Offensive security consultant focused on web application & API penetration testing, now extending into AI/LLM red teaming. I break production systems for a living and build in public under HariHax — research, writeups, and everything I learn along the way.
I'm a Technical Consultant at CyRAACS, where I run web application, API, network, and Active Directory security assessments across fintech and enterprise environments.
My work is manual-first — I go beyond automated scanners to chain business logic flaws, authorization bypasses, and complex attack paths that tools miss. I'm now extending that skillset into AI/LLM red teaming, testing the systems companies are racing to deploy without securing first, and integrating AI into my own testing workflow.
HariHax is my public identity — bug hunting, certifications, research, writeups, and video. Building in the open, one finding at a time.