Skip to content
View Manif3stVoid's full-sized avatar

Block or report Manif3stVoid

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Manif3stVoid/README.md

Manif3stVoid banner

πŸ‘‹ Hey there, I'm Shankar Ramakrishnan (Manif3stVoid)

Security Consultant | OSCP | Crest | AI/ML

I believe in a proactive, curiosity-driven approach to cybersecurity: identifying weaknesses before adversaries do, building secure systems, and continuously learning in a rapidly evolving field.


🌟 About Me

  • πŸ” Skilled Penetration Tester: Specializing in Web Application, Mobile Application, API , AI/ML, SCR, and Network Security.
  • πŸ›‘οΈ Security Professional: Focused on ethical hacking, vulnerability assessment, and helping organizations strengthen their defenses.
  • πŸ’» Lifelong Learner: OSCP certified with a commitment to staying ahead of emerging threats through hands-on practice and certifications like Crest CRT.
  • 🧠 Experience: Over 7 years in cybersecurity, delivering high-quality security assessments and contributing to safer digital environments.

πŸ† Achievements & Recognitions

  • Reported critical vulnerabilities to organizations like Google, Apple, Facebook, Microsoft, and Asus etc.
  • Holder of OSCP (Offensive Security Certified Professional), Crest CRT , eWAPTxV2 , eJPT and Secops AI/ML certifications.
  • Discovered and reported CVE impacting widely-used iOS Edge browser.

πŸ› οΈ My Skillset

  • Web Application Penetration Testing
  • API Penetration Testing
  • Mobile Application Penetration Testing
  • Thick Client Penetration Testing
  • AI/ML Penetration Testing
  • Secure Code Review
  • Wifi Penetration Testing
  • Network Penetration Testing
  • Cloud Security (AWS / Azure)
  • Report Writing & Remediation Guidance

πŸš€ Tools & Contributions

  • Building custom scripts for automated recon, vulnerability discovery, and pentest workflow optimization.
  • Interested in collaborating on ethical hacking tools, internal security tooling, and CTF-style challenges.

All tools shared are for educational and authorized use only β€” always obtain permission before testing.


πŸ“œ Notable Findings & Real-World Impact

Highlights from hands-on security assessments (sanitized and anonymized):

  • πŸ”“ Authentication & Authorization Flaws: Identified broken access controls enabling privilege escalation to administrative roles.
  • πŸ§ͺ Business Logic Vulnerabilities: Discovered logic flaws bypassing payment, subscription, or workflow restrictions.
  • 🌐 Critical Web Vulnerabilities: Found SQL injection, stored XSS, and insecure deserialization with real exploitation paths.
  • πŸ“± Mobile Application Weaknesses: Identified insecure local storage, improper certificate validation, and API abuse issues.
  • πŸ–§ Network Misconfigurations: Exposed services, weak segmentation, and credential reuse enabling lateral movement.

🧠 Interview talking point: Many high-risk findings were uncovered through manual testing and threat modeling, not automated tools.


πŸ”₯ Featured Case Study: From Minor Bug to Full Account Takeover

Context
During a web application security assessment, several issues were initially classified as low to medium risk when viewed independently.

Findings Chained

  • An IDOR vulnerability exposing internal object references
  • Weak authorization checks on a secondary API endpoint
  • Predictable session handling logic

Impact
By chaining these flaws, it was possible to escalate from a standard user account to full account takeover of high-privilege users, including access to sensitive business data.

Why This Mattered

  • None of the issues were flagged as critical by automated scanners
  • Risk only became visible through manual analysis and attacker-style thinking
  • The exploit path directly reflected realistic abuse scenarios

🧠 Key takeaway: Security risk is cumulative β€” individually minor issues can combine into critical compromises.


πŸ“„ Research, Write-ups & Knowledge Sharing

  • Actively working on practical pentesting write-ups focused on exploitation chains and remediation strategies.
  • Strong interest in sharing real-world lessons learned from offensive security engagements.

(Links to blog posts, Medium articles, or conference talks can be added here.)


πŸ“ˆ GitHub Stats

Your GitHub stats

Top Languages

GitHub Streak


🌍 Connect With Me

Open to:

  • πŸ”­ Collaborations on security projects
  • 🌱 Discussions on OSCP prep, pentesting techniques, and career growth
  • πŸ’¬ Questions around real-world security assessments

⚑ Fun Fact (Pentester Edition)

I once chained three β€œlow-risk” vulnerabilities to achieve full account takeover β€” a reminder that context beats severity scores every time.


πŸ“œ License

All content and shared tools are released under the MIT License unless otherwise specified. Contributions are welcome β€” fork, improve, and submit pull requests!

Thanks for stopping by β€” and remember: attackers only need one weakness. πŸ›‘οΈ

Popular repositories Loading

  1. resolvers resolvers Public

    Forked from trickest/resolvers

    The most exhaustive list of reliable DNS resolvers.

  2. Nuclei-Templates-Collection Nuclei-Templates-Collection Public

    Forked from emadshanab/Nuclei-Templates-Collection

    Nuclei Templates Collection

    Python

  3. resolvers1 resolvers1 Public

    Forked from jaikishantulswani/Resolvers

    Daily updated list of resolvers

  4. subs_all subs_all Public

    Forked from emadshanab/subs_all

    Subdomain Enumeration Wordlist. 8956437 unique words. Updated.

  5. AES-hooker AES-hooker Public

    Forked from az0mb13/hooker

    Python

  6. Payload Payload Public