Vikas Anand — VAPT expert with 50+ engagements across web, API, Android & network. Based in Patna, India.
I'm a Security Analyst with deep hands-on experience in Web Application, API, Android, and Network Penetration Testing. I've conducted 50+ VAPT engagements identifying 300+ vulnerabilities across government and private-sector clients.
I've helped secure 40+ government organizations and 10+ private-sector companies by identifying critical risks and supporting effective remediation — from auth flaws and IDOR to injection and business logic weaknesses.
Beyond client work, I actively participate in bug bounty programs across HackerOne and have reported valid findings to over 100 global companies including Google, NASA, DoD, and the United Nations.
OWASP Top 10, auth flaws, IDOR, injection, business logic vulnerabilities.
REST & GraphQL APIs, broken object-level auth, fuzzing, rate limiting.
Mobile app analysis with Frida, Objection, JADX, MobSF, ADB.
Scanning, exploitation, vulnerability assessment with Nessus & Nmap.
Valid security vulnerabilities submitted via HackerOne and direct programs — from tech giants to government bodies.
onerror="this.style.display='none';this.nextElementSibling.style.fontSize='24px'">Google