Skip to content
View Satz-N-Sentry's full-sized avatar
πŸ’­
🧐
πŸ’­
🧐

Block or report Satz-N-Sentry

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Satz-N-Sentry/README.md

Satheesh Nithiananthan

Security Researcher Β· Penetration Tester Β· Bug Bounty Hunter

Typing SVG


🎯 Specialization

I specialize in web application and mobile security research with a primary focus on:

  • Authentication & Authorization Bypass β€” OAuth flows, JWT weaknesses, session management failures
  • API Security β€” REST API abuse, mass assignment, parameter pollution, cross-tenant IDOR
  • Real-time Protocol Security β€” WebSocket authentication bypass, private event channel hijacking
  • Secret Exposure β€” SSR framework leaks, JS bundle analysis, supply chain passive recon
  • Mobile Security β€” Frida Gadget injection, SSL pinning bypass, APK analysis, gRPC interception
  • Business Logic Flaws β€” Tenant isolation failures, privilege escalation, access control gaps

All research follows OWASP Top 10:2025 Β· CWE mapping Β· Responsible disclosure only


πŸ”¬ Security Research & Bug Bounty

All research conducted under authorized bug bounty and VDP programs only. Responsible disclosure principles strictly followed across all engagements.

Vulnerability CWE Severity Platform Status
Cross-tenant WebSocket authentication bypass β€” unauthorized private channel subscription across tenant boundaries via improper Pusher auth token issuance β€” real-time security event eavesdropping confirmed CWE-284 πŸ”΄ High Intigriti Under Review
Server-side authorization bypass β€” cross-tenant write operations accepted with misleading 2xx responses bypassing tenant isolation controls CWE-755 🟑 Medium Intigriti Under Review
Tenant workspace enumeration via distinguishable API error responses on authenticated endpoints CWE-203 🟒 Low Intigriti Under Review
SSR framework secret exposure β€” production API token leaked in client-side state hydration β€” full read/write dataset access independently confirmed CWE-798 πŸ”΄ High HackerOne VDP Independently Validated
Hardcoded blockchain service credentials exposed in public JS bundle β€” multi-network surveillance risk across 7 chains CWE-798 🟑 Medium Bugcrowd Independently Validated
IDOR on financial ranking endpoint β€” private user financial data exposure CWE-639 🟑 Medium Bugcrowd Independently Validated
RBAC failures Β· AI endpoint over-privilege Β· security misconfigurations across live production assets β€” mapped to OWASP Top 10:2025 CWE-862, CWE-1336, CWE-693 🟑 Medium NCSA Bug Bounty VDP Certificate of Appreciation

Active Platforms

HackerOne Bugcrowd Intigriti


πŸ›  Technical Arsenal

Offensive Security

Web Application    β”‚ IDOR Β· XSS Β· SQLi Β· SSRF Β· CSRF Β· Auth Bypass Β· Business Logic
API Security       β”‚ REST abuse Β· Mass Assignment Β· Parameter Pollution Β· JWT Attacks
Mobile Security    β”‚ Frida Β· objection Β· APK patching Β· SSL pinning bypass Β· gRPC interception
Recon              β”‚ Subdomain enum Β· JS bundle analysis Β· SSR secret hunting Β· OSINT
WebSocket          β”‚ Auth bypass Β· Channel hijacking Β· Cross-tenant event eavesdropping
OAuth/Session      β”‚ State CSRF Β· redirect_uri bypass Β· Token leakage Β· Session fixation
Blockchain         β”‚ Smart contract recon Β· API key exposure Β· Web3 endpoint analysis

Defensive Security

SIEM               β”‚ Wazuh β€” custom detection rules Β· alert correlation Β· log forensics
Threat Detection   β”‚ Honeypot deployment Β· botnet identification Β· DPI analysis
Malware Analysis   β”‚ Android static analysis Β· ML-based detection Β· behavior mapping

Primary Toolchain

Core               β”‚ Burp Suite Β· Kali Linux Β· Postman Β· Nuclei
Recon              β”‚ Subfinder Β· ffuf Β· XnLinkFinder Β· Amass Β· httpx
Mobile             β”‚ Frida Β· objection Β· apktool Β· adb Β· apksigner
Analysis           β”‚ Wireshark Β· jwt.io Β· CyberChef Β· Shodan
Scripting          β”‚ Python Β· Bash Β· Docker

