|
1 | 1 | --- |
2 | | -title: "" |
| 2 | +title: "VIBE" |
3 | 3 | --- |
4 | 4 |
|
5 | | -A precise log of what’s broken, bypassed, and built. |
| 5 | +<div class="portfolio-hero"> |
| 6 | +<p class="hero-available">// available for new opportunities</p> |
6 | 7 |
|
7 | | -A personal space to write, reflect, and build clarity — no noise, no filters. Just raw thoughts, and everything that matters to me, in one place. |
| 8 | +<!-- # ~Vigneshwar --> |
8 | 9 |
|
9 | | -VIBE – <b>V</b>igneshwar’s <b>I</b>nsightful <b>B</b>logs & <b>E</b>xperiences. |
| 10 | +<p class="hero-subtitle">Security Engineer · AppSec · Offensive Security · AI Security</p> |
| 11 | +<p class="hero-bio">Breaking systems to build better ones. 3+ years securing <mark>2M+ users</mark> at Zoho. MS in Cybersecurity from <mark>UCF</mark>. Now engineering security tooling at the intersection of <mark>AI</mark> and <mark>offensive security</mark>.</p> |
10 | 12 |
|
| 13 | +<div class="hero-links"> |
| 14 | +<a href="https://www.linkedin.com/in/vigneshwar-sundararajan-07a2a5185/" class="hero-link" target="_blank" rel="noopener noreferrer">LinkedIn<a> |
| 15 | +<a href="https://github.com/vksundararajan" class="hero-link" target="_blank" rel="noopener noreferrer">GitHub</a> |
| 16 | +<a href="https://medium.com/@vigneshwarks" class="hero-link" target="_blank" rel="noopener noreferrer">Medium</a> |
| 17 | +<a href="https://tryhackme.com/p/vigneshwarks" class="hero-link" target="_blank" rel="noopener noreferrer">TryHackMe</a> |
| 18 | +<a href="/VIBE/blog/" class="hero-link">Blog</a> |
| 19 | +<a href="/VIBE/index.xml" class="hero-link">RSS</a> |
| 20 | +</div> |
| 21 | +</div> |
11 | 22 |
|
12 | | -### Most recent blogs |
13 | | -{{< recent-posts >}} |
| 23 | +--- |
| 24 | + |
| 25 | +<p class="section-label">// what i do</p> |
| 26 | + |
| 27 | +<div class="pillar-grid"> |
| 28 | +<div class="pillar"> |
| 29 | +<p class="pillar-icon">⚔</p> |
| 30 | +<p class="pillar-title">Offensive Security</p> |
| 31 | +<p>Red teaming, AD exploitation, CVE research, CTFs, and penetration testing with a developer mindset.</p> |
| 32 | +</div> |
| 33 | +<div class="pillar"> |
| 34 | +<p class="pillar-icon">🛡</p> |
| 35 | +<p class="pillar-title">Application Security</p> |
| 36 | +<p>Secure SDLC, threat modeling, code review, bug bounty, OAuth/SAML hardening, and CI/CD security automation.</p> |
| 37 | +</div> |
| 38 | +<div class="pillar"> |
| 39 | +<p class="pillar-icon">🤖</p> |
| 40 | +<p class="pillar-title">Security × AI</p> |
| 41 | +<p>Building agentic security systems — multi-agent frameworks, RAG pipelines, and LLM-powered recon tools.</p> |
| 42 | +</div> |
| 43 | +</div> |
| 44 | + |
| 45 | +--- |
| 46 | + |
| 47 | +<p class="section-label">// experience</p> |
| 48 | + |
| 49 | +<div class="experience-item"> |
| 50 | +<div class="exp-header"> |
| 51 | +<span class="exp-company">Bright Mind Enrichment</span> |
| 52 | +<span class="exp-period">09/2025 – Present</span> |
| 53 | +</div> |
| 54 | +<p class="exp-role">Security Engineer – Orlando, FL · Remote</p> |
| 55 | +<ul style="list-style-type: circle;"> |
| 56 | +<li>Conducted comprehensive vulnerability assessments on the organization’s Web infrastructure, proactively identifying and remediating high-severity risks stemming from outdated plugins, themes, and legacy core versions.</li> |
