Available for Security Engagements

Security
Analyst &
AppSec Specialist

Vikas Anand — VAPT expert with 50+ engagements across web, API, Android & network. Based in Patna, India.

0
VAPT Engagements
0
Vulns Found
0
Companies Secured
0
Govt. Orgs.
Let's Work Together HackerOne Profile Download Resume
// About

Who I Am

I'm a Security Analyst with deep hands-on experience in Web Application, API, Android, and Network Penetration Testing. I've conducted 50+ VAPT engagements identifying 300+ vulnerabilities across government and private-sector clients.

I've helped secure 40+ government organizations and 10+ private-sector companies by identifying critical risks and supporting effective remediation — from auth flaws and IDOR to injection and business logic weaknesses.

Beyond client work, I actively participate in bug bounty programs across HackerOne and have reported valid findings to over 100 global companies including Google, NASA, DoD, and the United Nations.

Web App Testing

OWASP Top 10, auth flaws, IDOR, injection, business logic vulnerabilities.

API Security

REST & GraphQL APIs, broken object-level auth, fuzzing, rate limiting.

Android DAST/SAST

Mobile app analysis with Frida, Objection, JADX, MobSF, ADB.

Network VAPT

Scanning, exploitation, vulnerability assessment with Nessus & Nmap.

// Skills

Technical Arsenal

Web / API Pentesting92%
VAPT / WAPT90%
OSINT & Recon88%
Bug Bounty87%
Burp Suite91%
Android DAST/SAST82%
Network Pentesting80%
Metasploit / SQLMap80%
Nessus / Nmap83%
ProjectDiscovery Suite85%
Python / Bash78%
Frida / JADX / MobSF76%
Kali LinuxOWASP Top 10ShodanCensysAmassSubfinderFFUFHttpxNaabuWiresharkADBObjection
// Primary Toolset
Burp Suite
Web proxy
Nuclei
Vuln scanner
FFUF
FFUF
Web fuzzer
Subfinder
Subdomain enum
Naabu
Port scanner
HTTP
Httpx
HTTP probing
Nmap
Network mapper
Nessus
Vuln assessment
MobSF
Mobile security
Frida
Dynamic analysis
// Experience & Education

My Journey

JULY 2025 – PRESENT
Security Analyst
Innovador Infotech Pvt. Ltd.
  • Conducted 50+ VAPT engagements for government and private-sector clients.
  • Security testing across web, API, network, and Android applications.
  • Identified auth flaws, IDOR, injection, and business logic weaknesses.
  • Collaborated with developers and stakeholders on remediation.
APRIL 2025 – JUNE 2025
Red Team Consultant
CyberNeonGen
  • Red team assessments for enterprise clients.
  • Web application exploitation and attack simulation.
  • Strengthened security posture and threat mitigation strategies.
AUG 2023 – MAY 2025
Masters in Computer Application
LNCT Group of Colleges, Bhopal
  • CGPA: 7.94
  • Focused on cybersecurity, networking, and software engineering.
OPEN SOURCE
S1MPL3_R3CON
github.com/kingcoolvikas
  • Recon automation: subdomain discovery, HTTP probing, port scanning.
  • Integrates ProjectDiscovery tools into a single workflow.
View on GitHub
// Certifications
Certified Ethical Hacker
CEH V12 PRACTICAL · EC-COUNCIL
Certified AppSec Practitioner
CAP · THE SECOPS GROUP
Certified Cloud Security Practitioner
CCSP-AWS · CLOUD SECURITY ALLIANCE
// Bug Bounty Hall of Fame

Companies Secured

0
COMPANIES WITH VALID REPORTS

Valid security vulnerabilities submitted via HackerOne and direct programs — from tech giants to government bodies.

Google Logo onerror="this.style.display='none';this.nextElementSibling.style.fontSize='24px'">Google
NASANASA
IBMIBM
AT&TAT&T
John DeereJohn Deere
BMWBMW
MercedesMercedes
VodafoneVodafone
SonySony
BBCBBC
LenskartLenskart
CBRECBRE
SupabaseSupabase
CircleCICircleCI
ESETESET
AirshipAirship
XsollaXsolla
VismaVisma
SIDNSIDN
WURWageningen University
DoDU.S. Dept. of Defense
United NationsUnited Nations
IntelIntel
NokiaNokia
PhilipsPhilips
StarbucksStarbucks
DellDell
LGLG
YahooYahoo
GitHubGitHub
// Security Writeups

Bug Bounty Stories

💉
IDOR · INJECTION
Mass Message Injection and IDOR in Account Verification
Two chained vulnerabilities discovered — mass message injection combined with IDOR in account verification flows, enabling unauthorized message delivery at scale.
🔍
RECON · OSINT
How I Earned a Bounty Using VirusTotal Recon
A creative OSINT approach using VirusTotal as a reconnaissance tool to uncover attack surface and land a valid bug bounty report — thinking beyond the usual toolset.
XSS · WEB
How I Found My First XSS on a Bug Bounty Program
The story of discovering a first Cross-Site Scripting vulnerability on a bug bounty program — the methodology, the payloads, and what made this find stand out.
View All Writeups on Medium
// Contact

Let's Connect

Phone
+91 7979948925
Location
Patna, Bihar, India
HackerOne