Skip to content
View r04i7's full-sized avatar

Block or report r04i7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
r04i7/README.md


whoami

class RohitKumar:
    def __init__(self):
        self.role        = "Senior Application Security Engineer"
        self.company     = "PwC (Senior Associate)"
        self.location    = "Kolkata, India"
        self.experience  = "5+ years in offensive security"
        self.specialties = ["Web App Security", "Mobile Pentest (iOS/Android)",
                            "API Security", "Source Code Analysis (SCA)",
                            "SSO / SAML / OAuth 2.0", "CVE Research"]
        self.builds      = ["Burp Suite extensions (Montoya API)",
                            "Python/Bash security automation"]
        self.published   = ["CVE-2024-35581", "CVE-2024-35582", "CVE-2024-35583"]
        self.mindset     = "Automate the manual. Verify everything. Assume breach."

🛡️ Senior AppSec Engineer with 5+ years across web, mobile (iOS/Android) and API penetration testing, source-code analysis and CVE research in banking, e-commerce and enterprise environments — currently at PwC, previously Black Duck (Synopsys) and Synopsys Inc., where I discovered 3 CVEs published in MITRE/NVD.


🎯 Impact & Research

🔬 CVEs Published 🗓️ Experience 🌐 Web/API Assessed 📱 Mobile Audited
3 in MITRE / NVD 5+ years 300+ apps 100+ apps

Published vulnerabilities (zero-day research & responsible disclosure):

CVE-2024-35581 CVE-2024-35582 CVE-2024-35583


💼 Career

PwC                      Senior Associate              Mar 2026 — Present
Black Duck (Synopsys)    Senior Security Consultant    Mar 2025 — Mar 2026
Black Duck (Synopsys)    Security Consultant           Sep 2024 — Mar 2025
Synopsys Inc.            Security Service Associate     Mar 2022 — Sep 2024   ← 3 CVEs disclosed
CSCC Labs                Cyber Security Analyst         Jul 2021 — Mar 2022

⚔️ Arsenal

Application & Network Burp Suite OWASP ZAP Postman Metasploit Wireshark

Mobile (iOS / Android) Frida MobSF Objection JADX Apktool

Languages & Build Python Bash Java C++

Domains & Standards SAML OAuth2 JWT API SCA IDOR XXE SQLi OWASP Mobile Top 10 SOC2 GDPR


🎖️ Certifications

OSCP CEH LPT


🚀 Featured Tooling

  • 🔐 saml-oauth-auto-tester — Burp (Montoya) extension that auto-runs the full SAML (XSW1–8, XXE, cert-faking) and OAuth 2.0 / OIDC (redirect hijack, PKCE, JWT alg=none) attack battery from Proxy history.
  • 🛡️ owasp-sentinel — Burp extension to manage and track flagged/hidden findings and surface OWASP Top-10 issues, streamlining triage during assessments.
  • 🍪 burp-session-token-analyzer — session-cookie / token analysis tool that flags weak session-management during web app testing.

📊 GitHub Analytics


🌐 Let's connect

r04i7.github.io  •  LinkedIn  •  Email

“The quieter you become, the more you are able to hear.”

Popular repositories Loading

  1. R3CON R3CON Public

    Forked from sahildari/R3CON

    Just some bash scripting to help your recon.

    Shell 2

  2. can-i-take-over-xyz can-i-take-over-xyz Public

    Forked from EdOverflow/can-i-take-over-xyz

    "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

    1

  3. burp-session-token-analyzer burp-session-token-analyzer Public

    Advanced Burp Suite extension that pinpoints the exact cookie(s)/header(s) maintaining a session, with OR-group & minimal-combination detection and send-to-Repeater.

    Java 1

  4. owasp-sentinel owasp-sentinel Public

    OWASP Sentinel Pro - real-time passive OWASP Top 10 + JWT/OAuth/SAML scanner for Burp Suite (Montoya API)

    Java 1

  5. saml-oauth-auto-tester saml-oauth-auto-tester Public

    Burp Suite extension (Montoya API) that auto-detects SAML and OAuth2.0/OIDC requests from Proxy history and runs the full pentest battery automatically.

    Java 1

  6. scaling-octo-chainsaw scaling-octo-chainsaw Public