πŸ“ Research Portfolio

Project Focus Impact
frida-ssl-bypass-setup Non-rooted Android SSL pinning bypass β€” Frida Gadget injection methodology Mobile Bug Bounty Β· CWE-295
Supply-Chain-Secret-Hunting SSR token exposure via passive JS bundle recon CWE-798 Β· High Β· Independently Validated
NCSA-VDP-Assessment Full passive VAPT β€” RBAC, AI over-privilege, misconfigs Certificate of Appreciation
FUTURE_CS_03 API Security β€” 9 vulnerabilities on OWASP crAPI OWASP Β· CVE Β· MITRE mapped
android-malware-analysis ML malware detection β€” Random Forest β€” 100% recall Static analysis Β· scikit-learn Β· Python
SAIZERO-Cowrie-Honeypot SSH honeypot β€” real botnet confirmed β€” Wazuh SIEM integration Real-world threat intelligence
wazuh-nmap-detection Real-time scan detection β€” TCP/UDP/ICMP β€” Level 15 critical alerts Custom Wazuh rule engine
wazuh-homelab Enterprise-grade Wazuh Manager & Agent homelab Production-ready SIEM setup

πŸ“Š OWASP Top 10:2025 Coverage

A01 Broken Access Control          β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  IDOR Β· Tenant Isolation Β· RBAC Bypass
A02 Cryptographic Failures         β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘  JWT Β· Token Exposure Β· Weak Crypto
A03 Injection                      β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘  SQLi Β· XSS Β· SSTI Β· Command Injection
A04 Insecure Design                β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  Business Logic Β· Auth Flow Design
A05 Security Misconfiguration      β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘  API Keys Β· Headers Β· Debug Endpoints
A06 Vulnerable & Outdated Components β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  Supply Chain Β· Dependency Analysis
A07 Auth & Identification Failures β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘  OAuth Β· WebSocket Β· Session Fixation
A08 Software & Data Integrity      β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  Webhook Β· Supply Chain Β· JS Tampering
A09 Security Logging & Monitoring  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  Blind Spots Β· Error Disclosure
A10 Server-Side Request Forgery    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  Webhook Abuse Β· Integration Endpoints

πŸ… Certifications & Recognition

Credential Issuer
🎯 CICSA β€” Certified IT Infrastructure & Cyber SOC Analyst RedTeam Hacker Academy
🎯 National Cybersecurity Certification NCSA Maldives
πŸŽ“ BSc Computer Science Alagappa University

πŸ“ˆ Current Research Focus

current_targets = {
    "priority_1": "Mobile API surface β€” gRPC method enumeration via Frida",
    "priority_2": "OAuth CSRF β€” state parameter validation bypass",
    "priority_3": "SSRF via webhook and integration endpoints",
    "priority_4": "JWT algorithm confusion β€” HS256 β†’ none/RS256",
    "priority_5": "Mass assignment on user profile endpoints"
}

methodology = "OWASP Top 10:2025 β†’ Threat model β†’ PoC β†’ Responsible disclosure"
affiliation  = "SAIZERO β€” Ground Zero Defence"

🌐 Connect

LinkedIn HackerOne Bugcrowd Intigriti TryHackMe


πŸ”§ Skills

Kali Linux Burp Suite OWASP Frida Nuclei Wireshark Wazuh Postman Python Docker Linux scikit-learn Bug Bounty Mobile Security WebSocket Security API Security JWT Analysis IDOR SSR Security Blockchain Security Passive Recon


SAIZERO β€” Ground Zero Defence

Affiliated independent security research unit Β· Est. 2025

Visitor Count

CyberLycan β€” Every shadow has a hunter 🐺

Popular repositories Loading

  1. wazuh-homelab wazuh-homelab Public

    Wazuh Manager & Agent installation

  2. wazuh-nmap-detection wazuh-nmap-detection Public

    Real-time Nmap port scan detection using Wazuh SIEM custom rules | Blue Team Home Lab

  3. FUTURE_CS_01 FUTURE_CS_01 Public

    VAPT Report β€” OWASP Juice Shop | SAIZERO Ground Zero Defence | Web Application Penetration Testing 2026

    HTML

  4. Satz-N-Sentry Satz-N-Sentry Public

  5. FUTURE_CS_02 FUTURE_CS_02 Public

    Phishing Email Analysis β€” Header Inspection, SPF/DKIM/DMARC, IOC Extraction | SAIZERO Ground Zero Defence

  6. FUTURE_CS_03 FUTURE_CS_03 Public

    API Security Risk Analysis β€” OWASP crAPI | 9 Vulnerabilities mapped to OWASP API Top 10, CVE, MITRE ATT&CK | SAIZERO