discovery-to-exploit-intel loop from a multi-tool manual workflow to a single reproducible container run, with consistent output across any host environment.
A drop-in recon asset that standardizes the earliest, most error-prone phase of an engagement and accelerates triage.
Where the depth is.
A self-assessed map across the three pillars I operate in — offense, defense, and the systems beneath both.
Offensive Security
Defense & Forensics
Systems & Code
A deliberate climb.
From foundational network-security certs to a stacked year of offensive specialization — every step compounding toward depth.
Penetration Testing Specialization
CompTIA Career Pathway
Stacked six advanced security certifications in a single year — PenTest+, CySA+, Security+, and the Network Security / Vulnerability Assessment professional tracks.
Forensics & Infrastructure Depth
Quick Heal · Red Hat
Certified Digital Forensic Investigator alongside Red Hat RHCSA-track administration — pairing investigation skill with the systems knowledge to defend them.
B.Tech, Computer Science & Engineering
Lovely Professional University
Building the formal CS foundation while competing in CTFs and climbing to the top 1% on TryHackMe.
Security Foundations
Fortinet NSE · CNSE
Earliest steps into the discipline — network security engineering foundations that set the trajectory.
Credentials & recognition
Thirteen industry certifications and a competitive record that proves the skills in the open.
Certifications
— 13 earnedCompetitive Record
Global Ranking
TryHackMe · Sustained hands-on dominance
Pentathon CTF
National CTF · Multi-discipline challenge
Chakravyuh CTF
Competitive CTF · Podium finish
TechnOcean CTF
Competitive CTF · Top-tier placement
AIESEC Hackathon
Hackathon · Selection round cleared
Global standing on TryHackMe
Let's find the
gaps before they do.
Open to penetration testing roles, security engineering positions, and collaborative research. If you need someone who thinks like an attacker and ships like a defender — let's talk.