SECURING THE FUTURE OF TECH.
I am Shashank Pachori (alias: crypticrhino0). Security Researcher | VAPT & Recon Tooling | Community Builder.
"You don't understand a vulnerability class until you've triggered it yourself."
BEYOND THE THEORY LOOP
THE MOMENT IT CLICKED
I spent my first stretch of security education buried in manuals and definitions - theory that looked complete on paper and told me nothing about how a real system actually breaks. The gap became obvious the first time I tried to apply it and couldn't.
That gap is what pushed me off the theory loop. I installed Kali, opened HackTheBox and TryHackMe, and started testing what I'd read against systems that don't care if you understood the concept - only whether the exploit works. The first time a lab I'd been stuck on for hours finally gave up its flag, that was the moment: theory is a starting point, not the work itself.
That's the mindset I've carried since - into VAPT, into recon tooling, into every disclosure I've filed. You don't understand a vulnerability class until you've triggered it yourself.
THE ARSENAL
SKILLS_MARQUEE.EXEOPERATIONS & BUILDS
Active projects, security scripts, and code contributions.
VEXTIX (IDevSec)
A custom OSINT and Reconnaissance tool designed to automate subdomain enumeration and vulnerability analysis. Built to scan large scopes concurrently, identifying critical P4/P5 issues such as missing HSTS, missing Content Security Policies (CSP), and insecure cookie attributes. Generates structured JSON reports for threat mapping.
ModuSec (IDevSec)View on PyPI
Modular Python-based reconnaissance and security auditing framework, published on PyPI. Contributed reconnaissance modules, security testing logic, and framework enhancements, plus ongoing bug reports identifying false positives across the clickjacking, IP exposure, and file-discovery modules.
CERTIFICATIONS
Verified industry credentials, accreditations, and technical security training.
DISCLOSURES / FINDINGS
Responsible disclosures, vulnerability reports, and program acknowledgments.
haryanapolice.gov.in
Missing security headers, clickjacking exposure, and server banner disclosures reported responsibly to NCIIPC India.
smkc.gov.in
Web application security vulnerability discovered during OSINT reconnaissance and reported to NCIIPC.
janbharatrang.nsd.gov.in
Identified web application vulnerability and submitted detailed technical advisory to NCIIPC.
Sonic Healthcare
Web vulnerability and exposure identified and submitted through Bugcrowd vulnerability disclosure program.
Sonic Healthcare (collaboration with fellow IDevSec R&D interns)
Collaborative vulnerability research conducted with IDevSec R&D team members and submitted via Bugcrowd.
Eurofins
Web infrastructure security exposure identified and disclosed through Bugcrowd.
THE BATTLEGROUNDS
CTF scoreboards and live repository footprints.
ARCADE LEADERBOARD
SCOREBOARD: ACTIVEHACK THE BOO 2024
Secured rank 1,339 out of 8,153 teams globally. Solved 7 challenging categories, demonstrating hands-on exploitation of SQL Injections and system commands.
THE DARK SIDE OF AI
An academic and ethical critique of artificial intelligence in modern conflict.
LETHAL AUTONOMOUS WEAPONS (LAWS)
Analysis of unmanned algorithmic targeting platforms. Investigated systems like the Kargu-2 Drone and artificial intelligence military targeting engines such as "Lavender AI" and "The Gospel," highlighting their deployment boundaries and structural hazards.
COGNITIVE WARFARE & DEEPFAKES
Tracking the evolution of cyber warfare from Stuxnet to AI-enhanced phishing. Examining how neural networks generate high-fidelity audio/video deepfakes for psychological campaigns and cognitive influence, blurring verification vectors.
MILITARY CONTRACTS & OPENAI
Critical assessment of the OpenAI-Pentagon deal and the removal of clauses banning military integration. Discussing the policy implications when commercial LLMs are modified to support cybersecurity, logistics, and battlefield command structures.
COMMUNITY FOOTPRINT
Chapters led, symposiums organized, and student communities scaled.
DCG91124 (DEFCON GURUGRAM)
Team Member // Event Coordinator
Active team member working alongside fellow team members to host cybersecurity platforms and drive student engagement.
0x0 PIR4T3S
Chapter Lead // BIT-SEC-CON Coordinator
Appointed as Chapter Lead for the IBMR Business School Chapter, driving student recruitment and helping students in their cybersecurity journey while building interactive security training labs.
BYTE BENDERS (IT CLUB)
President // IT Club Lead
Elected as President of the official IT Club at IBMR Business School, overseeing club activities, technological workshops, and intra-college events.
