Vansh Saini
Cybersecurity Analyst & VAPT Specialist
NIT Srinagar • B.Tech in Information Technology (CGPA 8.01/10)
“Offensive curiosity. Defensive precision. Systematically identifying attack vectors and verifying trust boundaries from network protocols to smart contracts.”
— Vansh Saini // Security Engineering & Operations
Specializing in SOC log triage (MITRE ATT&CK), web application VAPT (OWASP Top 10), and Azure cloud security controls (NSGs/WAF/Bastion). Ranked in the Top 3% on TryHackMe with CEH v13 and CNSP certifications.

Vansh Saini
NIT Srinagar • IT
Top 3% Global
Rank 8 / 2600+
Engineering Secure, Resilient Digital Architectures
A comprehensive engineering approach bridging offensive vulnerability assessment, defensive SOC monitoring, and cloud-native security controls.
I am a 3rd-year Information Technology undergraduate at the National Institute of Technology (NIT) Srinagar (CGPA: 8.01/10). My work centers on understanding systems at a fundamental level — from TCP/IP packet flows and Linux kernel permissions to web application logic flaws.
In offensive security, I have conducted structured vulnerability assessments mirroring enterprise audit lifecycles (such as my OWASP Juice Shop VAPT), generating formal risk registers, proof-of-concept exploits, and remediation strategies for 8 distinct vulnerability classes.
In security operations, I engineer custom tooling like Loghound, which scores and aggregates suspicious authentication logs mapped to MITRE ATT&CK techniques for faster triage.
Beyond traditional infrastructure, I explore decentralized auditability using Solidity and research defenses against emerging AI/LLM prompt injection vectors.
NIT Srinagar • B.Tech IT (2024–2028)
CGPA: 8.01 / 10.0
Srinagar (NIT), Jammu & Kashmir
Origins: Bhiwani & Bikaner
Web Application VAPT
Structured penetration testing following OWASP Top 10 guidelines. Proven ability to discover, exploit, and document vulnerabilities with standardized CVSS v3.1 scoring.
SOC & Detection Engineering
Analyzing authentication and web access logs, building custom Python log triage tools (Loghound), and mapping attack patterns to the MITRE ATT&CK framework.
Azure Cloud Security
Designing isolated multi-tier architectures with Azure VNet, Network Security Groups (NSGs), Application Gateway WAF, and Bastion jumpboxes for least-privilege administration.
Systems & Web3 Security
Developing robust automation in Python, Java, and C, with smart contract security and tamper-resistant audit trails developed on Solidity/Ethereum.
Featured Systems & Assessments
Real-world penetration testing, custom threat triage tooling, cloud infrastructure hardening, and decentralized audit systems with individual GitHub repositories.
Loghound — Security Log Triage & Threat Detection Tool
Python-based security log triage CLI tool mapping authentication anomalies to MITRE ATT&CK.
An automated threat triage and log analysis tool that ingests authentication and web access logs, scores anomalous events based on threat heuristics, and aggregates actionable investigation dossiers.
- ▸Built a Python-based security log triage engine to analyze authentication and web access logs, prioritizing suspicious activity for SOC analysts.
- ▸Implemented dynamic detection scoring, event aggregation, and automated MITRE ATT&CK framework technique mapping.
- ▸Developed an interactive terminal UI (TUI) with Textual for rapid incident drill-down and structured JSON audit reporting.
VAPT Lab — Web Application Pentest on OWASP Juice Shop
Structured web application VAPT identifying and documenting 8 distinct vulnerabilities with CVSS v3.1 ratings.
Azure Secure Web Application Infrastructure
Multi-tiered segmented cloud architecture on Microsoft Azure enforcing least-privilege and perimeter WAF defense.
Tamper-Proof Grievance & Audit Blockchain System
Solidity smart contract audit layer built during CodeSlayers 2K25 Hackathon (Ranked 8th / 2600+ Teams).
Room Writeups & CTF Walkthroughs
Detailed exploitation notes, privilege escalation walkthroughs, and TryHackMe rooms documented on my GitHub.
OWASP Juice Shop — Complete Web VAPT & Risk Assessment
Comprehensive offensive security assessment uncovering 8 distinct vulnerabilities across authentication bypass, BFOR, SQL injection, reflected XSS, and security misconfigurations.
Demonstrated formal risk reporting with CVSS 8.8 High severity metrics and actionable patch remediation.
TryHackMeDifficulty: MediumTryHackMe AI Security Path — Prompt Injection & Model Vulnerabilities
Detailed writeups on LLM adversarial prompt injection attacks, indirect context poisoning in RAG pipelines, and model guardrail evasion.
Documented systematic sanitizer guardrails for LLM agentic tool calls and output classification.
TryHackMeDifficulty: MediumJunior Penetration Tester Track — Privilege Escalation & Recon
Walkthroughs for Linux SUID exploitation, sudo misconfigurations, Windows Token manipulation, and automated Gobuster/Nmap port enumeration.
Reproducible bash & python automation scripts for fast local enumeration on compromised targets.
Technical Skills & Competencies
Offensive security tools, detection engineering environments, network defense, and core systems programming.
Select or hover over any technology logo above to view specialization details.
SOC & Security Operations
Security monitoring, log triage, incident analysis, and detection engineering mapped to MITRE ATT&CK.
VAPT & Offensive Security
Systematic web application penetration testing, vulnerability identification, and CVSS severity scoring.
Cloud Security & Controls
Securing cloud-native infrastructure, network isolation, WAF rules, and least-privilege administrative access.
Programming, Scripting & Web3
Developing automated security tools, backend API contracts, and smart contract verification.
Core Computer Science & Networking
Rigorous academic fundamentals from NIT Srinagar covering protocols, OS internals, and data structures.
Experience, Leadership & Hackathons
Leading technical sprints under pressure, managing operations at NIT Srinagar, and maintaining rigorous academic excellence.
Team Lead — National Finalist (Rank 8 / 2600+ Teams)
CodeSlayers 2K25 Hackathon • NIT Delhi
Led a 4-member engineering team during a 36-hour sprint, developing a decentralized grievance and tamper-resistant audit infrastructure.
- ▸Coordinated task allocation, technical architecture, and rapid prototyping under high-pressure 36-hour hackathon conditions.
- ▸Designed and implemented a Solidity smart contract layer on Ethereum for tamper-resistant grievance verification and auditable history.
- ▸Achieved 8th rank nationwide out of 2600+ registered teams, successfully qualifying for the National Finals.
Operations Lead (NIT Srinagar Pod) & PAS Executive Lead
Caarya (Caarya Innovative Solutions Pvt. Ltd.)
Spearheaded operational execution, cross-pod workflow systems, and accountability governance across student pods at NIT Srinagar.
- ▸Served as Operations Lead for the NIT Srinagar Industrial Pod, establishing operational structuring, execution tracking, communication workflows, and documentation systems.
- ▸Core Team Executive Lead for the Pod Accountability System (PAS) initiative: orchestrated workflow planning, participation coordination, and execution tracking using Notion, Google Sheets, and Discord.
- ▸Awarded official Letter of Recommendation (LOR) on 15 May 2026 by Director & CEO G. Nikhil Srivatsa recognizing reliability, structured thinking, and execution-oriented leadership.
Verified Recommendation Letter
Endorsed by G. Nikhil Srivatsa (Director & CEO, Caarya) • 15 May 2026
B.Tech in Information Technology
National Institute of Technology (NIT) Srinagar
Undergraduate student focusing on Computer Networks, Operating Systems, Systems Security, Cryptography, and Database Management Systems.
- ▸Current CGPA: 8.01 / 10.0
- ▸Active participant in collegiate cybersecurity CTFs, technical hackathons, and security research groups.
- ▸Deep theoretical grounding in OSI/TCP protocols, network defense, OS kernel concepts, and distributed systems.
Certifications & Accreditations
Verified knowledge and practical examinations validating offensive pentesting, network defense, and AI security expertise. Click any certificate to inspect the full document.
Issued: 30 April, 2026
Certified Ethical Hacker (CEH)
Industry-standard certification accredited under ANSI/ISO/IEC 17024 validating practical offensive security, threat vector analysis, network attacks, malware analysis, and web application exploitation.