| 57 | +<li>Hardened web assets against automated attacks by orchestrating timely patch cycles and implementing robust security configurations, effectively minimizing the attack surface and preventing the exploitation of known CVEs.</li> |
| 58 | +</ul> |
| 59 | +</div> |
| 60 | + |
| 61 | +<div class="experience-item"> |
| 62 | +<div class="exp-header"> |
| 63 | +<span class="exp-company">Zoho Corporation</span> |
| 64 | +<span class="exp-period">06/2020 – 07/2023</span> |
| 65 | +</div> |
| 66 | +<p class="exp-role">Member Technical Staff – Security Software Engineer · Chennai, India</p> |
| 67 | +<ul style="list-style-type: circle;"> |
| 68 | +<li>Led a weekly bug bounty initiative identifying 100+ web vulnerabilities annually, while educating 20+ developers on secure coding practices. Leveraged ethical hacking techniques to reduce system risks, increasing application resilience by 40%.</li> |
| 69 | +<li>Revamped SSO, 2FA, SAML, OAuth, and RBAC mechanisms for Endpoint Central Web, Android, and iOS. Secured 500k accounts, reducing unauthorized access by 60% and enhancing user verification.</li> |
| 70 | +<li>Introduced automated testing in GitLab’s CI/CD pipeline, reducing manual code reviews by 50% and enhancing deployment speed across seven high-impact products, improving efficiency and code quality at scale.</li> |
| 71 | +<li>Implemented 50+ security features across Manage Engine products, improving key functions like User Management and Role Management, resulting in a 45% reduction in access-related incidents.</li> |
| 72 | +<li>Conducted in-depth code reviews for Manage Engine products with over 100k lines of code (LOC), identifying critical vulnerabilities and improving code quality by 25%.</li> |
| 73 | +<li>Boosted product stability by resolving live security incidents for 2M+ global users, achieving a 30% increase in customer satisfaction scores and reinforcing product trust worldwide.</li> |
| 74 | + |
| 75 | +</ul> |
| 76 | +</div> |
| 77 | + |
| 78 | +--- |
| 79 | + |
| 80 | +<p class="section-label">// projects</p> |
| 81 | + |
| 82 | +<div class="project-grid"> |
| 83 | +<div class="project-card"> |
| 84 | +<p class="project-tag">Multi-Agent · Google ADK · LLM</p> |
| 85 | +<h4>Cross-Check</h4> |
| 86 | +<p>Multi-agent URL phishing detection framework using Google ADK and Mesop. Debate consensus mechanism among specialized agents minimizes hallucinations. Dockerized full-stack with automated testing.</p> |
| 87 | +<a href="https://github.com/vksundararajan/cross-check" class="project-link" target="_blank" rel="noopener noreferrer">→ GitHub</a> |
| 88 | +</div> |
| 89 | +<div class="project-card"> |
| 90 | +<p class="project-tag">LangGraph · MCP · Recon</p> |
| 91 | +<h4>AdaptiveFuzz</h4> |
| 92 | +<p>Reconnaissance framework powered by a multi-agent system on LangGraph. Context-aware LLMs with custom MCP for agent communication. Drastically reduces manual effort in vulnerability discovery.</p> |
| 93 | +<a href="https://github.com/vksundararajan/AdaptiveFuzz" class="project-link" target="_blank" rel="noopener noreferrer">→ GitHub</a> |
| 94 | +</div> |
| 95 | +<div class="project-card"> |
| 96 | +<p class="project-tag">RAG · LangChain · ChromaDB</p> |
| 97 | +<h4>Kestrel</h4> |
| 98 | +<p>RAG system with LangChain, ChromaDB, with Metasploit datasets. Supports CoT, ReAct, and Self-Ask reasoning for context-grounded vulnerability research with reduced hallucination.</p> |
| 99 | +<a href="https://github.com/vksundararajan/kestrel" class="project-link" target="_blank" rel="noopener noreferrer">→ GitHub</a> |
