Hey 👋, I’m Adarsh
Security Consultant
Security consultant and researcher specialising in web, API, and Android penetration testing and authorization testing. 200+ findings across 14+ client engagements. Founder and lead of a top 1% nationally ranked CTF team.

200+
Findings reported
14+
Client engagements
Top 1%
CTFtime, India
50+
Challenges authored
70+
Teams at CTF 2026
200+
Findings reported
14+
Client engagements
Top 1%
CTFtime, India
50+
Challenges authored
70+
Teams at CTF 2026
About
Summary
Application security consultant specialising in authorization and business logic testing across web, REST API, and Android. Reported 200+ findings over 14+ client engagements in insurance, financial services, healthcare, utilities, and manufacturing, including broken object level authorization on payment and claims endpoints and session lifecycle failures missed by prior audits. Independent vulnerability researcher with confirmed findings against NASA, Signicat, and the Government of Canada. Founder of TRIADA, a top 1% nationally ranked CTF team.
Career
Experience
Security Consultant
Aug 2026 – PresentSecurity Analyst Intern
Feb 2026 – Jul 2026Founder and Team Lead at TRIADA
Apr 2024 – PresentCore Team Member at VULNCON
May 2024 – PresentEducation
Yenepoya University
Bachelor of Computer Applications, specialising in Cybersecurity, Ethical Hacking, and Digital Forensics
Bangalore, India · Oct 2023 – 2026
Certifications
Certified API Security Analyst (CASA)
APIsec University
Exposure Management Expert
XM Cyber
Toolkit
Skills
Track record
Achievements
- Top 1% national ranking on CTFtime · Top 1% on TryHackMe
- 1st Runner Up, Threat Hunting Village CTF, Seasides Goa, 2025
- 2nd Runner Up, Seasides Offline CTF, 2026
- 2nd Runner Up, B5CTF, BSides Bangalore
- 5th Place, bi0s CTF
- Finalist, IBM National Hackathon, 2024
Client work
Engagements
Most engagements are covered by NDA, so specifics stay general. What follows is the shape of the work.
Insurance, North America
Cross-account object access, token lifecycle flaws, mobile credential storage issues.
Healthcare and Pharma Services
Subdomain takeover, unauthenticated management interfaces, EOL services with known CVEs.
Utilities and Metering
Unauthenticated access via filter bypass, unauthenticated token issuance.
Industrial Manufacturing
Eight internal workflow apps, vendor and customer master data through capital approval.
Reporting
CVSS v3.1 scoring, CWE mapping, developer-focused remediation.
Retest
Walked through with the client engineering team, verified before close.
Negative results
Documents what was tested and found sound, not just what broke.
Building
Projects
Proct
Assessment platform with a published threat model.
Quiz platform for institutional assessment built on Next.js, React, Prisma, and NextAuth: 22,000 lines across 29 API routes with 22 test suites. Every integrity control is enforced server-side, including sequencing, timing, and grading, so a tampered browser cannot read ahead, extend its own time, or recover an answer key. Published a threat model separating enforced controls from detection-only signals.
Next.js · Prisma · NextAuth · Threat modelling
TRIADA News
AI-enriched threat intelligence pipeline.
Aggregates 34 security sources hourly through GitHub Actions, covering vendor advisories, threat research, national CERTs, and cloud security bulletins. Extracts CVE identifiers, cross-references the CISA Known Exploited Vulnerabilities catalog, and classifies severity. Model output is treated as untrusted input: every AI response is schema-validated and sanitised, with a deterministic rule-based fallback on failure.
Next.js · GitHub Actions · Gemini · CISA KEV
SOC Automation Toolkit
Python toolkit built for SOC workflows during a TCS engagement.
Log parsing, anomaly detection, and threat-intel enrichment via AbuseIPDB, VirusTotal, and OTX, with automated HTML reporting.
SOC · Threat intel · Automation
TRIADA CTF Platform
Custom CTFd deployment powering TRIADA CTF 2026.
CTFd v3.8.2 redesigned end to end: tiered sponsor integration, custom frontend, and an Easter-egg challenge flag, serving 150+ players across a 24-hour competition.
CTFd · Infra · Frontend
DorkIQ
Reconnaissance tool that generates targeted search dorks.
Finds exposed files, admin panels, and misconfigured endpoints across a target's public footprint.
Recon tooling
Web Pentesting Playground
Deliberately vulnerable training application.
Covers 10+ vulnerability classes including SQL injection, XSS, IDOR, SSRF, and insecure file upload, with guided exploitation scenarios used in student training.
Training platform
Community
TRIADA
I founded TRIADA in 2024 and lead it, running the university’s CTF team and its national competitions.
Top 1%
CTFtime rank, India
50+
Challenges authored
70+
Teams at CTF 2026
₹5.3L+
Prize pool, all events
TRIADA CTF 2026
24-hour national competition. 70+ teams, 150+ players, 20,359 submissions, prize pool above Rs. 4.3 lakh, secured through direct sponsor outreach, run on in-house CTFd infrastructure.
TRIADA CTF 2025
The first CTF held at the university. 100+ participants, challenge design across web, crypto, forensics, and OSINT, sponsorship secured. Established the event that became CTF 2026.
Moments
Gallery






Writeups
Notes from the trenches
Technical writeups on CTF challenge solutions and vulnerability research, covering the approach, exploitation path, and what mattered.
Read writeupsContact
Get in touch
Interested in collaborating on application security, penetration testing, vulnerability research, or secure software engineering? Let’s connect.