0%
PORTFOLIO // v2.0 BASED IN INDIA 00:00:00 IST

SHASHWAT SHAH

> SECURITY ENGINEER / VAPT / OFFENSIVE SECURITY

I break into systems so attackers can't — web apps, APIs and networks, tested the way a real adversary would.

01

WHO AM I

22-year-old security professional with a builder's brain. Bachelor's in Computer Applications, Master's in Cybersecurity — now running vulnerability assessments & penetration tests against real-world targets.

Lately I'm deep into AI & agentic systems — agentic coding, and pushing AI into offensive security. I've wired Claude Code into Burp Suite via a custom MCP server, and built a Kali MCP server too — so an AI agent can actually drive the tools I pentest with. The future of VAPT is human judgement plus agentic speed, and I'm building toward it.

0+ VULNERABILITIES REPORTED
0 DEGREES — BCA / M.Sc CYBERSEC
0 CUSTOM MCP SERVERS BUILT
02

ARSENAL

// OFFENSIVE

  • Burp Suite Pro
  • Nmap / Nessus
  • Metasploit
  • OWASP Top 10
  • API Testing

// BUILD & AI

  • JavaScript / TS
  • Python
  • React / Node
  • MCP / Agentic AI
  • Claude Code

// STANDARDS

  • OWASP WSTG
  • PTES
  • CVSS Scoring
  • ISO 27001 aware
  • Report Writing
03

SELECTED WORK

01 2026

STOCK BROKING PLATFORMS

FINTECH / TRADING — CONFIDENTIAL

Web & API penetration tests across multiple stock-broking platforms — authentication, order execution, funds movement and trading workflows tested against real adversary tactics.

WEB APP PENTESTAPI SECURITYTRADING FLOWS
MULTIPLE BROKERS
ASSESSED
02 2026

AI-AUGMENTED PENTESTING

SECURITY R&D — OWN TOOLING

Built custom MCP servers wiring Claude Code into Burp Suite and Kali Linux — letting an AI agent drive real offensive tooling: recon, request tampering and exploitation, human-in-the-loop.

MCP SERVERBURP SUITEKALIAGENTIC AI
AI-DRIVEN
OFFENSIVE OPS
03 2025

STATE ENTRANCE-EXAM PORTAL

GOVERNMENT / EDTECH — CONFIDENTIAL

Admin-portal VAPT for a large state-level entrance-examination system — access control, privilege boundaries and candidate-data protection across the administrative back-end.

WEB APP PENTESTACCESS CONTROLADMIN PANEL
ADMIN PORTAL
HARDENED

* CLIENT NAMES WITHHELD UNDER NDA — FULL CASE STUDIES & REPORTS ON REQUEST

> INITIATE HANDSHAKE

LET'S BUILD
SOMETHING SECURE