Security engineer and founder building offensive/defensive tooling, secure full-stack products, and hardware wireless kits — with ~200 open-source security tools shipped and a focus on systems that stay maintainable as they grow.
| Identity |
Nikhil Nagpure · 5h4d0wn1k🌍 Open to relocation & frequent travel · always exploring somewhere new |
| Education | B.Tech CSE — Cybersecurity & Digital Forensics, VIT Bhopal (2021–2025) · CGPA 8.33/10 |
| Now |
Technical Lead @ CuboidSoft ·
Founder @ Shadownik ·
Founding SWE @ Pawan Technologies Previously: Offensive Security Intern @ InLighnX · Ethical Hacking Intern @ Internship Studio |
| Focus | Offensive Security · Red Teaming · API Security · AI/LLM Security · Hardware-Wireless Pentesting · Secure Full-Stack |
| Building | ApiSecPlatform (enterprise API security testing) · Portable Wireless Pentest Toolkit (ESP32-based) · SentinelWall AI threat detection |
| Project | Description | Stars |
|---|---|---|
| photo-organizer | Local-first, private-by-default photo & video library — Rust daemon + Flutter desktop, SQLCipher vault, ChaCha20-Poly1305 encryption, OCR & scene search, P2P LAN sync | |
| Decentralized Cloud Storage | Blockchain-backed decentralized storage — Solidity smart contracts sharing encrypted file references with on-chain access control | |
| ML Web-Attack Detection | ML-powered web-attack detection — phishing URL, DoS intrusion & XSS classification | |
| cybersecurity-framework | Interactive map of everything in cybersecurity — 27 domains, 776 categories, 1,067 curated offensive & defensive tools | |
| ApiSecPlatform | Enterprise API security platform for automated testing, threat insights, and OWASP-aligned checks | — |
| Portable Wireless Pentesting Toolkit | ESP32-based field pentesting device for wireless assessments and protocol testing | — |
The current effort — autonomous offensive/defensive security tooling for authorized labs. Every tool ships with docs, tests, and explicit legal-use boundaries.
| Tool | What it does |
|---|---|
| sentinelwall | Autonomous AI network threat detection & correlation — MITRE ATT&CK mapping, ML anomaly detection, rule DSL, STIX/Navigator/HTML exports |
| mythicforge | Adversarial LLM prompt-injection & jailbreak testing — 37 techniques, OWASP/NIST/MITRE ATLAS benchmarks, SARIF reports |
| shadowvault | Cryptographic secrets lifecycle manager — AES-256-GCM vault, OPSEC zeroize, team RBAC, migration tools |
| hermesc2 | C2 & post-exploitation research framework (lab) — listeners, stagers, beacons, encrypted transport, killswitch, offline loopback-only demo |
| viperstrike | MCP (Model Context Protocol) server vulnerability auditor — AST/whitebox SAST for agentic AI tool handlers, SARIF-capable |
| crownjewel | Cross-cloud identity federation auditor — Golden/Silver SAML, OAuth client-ID spoofing, OIDC validation, offline fixtures |
| aiarsenal | Adversarial AI/ML security studio — data poisoning, model backdoors, extraction, membership inference, prompt injection, agentic red-team planner |
| webbreach | OWASP Top-10 web exploitation framework — built-in localhost vulnerable targets, AI-guided scan queue |
| cloudpwn | Cloud & container penetration suite — AWS/GCP/Azure enumeration, docker leaks, k8s secrets, terraform audit, CSPM |
| supplysec | Supply-chain security gate — SBOM (CycloneDX/SPDX), offline advisory matching, policy gates, post-quantum scanning |
| toxindb | RAG retrieval-time poisoning detector — canary injection, provenance attestation, SARIF+MD reports |
| honeynet | Honeypot farm + deception grid — multi-protocol honeypots, attacker fingerprinting, dwell/risk scoring, quarantine |
198+ catalog security tools and counting — see the security tool catalog. For more flagships:
cryptocrack,grainrecon,exploitcraft,mobsek,endpointaegis,netpwn,wiair,socialforge,sprayshed,rogueai,postpwn, and thew/m/c/d/f/h/i/n/p/r/se/web/x/ai/clcoded series. All for authorized testing only.
Technical Lead — CuboidSoft (Jan 2025 - Present)
- Lead an IT software company delivering custom web applications, mobile apps, and digital solutions for SMEs and startups across multiple domains.
- Lead full-stack architecture and development for client projects using Next.js, Node.js, PostgreSQL, and modern frontend frameworks to build secure, scalable applications.
- Own development workflows end-to-end: Git version control, CI/CD pipelines, code reviews, and cloud/VPS deployment.
- Ship on company strategy, branding, and go-to-market — service packaging, proposal writing, and technical client presentations.
Founder — Shadownik · Freelance Venture (Jun 2024 - Present)
- Built and scaled a multi-service freelance venture across cybersecurity, full-stack engineering, cloud deployment, and digital operations.
- Delivered secure production systems and offensive security assessments for real-world clients.
- Leading product development for ApiSecPlatform and multiple automation-focused services.
- Developing responsive production web apps and scalable backend APIs.
- Building integrations, database workflows, and cloud-ready deployment pipelines.
- Performing web application security assessments (OWASP Top 10, Burp Suite, Metasploit), threat modeling, and red-team simulations.
- Contributing to large-scale IT infrastructure defense: intrusion detection monitoring, vulnerability triage, and security reporting.
- Identified and mitigated XSS vulnerabilities in production web applications; authored remediation reports.
- Designed practical security lab environments simulating real-world attack scenarios.
| Contributions | 3,003 in 2026 · 631 last week · 174 active days this year |
| Pull Requests | 134 authored · 95 merged |
| Repos on GitHub | 243 · 230 built from scratch · 770+ total stars |
| Organizations | 3 orgs · 20 repos (Shadownik · Cuboidsoft · CuboidPilot) |
Active contributor to major upstream projects:
- TheAlgorithms/Python — reversort generic & odd-even transposition generic → merged
- freeCodeCamp — truthy/falsy curriculum fix → merged
- pandas — GroupBy.agg MultiIndex bug (open)
- scipy — duplicate CSR entries in bipartite matching (open)
- SymPy — solve domain fix (open)
- EbookFoundation/free-programming-books — dead-link repair via Wayback (open)
- CEH (EC-Council)
- CNSP (The SecOps Group)
- Practical Ethical Hacking (TCM Security)
- Patent filed: A Self-Cleaning Glasses Case System (Application No: 202421032123)