Hi, I'm
Vishal Vishwakarma
I help organizations find what attackers would — across AI/LLM features, cloud infrastructure, web & APIs. Black-box penetration testing, red teaming, exposure analysis and security automation for fintech, banking and e-commerce.
Who I am
I break into things before someone with worse intentions does. As an Offensive Security Consultant at NetSentries — and a security analyst — I think like the attacker against banks, fintechs and the platforms that move people's money, chaining the small oversights everyone overlooks into the breach that actually matters.
These days that means AI / LLM penetration testing and cloud security — pressure-testing the models, features and infrastructure teams ship faster than they can secure. Black-box, zero-knowledge, automation-heavy. Off the clock I hunt private programs on Bugcrowd & Yogosha and run The Cyber Explorers.
What I do
Work history
Certs & recognition
Certifications
Disclosed CVEs
Recognition
- Global Hall of Fame — 300+ orgs incl. Google, Sony, BBC
- Yogosha Strike Force — selected member
- The Cyber Explorers — founder, cybersecurity YouTube
Hunt like a pro
Beginner roadmap
Research checklist
Free recon tools I built
Browser-based, keyless, client-side — built for bug-bounty recon. No install, nothing logged.
Subdomain Enumeration
Passive subdomain discovery from crt.sh, CertSpotter, DNSRepo, HackerTarget & OTX — merged, de-duped, with live DNS resolution and export.
recon.rootxvishal.comPassive URL Crawler
Historical URL & endpoint discovery from the Wayback Machine, Common Crawl, AlienVault OTX & URLScan — de-duped by path, with status codes and CSV export.
crawler.rootxvishal.comLet's secure what you ship.
Need a pentest, red-team engagement, AI/LLM or cloud security review — or a private bug-bounty invite? I'm open to engagements.