Issued: 30 July, 2026
Certified Network Security Practitioner (CNSP) — With Merit
Hands-on examination evaluated by S. Siddharth assessing enterprise network hardening, packet inspection, perimeter firewall configurations, IDS/IPS tuning, and defensive boundary enforcement.

Issued: 20 June, 2025
Defronix Ethical Hacker Essential (DEHE)
Certificate of Appreciation awarded for core practical foundation in offensive security principles, footprinting, reconnaissance, vulnerability assessment, system hacking, and web exploitation methodologies.

Issued: 27 May, 2026
AI Security Learning Path
Official certificate of completion signed by Ben Spring (CEO) and Ashu Savani (CTO) covering 20+ hours of advanced labs on LLM security, adversarial prompt injections, RAG pipeline poisoning, and model guardrail evasion.

TryHackMe Journey & Global Standing
Consistent hands-on CTF challenge completion, offensive labs, and specialized AI security research.

@vanshsaini
Top 3%
Ranked in the Top 3% of global security practitioners
Offensive Pentesting
Web exploits, privilege escalation, Burp Suite, OWASP Juice Shop, Metasploit.
SOC & Threat Triage
Log analysis, SIEM investigation, Wireshark packet capture, alert correlation.
AI & LLM Security
OWASP Top 10 for LLMs, prompt injection vectors, model guardrail evaluation.
Network Defense
Subnet scanning, firewall filtering, DNS security, encrypted tunneling.
Let's Connect & Collaborate
Open to SOC Analyst, Security Engineering, and VAPT opportunities, internships, and technical collaborations.
Send a Message
Feel free to reach out directly for full-time opportunities, security discussions, or technical projects.
Send a Direct Message
Fill in the details below to open a pre-formatted inquiry to Vansh.