AADITHYA VIMAL
CYBERSECURITY

Test in the lab. Fix in production.

I'm a cybersecurity engineer. Everything offensive on this page happened in isolated lab environments I own — the point is always the same: understand the failure, then write the fix.

TOP 3%

TRYHACKME GLOBAL

146

LABS CLEARED

18

BADGES EARNED

8/8

GOOGLE COURSES

Profiles · verified elsewhere

Find me on the leaderboards.

TryHackMe logo

TRYHACKME

Top 3% globally

146 completed rooms and 18 badges across network security, privilege escalation, web exploitation and Linux defense. Lab hours nobody can fake.

HACKTHEBOX

Machines & challenges

My HackTheBox profile — active machines, completed challenges and ranking, verified live on the platform.

Field work · isolated labs

Full reports, every command included.

Metasploitable2 Vulnerability Assessment — CVE-2011-2523 (VSFTPD 2.3.4 Backdoor)

Target: Linux Metasploitable2 Host (Isolated Lab)
Method: PTES (Penetration Testing Execution Standard)

Penetration testing in an isolated lab: network reconnaissance, VSFTPD 2.3.4 backdoor exploitation, payload inspection, and host remediation.

  • Nmap
  • Metasploit
  • Wireshark
  • Linux
  • Bash

Read the full lab report

Windows 7 Legacy Infrastructure Audit — MS17-010 (EternalBlue SMBv1)

Target: Windows 7 SP1 x64 (Isolated Lab)
Method: Vulnerability Assessment & Credential Auditing

Demonstrated remote code execution vulnerabilities in unpatched legacy SMBv1 services in an isolated virtual lab. Extracted NTLM hashes and audited Active Directory password complexity compliance.

  • Metasploit
  • Hashcat
  • Mimikatz
  • Active Directory
  • SMBv1

Read the full lab report

ThreatStream Threat Intelligence Pipeline — Brute-force / Scanning Infrastructure

Target: Global Malicious IP Feeds
Method: Automated Threat Ingestion & Geolocation

Ingested and normalized threat intelligence from public blocklists, resolved threat origins with MaxMind databases, and visualized active attack infrastructure on a 3D WebGL globe.

  • Python
  • MaxMind GeoIP
  • React Three Fiber
  • Firestore

Read the full lab report

WRITEUP Nº 001

THM-MD2PDF Walkthrough

My only published writeup — a complete TryHackMe run with every command, every finding and every fix. The bar everything else has to clear before it lands here.

Security builds · shipped · live

Tools I built for the work.

Scroll inside — these are the real running applications, embedded live.

SECURITY2026● LIVE DEMO

Horcrux

An operator-grade reconnaissance orchestration console that unifies network discovery, service fingerprinting, web fuzzing, and exploit intelligence into verified evidence workspaces.

My role: Designed and built the Typer console, Rich live progress managers, service-to-module router, and Next Best Action engine.

  • Python
  • Typer
  • Rich
  • Nmap
  • Nuclei
🔒horcruxtool.pages.dev
CONNECTING TO HORCRUX...
SECURITY2026● LIVE DEMO

ThreatStream

A frontend-only live cyber threat intelligence monitor visualizing real-world malicious IP indicators across 7 switchable globe views with zero fabricated attack paths.

My role: Designed and built the browser-based multi-feed ingestion pipeline, diff-driven state engine, and Globe.GL 3D operations visualization.

  • JavaScript
  • React
  • Globe.GL
  • Three.js
  • GeoIP
🔒threatstream.pages.dev
CONNECTING TO THREATSTREAM...
SECURITY2026● LIVE DEMO

Draftoryn

A professional cybersecurity document studio generating 30 canonical offensive security, DFIR, threat intel, and GRC deliverables with a Zero Hallucination Guarantee and AES-256 encrypted export.

My role: Designed and built the cross-platform Expo studio, deterministic document engine, Hono API on Cloudflare Workers, and AES-256 ZIP packaging.

  • Expo
  • React Native Web
  • Hono
  • Neon PostgreSQL
  • Clerk Auth
🔒draftoryn.pages.dev
CONNECTING TO DRAFTORYN...