| 100 | +</div> |
| 101 | +<div class="project-card"> |
| 102 | +<p class="project-tag">Cryptography · Cloud</p> |
| 103 | +<h4>Cloud Sec Encryptor</h4> |
| 104 | +<p>Personal tool for secure file transfers across cloud platforms. Automates encryption on upload and decryption on download, showcasing expertise in data protection and encryption engineering.</p> |
| 105 | +<a href="https://github.com/vksundararajan/cloud-sec-encryptor" class="project-link" target="_blank" rel="noopener noreferrer">→ GitHub</a> |
| 106 | +</div> |
| 107 | +</div> |
| 108 | + |
| 109 | +--- |
| 110 | + |
| 111 | +<p class="section-label">// certifications</p> |
| 112 | + |
| 113 | +<div class="cert-grid"> |
| 114 | +<a href="https://www.credential.net/10ca361d-d4e2-4cd8-b689-1109c711744c" class="cert-badge" target="_blank" rel="noopener noreferrer"> |
| 115 | +<span class="cert-name">CRTP</span> |
| 116 | +<div class="cert-info"> |
| 117 | +<span class="cert-full">Certified Red Team Professional</span> |
| 118 | +<span class="cert-provider">Altered Security</span> |
| 119 | +</div> |
| 120 | +</a> |
| 121 | +<a href="https://certs.ine.com/3bc3ed9c-4780-4f54-80f9-55440fa7bd2d#acc.tpIOqrXv" class="cert-badge" target="_blank" rel="noopener noreferrer"> |
| 122 | +<span class="cert-name">eJPT</span> |
| 123 | +<div class="cert-info"> |
| 124 | +<span class="cert-full">Junior Penetration Tester</span> |
| 125 | +<span class="cert-provider">INE Security</span> |
| 126 | +</div> |
| 127 | +</a> |
| 128 | +<a href="https://app.readytensor.ai/certificates/0df19c1d-6efc-4ecf-84db-6f06894ba4ea" class="cert-badge" target="_blank" rel="noopener noreferrer"> |
| 129 | +<span class="cert-name">AAIDC</span> |
| 130 | +<div class="cert-info"> |
| 131 | +<span class="cert-full">Agentic AI Expert + RAG Expert</span> |
| 132 | +<span class="cert-provider">Ready Tensor</span> |
| 133 | +</div> |
| 134 | +</a> |
| 135 | +<a href="https://www.linkedin.com/in/vigneshwar-sundararajan/overlay/Certifications/2029476952/treasury/?profileId=ACoAACultB4B-algwiixps1L4r1tI2EiFomc5jM" class="cert-badge" target="_blank" rel="noopener noreferrer"> |
| 136 | +<span class="cert-name">OCA</span> |
| 137 | +<div class="cert-info"> |
| 138 | +<span class="cert-full">Oracle Certified Associate</span> |
| 139 | +<span class="cert-provider">Oracle</span> |
| 140 | +</div> |
| 141 | +</a> |
| 142 | +</div> |
| 143 | + |
| 144 | +--- |
| 145 | + |
| 146 | +<p class="section-label">// training courses</p> |
14 | 147 |
|
15 | | -### Whoami |
16 | | -Name’s <mark>~Vigneshwar</mark>. Just an ordinary guy who enjoys exploring how things work under the hood, especially when it comes to breaking and securing systems. Nothing extraordinary. Not an expert. I’m the kind of person who enjoys testing things out, messing with tools, and learning by doing. Most of what I know comes from trying, failing, and trying again. |
| 148 | +<div class="training-grid"> |
| 149 | +<a href="https://www.udemy.com/certificate/UC-ad0afac7-99c5-4225-a570-28ae725b0ca4/" class="training-card" target="_blank" rel="noopener noreferrer"> |
| 150 | +<span class="training-name">BSCP</span> |
| 151 | +<div class="cert-info"> |
| 152 | +<span class="cert-full">Burp Web Security Academy</span> |
| 153 | +<span class="cert-provider">PortSwigger / Udemy</span> |
| 154 | +</div> |
| 155 | +</a> |
