Vaibhav Mulak

Offensive Security Practitioner | CTF Player | Security Tool Developer

Junior penetration tester focused on web application security, Linux privilege escalation, and Python automation. Top 1% on TryHackMe. I don't just run tools, I build them.

Scroll

About Me

I'm a self-taught security practitioner currently pursuing a BCA while mastering offensive security through structured labs, CTF competitions, and hands-on tool development. My focus areas include web application exploitation, Linux privilege escalation, and Python-based security automation.

I completed mentored VAPT training at NixSecura, where I practiced reconnaissance, vulnerability identification, exploitation, and post-exploitation in controlled lab environments. I actively participate in CTF competitions and have executed 200+ attack simulation labs on platforms like TryHackMe and VulnHub.

🎯
TryHackMe Top 1%
Ranked among top 1% of 2.1M+ users through consistent lab practice covering red teaming, web security, and Active Directory exploitation.
🛠️
Tool Builder
Built Python-based VAPT automation tools, network intrusion detection systems, and various security utilities from scratch.
🔍
NixSecura Training
Completed 2-month intensive mentorship covering web app and network security testing, red team scenarios, and VAPT methodologies.

What I Do

My technical practice is built on systematic methodology, continuous learning, and hands-on exploitation in controlled environments.

🌐

Web Application Exploitation

Identifying and exploiting OWASP Top 10 vulnerabilities through manual testing and automated scanning. Practiced extensive attack chaining combining multiple vulnerabilities for maximum impact.

XSS SQL Injection IDOR SSRF Access Control CSP Bypass
🐧

Linux Privilege Escalation

Systematic enumeration and exploitation of Linux misconfigurations, SUID binaries, weak file permissions, and sudo misconfigurations to achieve root access.

SUID/SGID Sudo Abuse Cron Jobs Capabilities Kernel Exploits
🐍

Python Security Automation

Building custom security tools to automate reconnaissance, vulnerability scanning, payload generation, and reporting. Focus on reducing manual effort in penetration testing workflows.

Recon Scripts Fuzzing Tools Payload Generation Report Automation Network Scanning

Projects

Security tools and systems built to solve real penetration testing challenges and deepen my understanding of offensive security concepts.

Security Utilities

Python Keylogger

Stealthy cross-platform keystroke logger for Linux and Windows. Built to understand input capture mechanisms and evasion techniques.

View on GitHub →

Multi-threaded Port Scanner

Fast port scanner with banner grabbing capabilities. Implements concurrent scanning techniques for efficient network reconnaissance.

View on GitHub →

C Security Tools

Collection of low-level C programs including buffer overflow playground and memory manipulation utilities for understanding binary exploitation.

View on GitHub →

Achievements

Recognition through competitive performance and community contribution in the cybersecurity field.

🏆

TryHackMe Top 1%

200+ Labs Completed

Ranked in the top 1% among 2.1M+ hackers globally. Completed comprehensive learning paths in Offensive Pentesting, Red Teaming, and Junior Penetration Testing. Successfully executed complex attack chains: Initial Access → Lateral Movement → Privilege Escalation across Linux, Windows, and Active Directory environments.

🎯

Hacker's Gambit CTF

Rank 75 / 400 Teams

Competed in a comprehensive CTF event covering Web Exploitation, Cryptography, Forensics, OSINT, Networking, Reverse Engineering, and Steganography. Demonstrated ability to rapidly adapt to diverse challenge categories under time pressure.

🎤

Community Engagement

Hacker's Meetup (NixSecura)

Co-organized a local offensive security meetup. Performed live red teaming demonstration by compromising a target machine in a controlled environment, explaining the complete attack flow and exploitation logic to attendees.

Blogs & Writeups

Documenting my learning journey through technical blogs, CTF writeups, and cybersecurity guides.

Python for Hackers

Python automation techniques for security practitioners

pythondepth.blogspot.com

InfoSec Path

Comprehensive cybersecurity guides and methodologies

infosecpath.blogspot.com

CTF Writeups

Detailed solutions for TryHackMe, HTB, and PicoCTF challenges

ctfplaybook.blogspot.com

Web Development

Web development tutorials and best practices

codeanddevelop.blogspot.com

Medium Articles

In-depth technical articles on security and development

shieldeddev.medium.com

Contact

Open to opportunities in penetration testing, security research, and tool development. Feel free to reach out for collaboration, questions, or just to discuss security topics.

vaibhavmulak33@gmail.com