Skip to content
View PratikKaran23's full-sized avatar

Block or report PratikKaran23

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
PratikKaran23/README.md
Pratik Karan Cycling achievements

       



About

Security Consultant at Prescient Security with deep focus on Web, API, Mobile, and Thick Client penetration testing. Discovered and reported 500+ vulnerabilities across public and private programs. Ranked #1 on Qwilr's Security Hall of Fame. Active bug bounty hunter on HackerOne as bloody_eye.

Currently exploring how AI augments offensive security workflows — specifically AI-assisted recon, JS analysis for endpoint discovery, and intelligent payload generation for WAF bypass.


Expertise

Domain Specialization Level
Web Application Security OWASP Top 10, Logic Flaws, Auth Bypass, IDOR Advanced
API Security REST, GraphQL, SOAP — Auth, Rate Limit, Injection Advanced
Mobile Pentesting Android APK reverse engineering, Frida, SSL Pinning Advanced
Thick Client Assessment .NET, Java, traffic interception, binary analysis Intermediate+
Bug Bounty Hunting HackerOne — 500+ validated vulns, #1 Qwilr HoF Advanced
AI-Assisted Recon JS analysis, endpoint discovery, payload generation Developing

Certifications

Certification Issuer
01 Offensive Security Certified Professional — OSCP Offensive Security
02 Offensive Security Web Expert — OSWE Offensive Security
03 Burp Suite Certified Practitioner — BSCP PortSwigger

Notable

  • #1 — Qwilr Security Hall of Fame
  • 500+ — Validated vulnerabilities reported
  • Active hunter on HackerOne · handle: bloody_eye
  • Consultant at Prescient Security — Web · API · Mobile · Thick Client

Stack

Burp Suite  OWASP  Kali Linux  Python  Bash  Frida  Nuclei  Caido


Security Consultant · Penetration Tester · Bug Bounty Hunter

Pinned Loading

  1. keysentinel keysentinel Public

    Universal API key validator for security researchers and bug bounty hunters - 19 providers, live validation

    JavaScript

  2. jsbleed jsbleed Public

    Recon & JS analysis tool for bug bounty hunters - finds secrets, endpoints, auth flaws & source maps in JS files

    Python