$ nmap -sC -sV -p- manthan.bhatt
Starting Nmap 7.94 ( https://nmap.org )
Nmap scan report for manthan.bhatt (AntisocialStare)
Host is up (0.0001s latency).
PORT STATE SERVICE VERSION
2028/tcp open education B.Tech CSE @ Nirma University
1337/tcp open offensive-sec Penetration Testing | Red Teaming | Post-Exploitation
2600/tcp open ctf-rank TryHackMe top 5% global | AWS CTF 125th global / 35th regional
8080/tcp filtered bug-bounty Bugcrowd active | HackWithIndiaa VDP (P2/P3 certified)
Host script results:
|_motd: I break things to understand them — then document exactly why they broke.
|_currently-running:
| [+] building L.E.A.P. v1.1.0 — Linux post-exploitation framework
| [+] building Homelab Dashboard (private) — SOC dashboard for a vuln-app fleet
| [+] active RegSentinel (private) — security layer lead, SuRaksha Hackathon
| [~] testing ExpenseFlow — OWASP Top 10 -> malware analysis -> C2 capture chain
Nmap done: 1 IP address (1 host up) scanned in 0.42 seconds
| Project | What it does | Stack |
|---|---|---|
| L.E.A.P. | Modular Bash post-exploitation framework — enumeration, privesc vectoring, container escape detection, in-memory C2 exfiltration | Bash |
| RegSentinel (private) | Agentic regulatory compliance system for SuRaksha Hackathon (Canara Bank) — sole security-layer lead: fingerprinting, hash-chained audit log, scoped JWTs, prompt-injection defenses | Next.js, FastAPI, LangGraph, PostgreSQL + pgvector |
| Homelab Dashboard (private) | Self-hosted SOC dashboard tracking a vulnerable-app fleet, test-coverage logs, and C2 session history, with a Vue directive enforcing sanitization before public display | Node/Express, MySQL, MongoDB, Vue.js |
| ExpenseFlow | Intentionally vulnerable app chaining OWASP Top 10 → malware analysis → C2 traffic capture, built for EHVA coursework (built, testing in progress) | Node.js, Express, PostgreSQL |
AWS Skills to Job CTF (SANS) — Ranked 125th globally / 35th regional · 20/37 challenges solved (Web Offensive, Forensics, Mixed Offensive) · Awarded 6-month SANS SkillQuest access
TryHackMe — Top 5% globally · 14 badges · Jr. Penetration Tester path complete (Metasploit, Burp Suite, network exploitation, Linux privesc)
Bug Bounty / VDP — Active on Bugcrowd; certified P2/P3 finding through the HackWithIndiaa Vulnerability Disclosure Program
Domains Penetration Testing · Web App Security · Post-Exploitation
Privilege Escalation · Network Enumeration · Container Security
Web Vulns SQLi · XSS · IDOR · SSRF · CORS Misconfig · OWASP Top 10
Recon subfinder · amass · httpx · katana · ffuf
- Testing ExpenseFlow's full attack chain end-to-end before EHVA submission
- Building out RegSentinel's audit-log and prompt-injection defense layers
- Expanding the homelab dashboard's telemetry modules
- Preparing for security engineering internship interviews
LinkedIn · Portfolio · bhattmanthan8@gmail.com · HTB · THM

