Skip to content
View VikashChoudhary-04's full-sized avatar

Block or report VikashChoudhary-04

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
VikashChoudhary-04/README.md

👨‍💻 Vikash Choudhary | Web Application Pentesting

I perform structured web application security testing focused on identifying, exploiting, and validating real-world vulnerabilities.


🛠️ Core Skills

  • Web Application Penetration Testing
  • SQL Injection (Authentication Bypass)
  • IDOR (Broken Access Control)
  • Cross-Site Scripting (XSS)
  • API Security Testing
  • Vulnerability Analysis & Reporting

⚙️ Tools

  • Burp Suite
  • Nmap
  • ffuf
  • dirsearch

🧠 Methodology

My testing approach follows a real-world pentesting workflow:

  1. Reconnaissance (attack surface mapping)
  2. Input identification
  3. Vulnerability testing (XSS, IDOR, SQL Injection)
  4. Exploitation
  5. Validation (false positive removal)
  6. Reporting with business impact

📂 Featured Work

🔴 OWASP Juice Shop — Security Assessment

  • SQL Injection → Authentication Bypass (Admin Access)
  • IDOR → Unauthorized Data Access
  • XSS → Client-side Execution

👉 Full project: View Assessment


📌 What I Focus On

  • Real-world vulnerability exploitation
  • Accurate validation (no false positives)
  • Clear, impact-driven reporting

📊 GitHub Stats

Vikash's GitHub stats


🔗 Connect


Pinned Loading

  1. MiniCorp-Red-Team-Simulation MiniCorp-Red-Team-Simulation Public

    End-to-end red team simulation: external attacker → web compromise → internal pivot → Active Directory takeover → professional report.

    1

  2. ScopeForgeX ScopeForgeX Public

    ScopeForgeX — A question-driven ethical hacking workflow automation tool that provides a single CLI dashboard to run recon/enum/vuln tools, generate final target lists, and produce organized output…

    Python 1

  3. subhunt subhunt Public

    Modular subdomain enumeration framework written in Go

    Go 1

  4. mitre-mapped-incident-report mitre-mapped-incident-report Public

    SOC incident investigation project demonstrating MITRE ATT&CK mapping, Splunk-based detection analysis, and professional incident reporting workflows.

    1

  5. recon-toolkit recon-toolkit Public

    My personal automation + methodology toolkit for reconnaissance and enumeration.

    Shell 1

  6. web-attack-monitoring web-attack-monitoring Public

    Splunk-based web attack monitoring project focused on detecting suspicious HTTP activity, brute force attempts, and common web attacks using log analysis and detection engineering.

    1