| 156 | +<a href="https://www.linkedin.com/learning/certificates/090b5304322d1094a23ec66a5ef142ee1de1a4d62c273beb05a2d28dceb23f62" class="training-card" target="_blank" rel="noopener noreferrer"> |
| 157 | +<span class="training-name">DFPC</span> |
| 158 | +<div class="cert-info"> |
| 159 | +<span class="cert-full">Docker Foundations Professional Certificate</span> |
| 160 | +<span class="cert-provider">LinkedIn Learning</span> |
| 161 | +</div> |
| 162 | +</a> |
| 163 | +<a href="https://tryhackme.com/certificate/THM-TIHKUGEEOV" class="training-card" target="_blank" rel="noopener noreferrer"> |
| 164 | +<span class="training-name">THM</span> |
| 165 | +<div class="cert-info"> |
| 166 | +<span class="cert-full">CompTIA PenTest+</span> |
| 167 | +<span class="cert-provider">TryHackMe</span> |
| 168 | +</div> |
| 169 | +</a> |
| 170 | +<a href="https://tryhackme.com/certificate/THM-ZP9HPOOBNR" class="training-card" target="_blank" rel="noopener noreferrer"> |
| 171 | +<span class="training-name">THM</span> |
| 172 | +<div class="cert-info"> |
| 173 | +<span class="cert-full">Jr Penetration Tester</span> |
| 174 | +<span class="cert-provider">TryHackMe</span> |
| 175 | +</div> |
| 176 | +</a> |
| 177 | +</div> |
| 178 | + |
| 179 | +--- |
17 | 180 |
|
18 | | -I come from a software development background, and over time, I started leaning more towards security. I’ve since completed my **Master’s in Cybersecurity and Privacy**, and have been progressively deepening my focus in the field — exploring web security, participating in CTFs, diving into Active Directory labs, and building or customizing tools along the way. |
| 181 | +<p class="section-label">// skills</p> |
19 | 182 |
|
20 | | -I’m not trying to go viral or be known for anything. This is more like a personal changelog — something I can look back on, or maybe something others can learn from if they’re walking a similar path. |
| 183 | +<div class="skill-section"> |
| 184 | +<div class="skill-group"> |
| 185 | +<p class="skill-group-label">Core Competencies</p> |
| 186 | +<div class="skill-tags"> |
| 187 | +<span class="skill-tag">Penetration Testing</span> |
| 188 | +<span class="skill-tag">Threat Modeling</span> |
| 189 | +<span class="skill-tag">Incident Response</span> |
| 190 | +<span class="skill-tag">Cryptography</span> |
| 191 | +<span class="skill-tag">Active Directory</span> |
| 192 | +<span class="skill-tag">Malware Analysis</span> |
| 193 | +<span class="skill-tag">Log Analysis</span> |
| 194 | +<span class="skill-tag">Security Code Review</span> |
| 195 | +<span class="skill-tag">Security Automation</span> |
| 196 | +<span class="skill-tag">Web Development</span> |
| 197 | +<span class="skill-tag">AI Security</span> |
| 198 | +<span class="skill-tag">Agentic AI</span> |
| 199 | +<span class="skill-tag">Generative AI (LLMs)</span> |
| 200 | +</div> |
| 201 | +</div> |
| 202 | +<div class="skill-group"> |
| 203 | +<p class="skill-group-label">Security Tools and OS</p> |
| 204 | +<div class="skill-tags"> |
| 205 | +<span class="skill-tag">Burp Suite Pro</span> |
| 206 | +<span class="skill-tag">Metasploit</span> |
| 207 | +<span class="skill-tag">Nessus</span> |
| 208 | +<span class="skill-tag">Splunk</span> |
| 209 | +<span class="skill-tag">Wireshark</span> |
| 210 | +<span class="skill-tag">OWASP ZAP</span> |
| 211 | +<span class="skill-tag">PowerShell</span> |
| 212 | +<span class="skill-tag">BloodHound CE</span> |
| 213 | +<span class="skill-tag">PowerView</span> |
| 214 | +<span class="skill-tag">ActiveDirectory Module</span> |
