Adarsh.

Hey 👋, I’m Adarsh

Security Consultant

Security consultant and researcher specialising in web, API, and Android penetration testing and authorization testing. 200+ findings across 14+ client engagements. Founder and lead of a top 1% nationally ranked CTF team.

Adarsh SR, application security consultant and founder of TRIADA CTF

200+

Findings reported

14+

Client engagements

Top 1%

CTFtime, India

50+

Challenges authored

70+

Teams at CTF 2026

200+

Findings reported

14+

Client engagements

Top 1%

CTFtime, India

50+

Challenges authored

70+

Teams at CTF 2026

About

Summary

Application security consultant specialising in authorization and business logic testing across web, REST API, and Android. Reported 200+ findings over 14+ client engagements in insurance, financial services, healthcare, utilities, and manufacturing, including broken object level authorization on payment and claims endpoints and session lifecycle failures missed by prior audits. Independent vulnerability researcher with confirmed findings against NASA, Signicat, and the Government of Canada. Founder of TRIADA, a top 1% nationally ranked CTF team.

Career

Experience

Security Consultant

Aug 2026 – Present
BOLA across payment, document, and permissions endpointsSession and JWT lifecycle failures14+ client-ready pentest reports, CVSS-rated

Security Analyst Intern

Feb 2026 – Jul 2026
Unauthenticated data exposure via filter bypassAndroid OAuth and biometric flaws via SAST/DASTSubdomain takeover and EOL CVEs

Founder and Team Lead at TRIADA

Apr 2024 – Present
TRIADA CTF 2026: 70+ teams, Rs. 4.3L+ prize poolGrew team to top 1% on CTFtime nationally50+ original challenges designed

Core Team Member at VULNCON

May 2024 – Present
Built the event web interface, 500+ attendees

Education

Yenepoya University

Bachelor of Computer Applications, specialising in Cybersecurity, Ethical Hacking, and Digital Forensics

Bangalore, India · Oct 2023 – 2026

Certifications

  • Certified API Security Analyst (CASA)

    APIsec University

  • Exposure Management Expert

    XM Cyber

Toolkit

Skills

Testing
Authorization & business logic, Web / API / Android pentesting, SAST / DAST, Threat modeling
Tooling
Burp Suite, sqlmap, Frida, MobSF, Nmap, ffuf, Ghidra
Standards
OWASP Top 10, OWASP MASVS, CVSS v3.1, CWE
Engineering
Python, TypeScript, Next.js, Prisma, Docker, GitHub Actions

Track record

Achievements

  • Top 1% national ranking on CTFtime · Top 1% on TryHackMe
  • 1st Runner Up, Threat Hunting Village CTF, Seasides Goa, 2025
  • 2nd Runner Up, Seasides Offline CTF, 2026
  • 2nd Runner Up, B5CTF, BSides Bangalore
  • 5th Place, bi0s CTF
  • Finalist, IBM National Hackathon, 2024

Client work

Engagements

Most engagements are covered by NDA, so specifics stay general. What follows is the shape of the work.

01Web / API / Android

Insurance, North America

Cross-account object access, token lifecycle flaws, mobile credential storage issues.

02External

Healthcare and Pharma Services

Subdomain takeover, unauthenticated management interfaces, EOL services with known CVEs.

03Web / API

Utilities and Metering

Unauthenticated access via filter bypass, unauthenticated token issuance.

04Web

Industrial Manufacturing

Eight internal workflow apps, vendor and customer master data through capital approval.

Reporting

CVSS v3.1 scoring, CWE mapping, developer-focused remediation.

Retest

Walked through with the client engineering team, verified before close.

Negative results

Documents what was tested and found sound, not just what broke.

Building

Projects

Proct

Assessment platform with a published threat model.

Quiz platform for institutional assessment built on Next.js, React, Prisma, and NextAuth: 22,000 lines across 29 API routes with 22 test suites. Every integrity control is enforced server-side, including sequencing, timing, and grading, so a tampered browser cannot read ahead, extend its own time, or recover an answer key. Published a threat model separating enforced controls from detection-only signals.

Next.js · Prisma · NextAuth · Threat modelling

TRIADA News

AI-enriched threat intelligence pipeline.

Aggregates 34 security sources hourly through GitHub Actions, covering vendor advisories, threat research, national CERTs, and cloud security bulletins. Extracts CVE identifiers, cross-references the CISA Known Exploited Vulnerabilities catalog, and classifies severity. Model output is treated as untrusted input: every AI response is schema-validated and sanitised, with a deterministic rule-based fallback on failure.

Next.js · GitHub Actions · Gemini · CISA KEV

SOC Automation Toolkit

Python toolkit built for SOC workflows during a TCS engagement.

Log parsing, anomaly detection, and threat-intel enrichment via AbuseIPDB, VirusTotal, and OTX, with automated HTML reporting.

SOC · Threat intel · Automation

TRIADA CTF Platform

Custom CTFd deployment powering TRIADA CTF 2026.

CTFd v3.8.2 redesigned end to end: tiered sponsor integration, custom frontend, and an Easter-egg challenge flag, serving 150+ players across a 24-hour competition.

CTFd · Infra · Frontend

DorkIQ

Reconnaissance tool that generates targeted search dorks.

Finds exposed files, admin panels, and misconfigured endpoints across a target's public footprint.

Recon tooling

Web Pentesting Playground

Deliberately vulnerable training application.

Covers 10+ vulnerability classes including SQL injection, XSS, IDOR, SSRF, and insecure file upload, with guided exploitation scenarios used in student training.

Training platform

Community

TRIADA

I founded TRIADA in 2024 and lead it, running the university’s CTF team and its national competitions.

Top 1%

CTFtime rank, India

50+

Challenges authored

70+

Teams at CTF 2026

₹5.3L+

Prize pool, all events

TRIADA CTF 2026

24-hour national competition. 70+ teams, 150+ players, 20,359 submissions, prize pool above Rs. 4.3 lakh, secured through direct sponsor outreach, run on in-house CTFd infrastructure.

TRIADA CTF 2025

The first CTF held at the university. 100+ participants, challenge design across web, crypto, forensics, and OSINT, sponsorship secured. Established the event that became CTF 2026.

Writeups

Notes from the trenches

Technical writeups on CTF challenge solutions and vulnerability research, covering the approach, exploitation path, and what mattered.

Read writeups

Contact

Get in touch

Open to engagements· Bangalore, India

Interested in collaborating on application security, penetration testing, vulnerability research, or secure software engineering? Let’s connect.