$ ssh guest@codebreaker25 — connected

[ Akash Gupta ]

 

Security Engineer with hands-on experience in VAPT, security automation, and offensive tooling — building custom security tools and wiring AI into pentesting workflows.

77th / 22,000+ · Pentathon 2025
130+ HTB/CTF writeups
6/6 · FamPay CTF full clear
@ Sopra Banking Software
▶ launch terminal contact me

Interactive shell — type help to begin. Try whoami, projects, ctf, matrix… (there are hidden commands 🚩)

guest@codebreaker25: ~

about

whoami --verbose

I'm a Security Engineer focused on offensive security — VAPT, security automation, and building the tooling that makes red-team work faster. I ranked 77th out of 22,000+ in the national Pentathon 2025 CTF, was a CloudSEK CTF finalist, and cleared the full board at the FamPay Security CTF (6/6). I've documented 130+ HackTheBox & CTF writeups along the way.

My work sits at the intersection of offensive security and AI — I build custom recon tools, exploit-chaining workflows, and increasingly integrate LLMs into pentesting via the Model Context Protocol. Currently I contribute to infrastructure automation and AI-powered internal tooling at Sopra Banking Software.

Comfortable across the stack: from binary internals and reverse engineering up through web, API, cloud, and Active Directory security.

       _____
      /  _  \   ____
     /  /_\  \ / ___\
    /    |    / /_/  >
    \____|__  \___  /
            \/_____/
user@host ~ akash@codebreaker25
role: Security Engineer
org: Sopra Banking Software
focus: VAPT · Offensive Tooling · AI
os: Kali · Fedora · WSL
langs: Python · Bash · JS · SQL · C
edu: BCA, JIMS Rohini (2025)
uptime: always learning

experience

cat /var/log/career.log

Junior Engineer — Infrastructure Management Mar 2026 – Present
Sopra Banking Software · Noida (Remote)

projects

ls -la ~/projects

kali-mcp-appliance/
AI-Powered Kali MCP Server

A Model Context Protocol server in a Docker-containerized Kali environment that lets LLMs (Claude / Copilot) orchestrate 15+ pentest tools through natural language. Built on FastMCP over stdio, with OpenVPN for HTB/TryHackMe labs. The AI chains tools intelligently — spot SMB on 445, auto-suggest CrackMapExec. Hardened with shlex input sanitization, 300s command timeouts, and container isolation.

DockerKaliFastMCPPythonOpenVPNLLM
read the writeup →
network-vulnerability-scanner/
Network Vulnerability Scanner

A Python CLI that automates the full assessment pipeline: custom multi-threaded socket port scanning (100+ threads, queue-based), service fingerprinting, dual-mode version detection (banner + nmap -sV), and CVE correlation via the NVD API with semantic-version matching and CVSS scoring. Outputs structured JSON / CSV / TXT reports.

PythonMultithreadingNVD APIpython-nmapCVE/CVSS
view on GitHub →
secure-college-companion/
Secure College Companion

Authenticated Android messaging and announcement app built following secure SDLC and OWASP MASVS principles, with threat modeling applied throughout the design.

AndroidOWASP MASVSSecure SDLC

ctf & competitions

./submit_flag.sh

🚩 FamPay Security CTF — full board clear: solved all 6/6 challenges (1,850 pts, 100% solve rate) spanning Cloud, Web authentication, Firebase security rules, and static/dynamic analysis.
77th
Pentathon 2025
of 22,000+ · national · individual
112/500
CloudSEK CTF — Finalist
qualified from 2,500+
130+
HTB / CTF Writeups
documented & published
60th
CTF 1753
of 600+
~111th
DownUnder CTF 2024
team ranking

Skills demonstrated: Web Exploitation (OWASP), API Security, JWT/SSTI/RCE chains, Binary Exploitation, Reverse Engineering, Privilege Escalation, Recon Automation.

skills

cat skills.json | jq

Offensive Techniques

Web Pentesting (OWASP Top 10)API SecurityREST/GraphQL IDORRole TamperingXSSSQLiJWT Attacks SSTIActive DirectoryPrivilege EscalationSource Code Review

Tools & Frameworks

Burp SuiteNmapWiresharkGhidraGDB/pwndbg BloodHoundImpacketCrackMapExecFFUFDirsearch ExegolOWASP ZAPPostmanDocker

Programming & Scripting

PythonBashJavaScriptSQLC (RE)Assembly (learning)

AI & Automation

MCPLLM Tool IntegrationMicrosoft Copilot Studio RAG PipelinesPython/Bash Automation

Platforms

Kali LinuxFedoraWindowsWSL Hack The BoxTryHackMePortSwigger Labs

writeups & research

git log --oneline ~/blog

Featured technical write-ups published on Medium. Full multi-step exploitation chains, from initial recon to root.

CloudSEK CTF · Round 2 · Finalist
CloudSEK CTF_FINAL 2025 — Multi-step exploitation (JWT → SSTI → RCE)

Chaining a JWT weakness into server-side template injection and finally remote code execution — the full Round 2 finalist submission.

JWTSSTIRCEWeb
read on Medium →
CloudSEK CTF · 2025
CloudSEK CTF 2025 — Writeup

Qualifier writeup walking through the challenge set — recon, auth bypasses, and the reasoning behind each solve.

WebAuthRecon
read on Medium →
Research · Tooling
AI-Powered Kali MCP Appliance

Architecture deep-dive on the containerized Kali appliance — VPN/networking fixes across WSL/Docker and a threat model of the appliance itself.

MCPDockerWSLLLM
read on Medium →

contact

./connect.sh

Open to security engineering, red team, and offensive tooling roles. Let's talk.