Sitelet https://github.com/cyberhavik
Skip to content
View cyberhavik's full-sized avatar
🎯
Focusing
🎯
Focusing
  • Patna ,Bihar
  • 00:19 (UTC -12:00)

Block or report cyberhavik

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cyberhavik/README.md
Saurav Kumar - Cybersecurity Analyst and Full-Stack Developer



Profile Views LinkedIn Portfolio Encrypted Mail IEEE Publication


[OPERATIONAL SUMMARY]
Cybersecurity analyst and software engineer specializing in web vulnerability assessment, zero-trust infrastructure, and AI security research. I build systems that stay secure under real attack conditions and write code that ships fast without exposing new attack surfaces.


⚑ 0x01 · Security Tools & Platforms

Python Flask Selenium MySQL

An automated application security tester designed to catch injection vulnerabilities before attackers do. It runs fast and keeps setup simple.

  • Scans web apps for OWASP Top 10 flaws without manual configuration.
  • Tests injection points and checks exposed REST API endpoints.
  • Outputs clear vulnerability reports that tell developers exactly what to fix and how to patch it.
Python Flask Selenium Heuristics

A local intrusion prevention tool built to stop credential harvesting and phishing attacks on the desktop before payloads execute.

  • Inspects live traffic and breaks down link structures in real time.
  • Uses behavioral threat detection to catch spoofed login pages and unrated domains.
  • Intercepts navigation attempts instantly when a link fails verification checks.
Next.js 15 React 19 Express Prisma

A content management system built on strict zero-trust principles. It handles high traffic while maintaining clear internal privilege boundaries.

  • Enforces secure JSON web token auth with short session lifetimes and strict verification.
  • Applies clear role-based access control to block vertical privilege escalation.
  • Sanitizes all incoming data at the API edge to stop cross-site scripting and database injection.
Next.js TypeScript Firebase Genkit Gemini

A vision assistant built to give low-vision users real-time spatial navigation and environmental awareness through natural spoken interaction.

  • Runs Gemini Vision models to analyze optical camera feeds with minimal processing overhead.
  • Detects physical obstacles, identifies signs, and decodes sign language gestures directly from video streams.
  • Keeps inference latency low so feedback feels instantaneous and natural in everyday use.


πŸ“’ 0x02 Β· The Dual-Voice Distribution Engine

Every release, open-source SDK, and security advisory follows a two-channel communication structure. This keeps technical clarity high for engineers while delivering clear risk metrics to executive leadership:

πŸ› οΈ 1. The Hacker-Builder Voice (Developer Channels)

  • Target Channels: Personal LinkedIn, X (Twitter), GitHub repositories, and developer community boards.
  • Primary Focus: Developer experience, open-source SDK releases in Python and JavaScript, CLI speed, local key verification, and clear installation instructions.
  • Tone: Direct, objective, and casual. Speak plain engineering logic like one developer talking to another over coffee. No buzzwords or PR agency fluff.

🏒 2. The Sponsor Voice (Institutional & Corporate Channels)

  • Target Channels: Corporate and institutional feeds, security newsletters, and industry partner networks.
  • Primary Focus: Enterprise risk management, non-human identity controls, system governance, root registry updates, and regulatory compliance across OWASP and data privacy standards.
  • Tone: Calm, authoritative, and focused on operational risk. Present verified facts directly to CISOs, security directors, and technology governance officers.


🌐 0x03 · Community & Operations

πŸ“ Partner: Cybersecurity Community Operations

[DCG Gurugram] Β· Aug 2025 - Present

  • Organize local vulnerability research meetups, live exploit breakdown sessions, and practical application security workshops.
  • Connect bug bounty hunters, security engineers, and developers to share actual threat data and practical defensive code.

πŸ“ IoT Security Head

[MRISA: Manav Rachna InfoSec Army] Β· Aug 2024 - Present

  • Lead embedded device firmware dissection and wireless hardware hackathons. Mentor junior analysts in practical firmware dumping and protocol analysis.
  • Build infrastructure and custom challenge networks for university Capture The Flag competitions running with over 700 active players.
  • Run technical workshops that walk through practical exploit mechanics across standard web and network attack vectors.


πŸ›‘οΈ 0x04 Β· Technical Arsenal & Skills Matrix

πŸ”΄ Offensive Security & VAPT 🟒 Defensive & AppSec ⚑ Engineering & Cloud πŸ€– AI & Cognitive Security
VAPT Threat Modeling Python LLM Security
OWASP Top 10 Secure SDLC TypeScript PyTorch
CTF Operations Zero-Trust Auth Next.js 15 Computer Vision
Burp Suite & DAST Linux Hardening Docker & Azure Firebase Genkit


πŸ“‘ 0x05 Β· Research & Competition Record

πŸ”¬ Peer-Reviewed Research

Title       : "AI-Driven Techniques for Web Search Vulnerability Identification"
Publication : IEEE Xplore (2026)
Co-Authors  : Alan Jolly John, Sarthak Dubey, Saurav Kumar
Summary     : Built machine learning models to test, discover, and categorize structural flaws across modern web search backends.
Dossier     : https://ieeexplore.ieee.org/document/11386307

βš”οΈ CTF & Hackathon Record

Year Engagement & Competition Details Classification Outcome
2025 INTRUSIONX (Offensive Security & VAPT Tournament) Rank #1 πŸ₯‡ WINNER
2024 Avinya Tech Fest, IIT Guwahati (National Hackathon) National Finalist πŸŽ–οΈ FINALIST
2023 Hacksplash 1.0 (Software Engineering & Innovation) Rank #1 πŸ₯‡ WINNER
2024 CyCog CTF (Capture The Flag Security Competition) Rank #8 πŸ… TOP 10
2023 CyberHavoc CTF (National Cybersecurity Tournament) Rank 170 / 1500+ πŸ… TOP 11%
2023 Tech Trover Debugging (Code & Algorithmic Debugging) Rank #3 πŸ₯‰ 3RD PLACE


πŸ“‘ 0x06 Β· Live Telemetry & Activity

SOC Telemetry & Real-Time IDS Monitoring



Developer Operations & Code Telemetry


πŸ”’ SECURE BY DESIGN, TESTED BY BREACH. πŸ”’
[Operator Dossier Synchronized & Encrypted via Git Telemetry]

Popular repositories Loading

  1. IDM-Activation-Script IDM-Activation-Script Public

    An open-source tool to activate and reset the trial of Internet Download Manager

    Batchfile 1.2k 152

  2. cyberhavik cyberhavik Public

    4

  3. OBV_ctf OBV_ctf Public

    operation_black_vault

    Python 2 1

  4. Chrome_NewTab Chrome_NewTab Public

    Extension for chrome inspired by Google's 'Material You' design

    HTML 1 1

  5. the-librarian-game the-librarian-game Public

    JavaScript 1

  6. SMEH_NEWS SMEH_NEWS Public

    An open-source news content management system and editor dashboard built with Next.js 15, React 19, Express, Prisma, and Redis.

    TypeScript 1 1