| 215 | +<span class="skill-tag">Mimikatz</span> |
| 216 | +<span class="skill-tag">SafetyKatz</span> |
| 217 | +<span class="skill-tag">Ghidra</span> |
| 218 | +<span class="skill-tag">Docker</span> |
| 219 | +<span class="skill-tag">Kali Linux</span> |
| 220 | +<span class="skill-tag">Windows</span> |
| 221 | +<span class="skill-tag">Unix</span> |
| 222 | +<span class="skill-tag">macOS</span> |
| 223 | +</div> |
| 224 | +</div> |
| 225 | +<div class="skill-group"> |
| 226 | +<p class="skill-group-label">Languages & Frameworks</p> |
| 227 | +<div class="skill-tags"> |
| 228 | +<span class="skill-tag">Python</span> |
| 229 | +<span class="skill-tag">Java</span> |
| 230 | +<span class="skill-tag">C++</span> |
| 231 | +<span class="skill-tag">Ansible</span> |
| 232 | +<span class="skill-tag">Bash/Shell Scripting</span> |
| 233 | +<span class="skill-tag">JavaScript</span> |
| 234 | +<span class="skill-tag">Bash</span> |
| 235 | +<span class="skill-tag">LangChain</span> |
| 236 | +<span class="skill-tag">LangGraph</span> |
| 237 | +<span class="skill-tag">MCP</span> |
| 238 | +<span class="skill-tag">Google ADK</span> |
| 239 | +<span class="skill-tag">Mesop</span> |
| 240 | +<span class="skill-tag">MCP (Model Context Protocol)</span> |
| 241 | +<span class="skill-tag">Node.js</span> |
| 242 | +<span class="skill-tag">Ember.js</span> |
| 243 | +<span class="skill-tag">Handlebars</span> |
| 244 | +<span class="skill-tag">PHP</span> |
| 245 | +<span class="skill-tag">MySQL</span> |
| 246 | +<span class="skill-tag">PostgreSQL</span> |
| 247 | +<span class="skill-tag">MongoDB</span> |
| 248 | +</div> |
| 249 | +</div> |
| 250 | +</div> |
| 251 | + |
| 252 | +--- |
| 253 | + |
| 254 | +<div class="portfolio-body"> |
| 255 | +<div class="section-header"> |
| 256 | +<p class="section-label">// recent logs</p> |
| 257 | +<a href="/VIBE/blog/" class="section-more">→ all posts</a> |
| 258 | +</div> |
| 259 | + |
| 260 | +{{< recent-posts >}} |
| 261 | +</div> |
| 262 | + |
| 263 | +--- |
21 | 264 |
|
22 | | -Everything here is simple, honest, and written mostly for myself. No fluff. No filters. Just raw logs from someone figuring things out... |
| 265 | +<div class="portfolio-body"> |
| 266 | +<p class="section-label">// whoami</p> |
23 | 267 |
|
24 | | -### Disclaimer |
25 | | -Nothing here is meant to be a guide for real-world attacks, and definitely not for anything illegal. This site isn’t about showing off or claiming to know it all. Most of this is me figuring things out as I go. **Things might be wrong, incomplete, or outdated**. That’s part of learning. |
| 268 | +Name's <mark>~Vigneshwar</mark>. Just an ordinary guy who enjoys exploring how things work under the hood — especially when it comes to breaking and securing systems. Software development background, leaned into security over time. MS in Cybersecurity from UCF. Now building at the edge of offensive security and AI. |
26 | 269 |
|
27 | | -<mark>Everything shared here is for learning purposes only.</mark> If you’re using any of this knowledge, make sure you’re doing it responsibly and ethically. I’m not here to tell you what to do — and I’m definitely not responsible if someone misuses what’s written here. |
| 270 | +VIBE — <b>V</b>igneshwar's <b>I</b>nsightful <b>B</b>logs & <b>E</b>xperiences. |
28 | 271 |
|
29 | | -This is just my personal log. Keep it clean, keep it legal.. |
| 272 | +</div> |
0 commit comments