Skip to content
View 5h4d0wn1k's full-sized avatar
:dependabot:
Nothing is impossible for those who try
:dependabot:
Nothing is impossible for those who try

Block or report 5h4d0wn1k

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
5h4d0wn1k/README.md
Nikhil Nagpure Vulnerability Research & Coordinated Disclosure, Memory Safety & Fuzzing, Offensive Security Practitioner, AI/LLM Security Engineering, Hardware & Wireless Pentesting, 97 Merged Upstream PRs Profile views Β Β  Followers Β Β  249 repositories 1,025 stars Β Β  6 merged pull requests to independent open-source projects Β Β  License

LinkedIn-0A66C2?style=for-the GitHub-111827?style=for-the Portfolio-0891b2?style=for-the Profile last updated Email-EA4335?style=for-the


πŸ›‘οΈ About Me

Identity Nikhil Nagpure Β· 5h4d0wn1k
🌍 Open to relocation & frequent travel · always exploring somewhere new
Education B.Tech CSE β€” Cybersecurity & Digital Forensics, VIT Bhopal (2021–2025) Β· CGPA 8.33/10
Now Technical Lead @ CuboidSoft Β· Founder @ Shadownik Β· Founding SWE @ Pawan Technologies
Previously: Offensive Security Intern @ InLighnX Β· Ethical Hacking Intern @ Internship Studio
Focus Vulnerability Research Β· Memory Safety Β· Fuzzing Β· Offensive Security Β· Red Teaming Β· API Security Β· AI/LLM Security Β· Hardware-Wireless Pentesting Β· Secure Full-Stack
Building ApiSecPlatform (enterprise API security testing) Β· Portable Wireless Pentest Toolkit (ESP32-based) Β· SentinelWall AI threat detection

Focus areas
Vulnerability Research-9f1239?style=flat-square Memory Safety-c026d3?style=flat-square Fuzzing-7c3aed?style=flat-square Offensive Security-red?style=flat Red Teaming-darkred?style=flat API Security-22d3ee?style=flat LLM Security-a21caf?style=flat Hardware & Wireless-14b8a6?style=flat Secure Full--Stack-eab308?style=flat

Core stack
Python-3776AB?style=flat TypeScript-3178C6?style=flat C++-00599C?style=flat Solidity-363636?style=flat Go-00ADD8?style=flat-square C-A8B9CC?style=flat-square Rust-000000?style=flat Dart-0175C2?style=flat SQL-4479A1?style=flat Java-E34F26?style=flat

Certifications
CEH-e63946?style=flat CNSP-457b9d?style=flat PEH (TCM)-6d6875?style=flat IELTS 7.5 (C1)-2a9d8f?style=flat

Communities
DEFCON Franklin Security-black?style=flat Cyber Expert - Ministry of Home Affairs (India)-1f5c8b?style=flat


🧰 Tech Stack

Python-3776AB?style=for-the TypeScript-3178C6?style=for-the C++-00599C?style=for-the Solidity-363636?style=for-the Dart-0175C2?style=for-the Rust-000000?style=for-the Next.js-000000?style=for-the Linux-FCC624?style=for-the Docker-2496ED?style=for-the Offensive Security-22d3ee?style=for-the Hashcat-123456?style=for-the KaliLinux-557C94?style=for-the


πŸš€ Featured Projects

Project Description Stars
photo-organizer Local-first, private-by-default photo & video library β€” Rust daemon + Flutter desktop, SQLCipher vault, ChaCha20-Poly1305 encryption, OCR & scene search, P2P LAN sync Stars
Decentralized Cloud Storage Blockchain-backed decentralized storage β€” Solidity smart contracts sharing encrypted file references with on-chain access control Stars
ML Web-Attack Detection ML-powered web-attack detection β€” phishing URL, DoS intrusion & XSS classification Stars
cybersecurity-framework Interactive map of everything in cybersecurity β€” 27 domains, 776 categories, 1,067 curated offensive & defensive tools Stars
ApiSecPlatform Enterprise API security platform for automated testing, threat insights, and OWASP-aligned checks β€”
Portable Wireless Pentesting Toolkit ESP32-based field pentesting device for wireless assessments and protocol testing β€”

🧨 Flagship Security Toolchain (Shadow Kitchen)

The current effort β€” autonomous offensive/defensive security tooling for authorized labs. Every tool ships with docs, tests, and explicit legal-use boundaries.

