karthick@kali:~
$ whoami

Karthickraja S

Penetration Tester · SOC Analyst · Vulnerability Analyst · eJPT Certified

I break into systems on purpose — then help fix what let me in. Hands-on experience across penetration testing, vulnerability assessment, and SOC operations, with three self-built labs to show the work, not just list the tools.

About

Summary

eJPT-certified Penetration Tester and SOC Analyst with hands-on experience in penetration testing, vulnerability assessment, network exploitation, SOC operations, VAPT, threat detection, and incident response. I like taking new tools apart to see how they work, and I care about turning that curiosity into fewer real-world security gaps for the teams I work with.

23
vulns found in a live
client AWS environment
3
end-to-end security
projects shipped
1
industry certification
(eJPT)
Skills

What I work with

Offensive tools

NmapMetasploitBurp Suite CrackMapExecSQLMapNikto GobusterSublist3renum4linux NetcatMimikatzWireshark

Pentest techniques

Network ScanningService Enumeration ExploitationPost-Exploitation Privilege EscalationPass-the-Hash Active Directory AttacksPassword Cracking

Web security

SQL InjectionXSSOWASP Top 10 DVWAWebGoatPortSwigger Academy SSL/TLS Analysis

SIEM & monitoring

Wazuh (SIEM/XDR)SysmonLog Analysis Alert TriageDetection TuningSyslog

Scripting & frameworks

PythonPowerShellMITRE ATT&CK CVSS v3.1NIST SP 800-115

Practice platforms

TryHackMe — activeHack The Box — active PortSwigger AcademyPentesterLab
Certification

Credentials

eJPT — eLearnSecurity Junior Penetration Tester

INE Security · Issued March 2026
Certificate ID: 177505505 · certs.ine.com/47c95437-cfc4-426d-9e52-e1bc29f0607a
VERIFIED
Projects

Featured work

Academic Institution Black-Box Penetration Test — AWS Infrastructure

Mar 2026

Hired to test a live college's cloud systems (AWS) the same way a real hacker would — no inside knowledge to start. Went back after fixes were made to confirm they actually worked, and delivered a clear before/after report the client could act on.

9 Critical 8 High 6 Medium
AWS EC2Black-Box TestingRemediation Verification

AttackRange — Purple-Team Detection Lab

Jul 2026

Built a test lab to play both sides of a cyberattack: broke into a target system using real hacker techniques (password guessing, exploiting a known vulnerability) to gain full control, then set up monitoring to catch that same attack live. Found a blind spot where the attack was slipping past undetected, and fixed it so it now triggers an automatic alert.

NmapHydraMetasploit Wazuh SIEMDockerBash MITRE ATT&CK T1110 / T1190 / T1082 / T1033

ThreatScope SOC — Real-Time Honeypot Threat Intelligence Dashboard

Jul 2026

Set up a decoy server designed to attract real hackers, then built a live dashboard showing exactly what they did — logins, commands typed, files downloaded — as it happened. Built the backend that automatically scores how dangerous each attack is and matches it against known industry-wide attack patterns.

Cowrie HoneypotDockerFlask PythonSQLiteREST APIs MITRE ATT&CK Mapping
Education

Background

B.Tech in Information Technology

Kalasalingam Academy of Research and Education · 2022 – 2026
CGPA: 8.53 / 10 · Coursework: Network Security, Cryptography, Computer Networks, Operating Systems, Database Systems