Hello! I am Preet Kapoor, a security researcher who believes that true offensive security requires more than just running tools—it requires building them.
My approach to cybersecurity merges relentless curiosity with rigorous automation. Whether I am architecting high-performance cryptographic utilities in Rust, automating offensive recon pipelines in Python, or hunting down subtle web vulnerabilities, I don't just look for the easy win. I specialize in stepping away from off-the-shelf exploits to test new, innovative approaches that uncover what others miss.
I bring a persistent, detail-driven mindset to every engagement. For me, perfection isn't just about finding the vulnerability—it is about engineering the smartest, most efficient way to prove the impact and secure the infrastructure.
Rust-Crack ↗
A high-performance, blazingly fast hash and cryptographic auditing utility built in Rust. Designed for rapid wordlist evaluation, hash identification, and benchmark testing.
Vasuki ↗
An advanced reconnaissance and offensive automation framework crafted to streamline target analysis, asset discovery, and vulnerability assessment workflows.
Trickster ↗
Unified security toolkit blending VirusTotal scanning, local phishing detection, file/URL threat analysis, and enterprise-grade password policy enforcement—all under the same hood.
Vulnerable Machine ↗
Custom-built and community-solved vulnerable machines focusing on real-world privilege escalation, kernel exploitation, and initial access vectors.
Writeups • MethodologyCTF Walkthrough ↗
Step-by-step documentation and exploit breakdowns for competitive Capture The Flag challenges across cryptography, web, and pwn categories.
Web Security • LabsPortSwigger Academy ↗
Comprehensive solutions and notes for PortSwigger Web Security Academy labs, covering advanced SQLi, SSRF, BOLA, and OAuth flaws.
Offensive ↗
Curated cheatsheets, attack methodologies, payload references, and privilege escalation techniques for penetration testing and red teaming.
Defensive ↗
Blue team strategies, SIEM detection rules, incident response playbooks, and system hardening configurations to protect critical infrastructure.
Cloud ↗
Security architectures, IAM policy auditing, container security, and cloud metadata exploitation notes across AWS, Azure, and GCP environments.