// sdlc-security
SDLC Security
Shift-left security across design, code, and release.
$ portfolio
Product Security
AppSec · DevSecOps · Threat modeling · Secure code review · Mobile & cloud security · Open-source research.
Product Security Engineer
$ ls portfolio/
Security tools, vulnerable labs, and learning resources — built in public on GitHub.
Open-source mobile AppSec playground showcasing insecure design patterns, threat modeling, and exploitation scenarios.
Open on GitHubOpen Source • Dec 2024 – PresentOpen-source iOS AppSec playground focused on product-security-first misconfiguration exploitation.
Open on GitHub97 stars • 25 forks • PugVulnerable NodeJS Web Application
Open on GitHub43 stars • 5 forks • ShellScanning APK file for URIs, endpoints & secrets.
Open on GitHub4 stars • 0 forks • HTMLDeep dives into application vulnerabilities, CVEs, bug bounty reports, and practical defensive insights.
Open on GitHub2 stars • 0 forks • Learning resourceComplete practical study plan for cybersecurity paths like Pentest, AppSec, Cloud Security, and DevSecOps.
Open on GitHubGrouped by domain — SDLC, supply chain, AI agents, web, mobile, cloud, and leadership.
// sdlc-security
Shift-left security across design, code, and release.
// supply-chain
Pipeline security, dependency trust, and CI/CD hardening.
// ai-agent-security
Securing AI systems, agents, and automated security workflows.
// mobile-security
Android, iOS, and reverse engineering depth.
// web-security
Web apps, APIs, and modern browser attack surfaces.
// cloud-security
Cloud posture, identity, and environment hardening.
// leadership
Driving secure outcomes with teams and stakeholders.
Product security, consulting, and hands-on offensive + defensive work.
Published research, engineering deep-dives, open-source work, and community knowledge sharing.
Hands-on guides on Frida, Android pentesting labs, content providers, native modules, protected components, and mobile security fundamentals.
How we built an end-to-end secret detection system at scale
Defense-in-depth secret scanning across IDE, pre-push hooks, CI/CD, Lambda, Confluence, Jira, Slack, and Postman — with centralized alerting and remediation.
Building and sharing practical repositories, experiments, and learning resources through GitHub.
Contributing through walkthroughs, research notes, and practical explanations that help other engineers learn faster.
Talk recordings, Black Hat Arsenal, Seasides, and community speaking.
Black Hat Europe 2024
Your Mobile AppSec Playground to Explore, Exploit & Excel
with Amit Kumar & Vedant Wayal
Showcased open-source Android AppSec playground with 30+ vulnerabilities and real-world mobile pentesting scenarios at the Arsenal track.

India's Most Loved Conference
Defend Android Apps — Reveal Weaknesses, Implement Robust Strategies
with Amit Kumar & Gaurav Bhosale
Hands-on session on Android security weaknesses, defensive strategies, and shielding apps against real-world exploitation.

Season 4 · 3-Day Online Workshop
Day 1 · 4-hour hands-on workshop
with Amit Kumar
Workshop on writing bypass code for Android security checks — root detection, emulator checks, Frida hooks, and runtime protection evasion. Delivered as Security Consultant at Payatu.
$ ./connect.sh
Open to security consulting, talks, and collaboration on open-source AppSec tools.