Open to opportunities
$ whoami // Hariom Singh

HariHax

Offensive security consultant focused on web application & API penetration testing, now extending into AI/LLM red teaming. I break production systems for a living and build in public under HariHax — research, writeups, and everything I learn along the way.

harihax@offsec:~
cat profile.json
{
  "role": "Security Consultant",
  "focus": ["web", "api", "ai"],
  "certs": "eJPT, CRTA, eWPTX",
  "next": "HTB COAE",
  "status": "hunting"
}
./run_assessment.sh

What I Do

01
🌐
Web & API Pentesting
Manual exploitation of business logic, auth, and authorization flaws across fintech & enterprise apps.
02
🤖
AI / LLM Red Teaming
Prompt injection, jailbreaks, RAG attacks, and agentic abuse against AI-powered features.
03
🎯
Bug Hunting
Hunting on self-hosted public programs using real-world web & API attack chains.
04
✍️
Research & Content
Publishing writeups and video research on offensive security and AI attacks.

I'm a Technical Consultant at CyRAACS, where I run web application, API, network, and Active Directory security assessments across fintech and enterprise environments.

My work is manual-first — I go beyond automated scanners to chain business logic flaws, authorization bypasses, and complex attack paths that tools miss. I'm now extending that skillset into AI/LLM red teaming, testing the systems companies are racing to deploy without securing first, and integrating AI into my own testing workflow.

HariHax is my public identity — bug hunting, certifications, research, writeups, and video. Building in the open, one finding at a time.

0
Web & API Assessments
0
Certifications
0
Years in Security
🌐
Web & API Security
OWASP Top 10, IDOR/BOLA, BFLA, SSRF, auth bypass, business logic, GraphQL & REST. Black-box and gray-box.
🤖
AI / LLM Red Teaming
Prompt injection, jailbreaking, RAG pipeline attacks, agentic abuse. Pursuing HTB COAE.
🏗️
Network, AD & Infra
Internal/external network PT, AD assessments, firewall & secure config reviews (CIS / STIG).
☁️
Cloud Security
Cloud fundamentals & security basics — IAM misconfigs, exposed services, cloud recon.

Work History

Technical Consultant — Offensive Security
Jan 2025 – Present
CyRAACS Services Private Limited · Bengaluru, Karnataka
  • Conducted 50+ web application and API penetration tests across fintech and enterprise platforms using black-box and gray-box methodologies.
  • Identified and validated critical vulnerabilities — IDOR, SSRF, SQLi, XSS, CSRF, authentication flaws, and authorization bypasses affecting business-critical functionality.
  • Assessed REST and GraphQL APIs for authentication, authorization, input validation, and business logic vulnerabilities beyond automated scanner coverage.
  • Performed internal and external network penetration testing and Active Directory assessments — enumeration, privilege escalation, lateral movement, and misconfiguration analysis.
  • Ran secure configuration reviews for VDI environments, Windows endpoints, and network devices aligned with CIS and STIG benchmarks.
  • Built automation in Python, PowerShell, and Bash to streamline recon, enumeration, and vulnerability validation workflows.
  • Mentored junior analysts and interns on web app testing, vulnerability validation, and technical reporting.
Cyber Security Intern
Apr 2024 – Jun 2024
Center for Cyber Security Studies & Research · Jaipur (Remote)
  • Assisted in VAPT of web applications and network environments aligned with OWASP Top 10.
  • Performed reconnaissance and vulnerability scanning using industry-standard tooling.
  • Prepared vulnerability reports and supported remediation validation.

Technical Stack

Web & API
Burp Suite Pro OWASP Top 10 SQL Injection XSS / CSRF SSRF IDOR / BOLA BFLA Auth Bypass GraphQL REST APIs JWT Attacks FFUF Katana Nuclei
AI / LLM Security
Prompt Injection Jailbreaking OWASP LLM Top 10 RAG Attacks Agentic Abuse Prompt Extraction MITRE ATLAS LLM API Testing AI-Augmented Testing
Network / AD / Infra
Nmap Nessus Expert Metasploit Wireshark Active Directory BloodHound Impacket Firewall Audits CIS / STIG Wi-Fi PT
Recon & Tooling
Python Bash PowerShell Amass Subfinder HTTPX gau Waybackurls Claude Code Kali Linux Git

Certifications & Projects

🎯
eJPT
Junior Penetration Tester · INE Security
Oct 2024
🔴
CRTA
Certified Red Team Analyst · CyberWarfare Labs
Mar 2026
🌐
eWPTX
Web App Pentester eXtreme · INE Security
May 2026
🤖
COAE
Certified Offensive AI Expert · Hack The Box
In Progress
Projects
🔭
NetInspector — Network Port Scanner
Python · Sep 2024
Python-based port scanner with TCP Connect and SYN scanning, service version detection, and basic OS fingerprinting. Multithreaded for speed across large IP ranges, with a modular architecture covering host discovery, port scanning, and service enumeration.

Research & Writeups

// Currently researching & writing on
AI / LLM Security Prompt Injection API Attack Chains Claude Code + Burp Workflow Business Logic Flaws Self-Hosted BB Methodology Recon Automation

Get In Touch

Open to freelance VAPT engagements, security research collaborations, and the right opportunities in offensive security and AI red teaming. Got something interesting? Reach out.