Red TeamCTF PlayerTool Developer

SECURING THE FUTURE OF TECH.

I am Shashank Pachori (alias: crypticrhino0). Security Researcher | VAPT & Recon Tooling | Community Builder.

crypticrhino0@gateway:~$
NODE_01 // VAPT● ACTIVE_RECON
NODE_02 // VULN_DISCLOSURES▲ PUBLISHED_REPORTS
> INITIALIZING RECONNAISSANCE...
> HSTS SCANNER: ACTIVE (VEXTIX ENG)
> FRAMEWORK: MODUSEC & VEXTIX
> WARNING: AWARENESS IS FIRST STEP.
[ SYSTEM_CATALYST ]
"You don't understand a vulnerability class until you've triggered it yourself."
This exact realization broke the "theory loop," prompting a deep dive into Kali Linux, HackTheBox, and active security research.

BEYOND THE THEORY LOOP

THE MOMENT IT CLICKED

I spent my first stretch of security education buried in manuals and definitions - theory that looked complete on paper and told me nothing about how a real system actually breaks. The gap became obvious the first time I tried to apply it and couldn't.

That gap is what pushed me off the theory loop. I installed Kali, opened HackTheBox and TryHackMe, and started testing what I'd read against systems that don't care if you understood the concept - only whether the exploit works. The first time a lab I'd been stuck on for hours finally gave up its flag, that was the moment: theory is a starting point, not the work itself.

That's the mindset I've carried since - into VAPT, into recon tooling, into every disclosure I've filed. You don't understand a vulnerability class until you've triggered it yourself.

"You don't understand a vulnerability class until you've triggered it yourself."

THE ARSENAL

SKILLS_MARQUEE.EXE
Burp Suite
Metasploit
Nmap
Gobuster
Nessus
Wireshark
OSINT
Python
Bash
C/C++
SQL
AWS
Linux
Git
GitHub
Burp Suite
Metasploit
Nmap
Gobuster
Nessus
Wireshark
OSINT
Python
Bash
C/C++
SQL
AWS
Linux
Git
GitHub
Reverse Engineering
Network Security
Active Directory
VAPT
Red Teaming
BeautifulSoup
Regex Extraction
HSTS Analyzers
IOT Security
Linux Admin
Docker
Identity Security
Wireshark
OSINT Recon
Reverse Engineering
Network Security
Active Directory
VAPT
Red Teaming
BeautifulSoup
Regex Extraction
HSTS Analyzers
IOT Security
Linux Admin
Docker
Identity Security
Wireshark
OSINT Recon

OPERATIONS & BUILDS

Active projects, security scripts, and code contributions.

STATUS: FEATURED_BUILDS
OSINT / VAPT

VEXTIX (IDevSec)

A custom OSINT and Reconnaissance tool designed to automate subdomain enumeration and vulnerability analysis. Built to scan large scopes concurrently, identifying critical P4/P5 issues such as missing HSTS, missing Content Security Policies (CSP), and insecure cookie attributes. Generates structured JSON reports for threat mapping.

PythonConcurrent ExecutionOSINTJSON Reports
ROLE: SOLE DEVELOPERSTATUS: IN_DEVELOPMENT
PyPI Package

ModuSec (IDevSec)View on PyPI

Modular Python-based reconnaissance and security auditing framework, published on PyPI. Contributed reconnaissance modules, security testing logic, and framework enhancements, plus ongoing bug reports identifying false positives across the clickjacking, IP exposure, and file-discovery modules.

PythonPyPIRecon FrameworkSecurity Auditing
ASSOCIATED WITH: IDEVSECTIMEFRAME: JUL 2026 – PRESENT

DISCLOSURES / FINDINGS

Responsible disclosures, vulnerability reports, and program acknowledgments.

SUBMITTED_FINDINGS: 6
SEVERITY: P5

haryanapolice.gov.in

VULNERABILITY CLASSWeb Exposure / Security Headers

Missing security headers, clickjacking exposure, and server banner disclosures reported responsibly to NCIIPC India.

Acknowledged by NCIIPC
SEVERITY: P5

smkc.gov.in

VULNERABILITY CLASSWeb Vulnerability

Web application security vulnerability discovered during OSINT reconnaissance and reported to NCIIPC.

Acknowledged by NCIIPC
SEVERITY: P5

janbharatrang.nsd.gov.in

VULNERABILITY CLASSWeb Vulnerability

Identified web application vulnerability and submitted detailed technical advisory to NCIIPC.

Acknowledged by NCIIPC
SEVERITY: P5

Sonic Healthcare

VULNERABILITY CLASSWeb Vulnerability / Exposure

Web vulnerability and exposure identified and submitted through Bugcrowd vulnerability disclosure program.