Tool What it does
sentinelwall Autonomous AI network threat detection & correlation β€” MITRE ATT&CK mapping, ML anomaly detection, rule DSL, STIX/Navigator/HTML exports
mythicforge Adversarial LLM prompt-injection & jailbreak testing β€” 37 techniques, OWASP/NIST/MITRE ATLAS benchmarks, SARIF reports
shadowvault Cryptographic secrets lifecycle manager β€” AES-256-GCM vault, OPSEC zeroize, team RBAC, migration tools
hermesc2 C2 & post-exploitation research framework (lab) β€” listeners, stagers, beacons, encrypted transport, killswitch, offline loopback-only demo
viperstrike MCP (Model Context Protocol) server vulnerability auditor β€” AST/whitebox SAST for agentic AI tool handlers, SARIF-capable
crownjewel Cross-cloud identity federation auditor β€” Golden/Silver SAML, OAuth client-ID spoofing, OIDC validation, offline fixtures
aiarsenal Adversarial AI/ML security studio β€” data poisoning, model backdoors, extraction, membership inference, prompt injection, agentic red-team planner
webbreach OWASP Top-10 web exploitation framework β€” built-in localhost vulnerable targets, AI-guided scan queue
cloudpwn Cloud & container penetration suite β€” AWS/GCP/Azure enumeration, docker leaks, k8s secrets, terraform audit, CSPM
supplysec Supply-chain security gate β€” SBOM (CycloneDX/SPDX), offline advisory matching, policy gates, post-quantum scanning
toxindb RAG retrieval-time poisoning detector β€” canary injection, provenance attestation, SARIF+MD reports
honeynet Honeypot farm + deception grid β€” multi-protocol honeypots, attacker fingerprinting, dwell/risk scoring, quarantine

198+ catalog security tools and counting β€” see the security tool catalog. For more flagships: cryptocrack, grainrecon, exploitcraft, mobsek, endpointaegis, netpwn, wiair, socialforge, sprayshed, rogueai, postpwn, and the w/m/c/d/f/h/i/n/p/r/se/web/x/ai/cl coded series. All for authorized testing only.


πŸ‘¨β€πŸ’» Experience

Technical Lead β€” CuboidSoft (Jan 2025 - Present)

  • Lead an IT software company delivering custom web applications, mobile apps, and digital solutions for SMEs and startups across multiple domains.
  • Lead full-stack architecture and development for client projects using Next.js, Node.js, PostgreSQL, and modern frontend frameworks to build secure, scalable applications.
  • Built everything from scratch with my co founder
  • Building thecodemunk.in , app.thecodemunk.in , pilot.cuboidsoft.in , cai.cuboidsoft.in

Founder β€” Shadownik Β· Freelance Venture (Jun 2024 - Present)

  • Build and scale a multi-service freelance venture across cybersecurity, full-stack engineering, cloud deployment, and digital operations.
  • Deliver secure production systems and offensive security assessments for real-world clients.
  • Lead product development for ApiSecPlatform and multiple automation-focused services.

Founding SWE β€” Pawan Technologies (Sep 2025 - Feb 2026)

  • Developed responsive production web apps and scalable backend APIs.
  • Built integrations, database workflows, and cloud-ready deployment pipelines.
  • Built davcreations.in , https://kaarveragroindia.com/

Offensive Cybersecurity Intern β€” InLighnX Global Pvt. Ltd. (Jun 2025 - Dec 2025)

  • Performed web application security assessments (OWASP Top 10, Burp Suite, Metasploit), threat modeling, and red-team simulations.
  • Contributed to large-scale IT infrastructure defense: intrusion detection monitoring, vulnerability triage, and security reporting.

Ethical Hacking Intern β€” Internship Studio (Nov 2023 - Dec 2023)

  • Identified and mitigated XSS vulnerabilities in production web applications; authored remediation reports.
  • Designed practical security lab environments simulating real-world attack scenarios.

πŸ“Š GitHub Analytics

Profile Summary

GitHub statistics summary card Repositories per language summary card Most committed language summary card
Streak Stats
Contribution Heatmap

πŸ† Certifications & Highlights

  • CEH (EC-Council)
  • CNSP (The SecOps Group)
  • Practical Ethical Hacking (TCM Security)
  • Patent filed: A Self-Cleaning Glasses Case System (Application No: 202421032123)

πŸ“¬ Let's Connect

LinkedIn-0A66C2?style=for-the GitHub-111827?style=for-the Portfolio-0891b2?style=for-the Email-EA4335?style=for-the


"Build secure systems. Solve real problems. Create measurable impact."

Thanks for visiting

Pinned Loading

  1. photo-organizer photo-organizer Public

    Local-first, private-by-default photo & video library. Rust daemon + Flutter desktop with Android pairing; SQLCipher encryption, ChaCha20-Poly1305 vault, OCR & scene search, P2P LAN sync β€” all on-d…

    Shell 16 2

  2. Decentralized-cloud-storage Decentralized-cloud-storage Public

    Blockchain-backed decentralized storage prototype β€” Solidity smart contracts sharing encrypted file references with on-chain access control (Hardhat).

    Solidity 8

  3. A-Secure-Warning-Platform-From-Web-Attacks-Using-Machine-Learning A-Secure-Warning-Platform-From-Web-Attacks-Using-Machine-Learning Public

    Machine-learning web-attack detection platform for phishing URL, DoS intrusion, and XSS classification β€” scikit-learn + Flask labs.

    HTML 7