AADITHYA VIMAL
TECHNICAL

For engineers who want the full picture.

This is the deep end: how my projects are built, how I run infrastructure, and what my security research actually involves. Plain language where possible, precise terms where they matter.

5+

SURFACES SHIPPED (CLI · MCP · VS CODE · WEB)

0

SECRETS LEAVING THE DEVICE (LOCAL-FIRST)

2

FULL VAPT LAB REPORTS WITH FIXES

STACK

HOW I BUILD

Default stack: TypeScript + Next.js + PostgreSQL, deployed on Linux servers I administer myself (Docker, Nginx, automated TLS). Python for data pipelines and security tooling. AI features stay local-first where privacy matters — DuckDB in the browser, on-device inference, secret redaction before any model call.

Two principles: deterministic tools are authoritative, AI is advisory — and data stays local unless there’s a reason to move it. Each project page documents the specific architecture and tradeoffs.

DEFAULT_LOADOUT // HP

TYPESCRIPTAPP + TOOLING · 92%
NEXT.JSSSR + ROUTES · 88%
POSTGRESQLSOURCE OF TRUTH · 82%
PYTHONPIPELINES + TOOLING · 78%
DOCKERSHIP + RUN · 84%
LIVE FIRE

TRY THEM INSIDE THIS PAGE

Two production builds running live below — ThreatStream threat intel and Horcrux recon console. Interact, then open direct or read the source.

SLOT 01 // THREAT INTEL GLOBEOPEN DIRECT ↗
🔒threatstream.pages.dev
CONNECTING TO THREATSTREAM...
SLOT 02 // RECON CONSOLEOPEN DIRECT ↗
🔒horcruxtool.pages.dev
CONNECTING TO HORCRUX...
SECURITY RESEARCH

SECURITY, RESPONSIBLY

All offensive work below happened in isolated lab environments I control — never against systems I don’t own. The point of each exercise: understand the failure, then write the fix.

Metasploitable2 Vulnerability Assessment — CVE-2011-2523 (VSFTPD 2.3.4 Backdoor)

Target: Linux Metasploitable2 Host (Isolated Lab)
Method: PTES (Penetration Testing Execution Standard)

Penetration testing in an isolated lab: network reconnaissance, VSFTPD 2.3.4 backdoor exploitation, payload inspection, and host remediation.

  • Nmap
  • Metasploit
  • Wireshark
  • Linux
  • Bash

The full report walks through every command — recon, exploitation, credential cracking — and ends with a prioritized remediation table.

READ THE FULL LAB REPORT ON GITHUB ↗

Windows 7 Legacy Infrastructure Audit — MS17-010 (EternalBlue SMBv1)

Target: Windows 7 SP1 x64 (Isolated Lab)
Method: Vulnerability Assessment & Credential Auditing

Demonstrated remote code execution vulnerabilities in unpatched legacy SMBv1 services in an isolated virtual lab. Extracted NTLM hashes and audited Active Directory password complexity compliance.

  • Metasploit
  • Hashcat
  • Mimikatz
  • Active Directory
  • SMBv1

The full report walks through every command — recon, exploitation, credential cracking — and ends with a prioritized remediation table.

READ THE FULL LAB REPORT ON GITHUB ↗

ThreatStream Threat Intelligence Pipeline — Brute-force / Scanning Infrastructure

Target: Global Malicious IP Feeds
Method: Automated Threat Ingestion & Geolocation

Ingested and normalized threat intelligence from public blocklists, resolved threat origins with MaxMind databases, and visualized active attack infrastructure on a 3D WebGL globe.

  • Python
  • MaxMind GeoIP
  • React Three Fiber
  • Firestore

The full report walks through every command — recon, exploitation, credential cracking — and ends with a prioritized remediation table.

READ THE FULL LAB REPORT ON GITHUB ↗

Broader practice: Top 3% on TryHackMe (146 rooms, 18 badges) and the Google Cybersecurity Professional Certificate.

SKILL MATRIX

LOADOUT STATS

RANKDOMAINARSENAL
SOFFENSIVE SECURITYNmapMetasploitBurp SuiteSQLiOWASP Top 10Kali
ADEFENSIVEIncident ResponseSIEMSplunkChronicleIAMRBAC
SLINUX & INFRASECSSHNginxHardeningFirewallDocker
ANETWORKTCP/IPDNSWiresharkVPN
WRITEUP Nº 001

THM-MD2PDF WALKTHROUGH

My only published technical writeup — and it meets the bar I hold everything else to: a complete TryHackMe walkthrough with every command, every finding and every fix, written to be reproduced step by step in an isolated lab.