Issued by Bugcrowd
SEVERITY: P5

Sonic Healthcare (collaboration with fellow IDevSec R&D interns)

VULNERABILITY CLASSWeb Vulnerability

Collaborative vulnerability research conducted with IDevSec R&D team members and submitted via Bugcrowd.

Issued by Bugcrowd
SEVERITY: P5

Eurofins

VULNERABILITY CLASSWeb Exposure

Web infrastructure security exposure identified and disclosed through Bugcrowd.

Issued by Bugcrowd

THE BATTLEGROUNDS

CTF scoreboards and live repository footprints.

SCORE: 5,975 POINTS

ARCADE LEADERBOARD

SCOREBOARD: ACTIVE
01crypticrhino0 (HACK THE BOO 2024)
5,975 POINTS
02crypticrhino0 (Disclosures)
LIVE_SYNC
03crypticrhino0 (GitHub Log)
LIVE_SYNC
* Scoreboard telemetry synchronized live across competitive CTFs, vulnerability disclosures, and repository logs.

HACK THE BOO 2024

Secured rank 1,339 out of 8,153 teams globally. Solved 7 challenging categories, demonstrating hands-on exploitation of SQL Injections and system commands.

EVENTHACK THE BOO 2024
SOLVED7 / 18 CHALLENGES
SCORE5,975 POINTS
RANK1,339 / 8,153 TEAMS
SQL InjectionWeb Exploits

GITHUB footprint

Maintaining active repositories with 105 contributions in the last year across public & private projects.

USER: CRYPTICRHINO0 4 PUBLIC REPOS
RESEARCH_SPOTLIGHT // ACADEMIC_WORK

THE DARK SIDE OF AI

An academic and ethical critique of artificial intelligence in modern conflict.

ADVISOR: DR. CHANDNI BANSAL

"Awareness is the first step toward accountability."

Ethical AI advocacy pushing for binding UN treaties to enforce strict "human-in-the-loop" protocols in warfare.

AI IN WARFARE
[ DEPLOYMENT ]

LETHAL AUTONOMOUS WEAPONS (LAWS)

Analysis of unmanned algorithmic targeting platforms. Investigated systems like the Kargu-2 Drone and artificial intelligence military targeting engines such as "Lavender AI" and "The Gospel," highlighting their deployment boundaries and structural hazards.

Kargu-2Lavender
[ MANIPULATION ]

COGNITIVE WARFARE & DEEPFAKES

Tracking the evolution of cyber warfare from Stuxnet to AI-enhanced phishing. Examining how neural networks generate high-fidelity audio/video deepfakes for psychological campaigns and cognitive influence, blurring verification vectors.

PhishingStuxnet
[ CRITIQUE ]

MILITARY CONTRACTS & OPENAI

Critical assessment of the OpenAI-Pentagon deal and the removal of clauses banning military integration. Discussing the policy implications when commercial LLMs are modified to support cybersecurity, logistics, and battlefield command structures.

OpenAIUN Treaties

COMMUNITY FOOTPRINT

Chapters led, symposiums organized, and student communities scaled.

ROLES: LEADER_&_TEAM
NOV 2025 - PRESENTTEAM MEMBER

DCG91124 (DEFCON GURUGRAM)

Team Member // Event Coordinator

Active team member working alongside fellow team members to host cybersecurity platforms and drive student engagement.

Helped organize the Haryana Cyber Security Symposium (HCSS) 2025 at MRIIRS on Nov 16, 2025. Coordinated with industry keynote speakers, scaling registration to hundreds of active attendees.
VAPT CommunitySymposium 2025
SEPT 2025 - JUNE 2026CHAPTER LEAD (IBMR CHAPTER)

0x0 PIR4T3S

Chapter Lead // BIT-SEC-CON Coordinator

Appointed as Chapter Lead for the IBMR Business School Chapter, driving student recruitment and helping students in their cybersecurity journey while building interactive security training labs.

Helped scale the BIT-SEC-CON security platform from v1 to v2, managing the new community hub at bitseccon.0x0pirates.com. Partnered with OpenUK as community partner for the India AI Impact Summit 2026.
LeadershipBIT-SEC-CON v2OpenUK Partner
SEPT 2024 - JUNE 2026CLUB PRESIDENT

BYTE BENDERS (IT CLUB)

President // IT Club Lead

Elected as President of the official IT Club at IBMR Business School, overseeing club activities, technological workshops, and intra-college events.

Successfully organized 'Campus Clash,' a campus-wide BGMI e-gaming tournament on Oct 15, 2024. Coordinated logistics, sponsorships, and tournament rules, resulting in a successful championship match won by student teams.
IT AdministrationE-Sports Coordinator