Security engineer and founder building offensive/defensive tooling, secure full-stack products, and hardware wireless kits β with ~200 open-source security tools shipped and a focus on systems that stay maintainable as they grow.
| Identity |
Nikhil Nagpure Β· 5h4d0wn1kπ Open to relocation & frequent travel Β· always exploring somewhere new |
| Education | B.Tech CSE β Cybersecurity & Digital Forensics, VIT Bhopal (2021β2025) Β· CGPA 8.33/10 |
| Now |
Technical Lead @ CuboidSoft Β·
Founder @ Shadownik Β·
Founding SWE @ Pawan Technologies Previously: Offensive Security Intern @ InLighnX Β· Ethical Hacking Intern @ Internship Studio |
| Focus | Offensive Security Β· Red Teaming Β· API Security Β· AI/LLM Security Β· Hardware-Wireless Pentesting Β· Secure Full-Stack |
| Building | ApiSecPlatform (enterprise API security testing) Β· Portable Wireless Pentest Toolkit (ESP32-based) Β· SentinelWall AI threat detection |
| Project | Description | Stars |
|---|---|---|
| photo-organizer | Local-first, private-by-default photo & video library β Rust daemon + Flutter desktop, SQLCipher vault, ChaCha20-Poly1305 encryption, OCR & scene search, P2P LAN sync | |
| Decentralized Cloud Storage | Blockchain-backed decentralized storage β Solidity smart contracts sharing encrypted file references with on-chain access control | |
| ML Web-Attack Detection | ML-powered web-attack detection β phishing URL, DoS intrusion & XSS classification | |
| cybersecurity-framework | Interactive map of everything in cybersecurity β 27 domains, 776 categories, 1,067 curated offensive & defensive tools | |
| ApiSecPlatform | Enterprise API security platform for automated testing, threat insights, and OWASP-aligned checks | β |
| Portable Wireless Pentesting Toolkit | ESP32-based field pentesting device for wireless assessments and protocol testing | β |
The current effort β autonomous offensive/defensive security tooling for authorized labs. Every tool ships with docs, tests, and explicit legal-use boundaries.
| Tool | What it does |
|---|---|
| sentinelwall | Autonomous AI network threat detection & correlation β MITRE ATT&CK mapping, ML anomaly detection, rule DSL, STIX/Navigator/HTML exports |
| mythicforge | Adversarial LLM prompt-injection & jailbreak testing β 37 techniques, OWASP/NIST/MITRE ATLAS benchmarks, SARIF reports |
| shadowvault | Cryptographic secrets lifecycle manager β AES-256-GCM vault, OPSEC zeroize, team RBAC, migration tools |
| hermesc2 | C2 & post-exploitation research framework (lab) β listeners, stagers, beacons, encrypted transport, killswitch, offline loopback-only demo |
| viperstrike | MCP (Model Context Protocol) server vulnerability auditor β AST/whitebox SAST for agentic AI tool handlers, SARIF-capable |
| crownjewel | Cross-cloud identity federation auditor β Golden/Silver SAML, OAuth client-ID spoofing, OIDC validation, offline fixtures |
| aiarsenal | Adversarial AI/ML security studio β data poisoning, model backdoors, extraction, membership inference, prompt injection, agentic red-team planner |
| webbreach | OWASP Top-10 web exploitation framework β built-in localhost vulnerable targets, AI-guided scan queue |
| cloudpwn | Cloud & container penetration suite β AWS/GCP/Azure enumeration, docker leaks, k8s secrets, terraform audit, CSPM |
| supplysec | Supply-chain security gate β SBOM (CycloneDX/SPDX), offline advisory matching, policy gates, post-quantum scanning |
| toxindb | RAG retrieval-time poisoning detector β canary injection, provenance attestation, SARIF+MD reports |
| honeynet | Honeypot farm + deception grid β multi-protocol honeypots, attacker fingerprinting, dwell/risk scoring, quarantine |
198+ catalog security tools and counting β see the security tool catalog. For more flagships:
cryptocrack,grainrecon,exploitcraft,mobsek,endpointaegis,netpwn,wiair,socialforge,sprayshed,rogueai,postpwn, and thew/m/c/d/f/h/i/n/p/r/se/web/x/ai/clcoded series. All for authorized testing only.
Technical Lead β CuboidSoft (Jan 2025 - Present)
- Lead an IT software company delivering custom web applications, mobile apps, and digital solutions for SMEs and startups across multiple domains.
- Lead full-stack architecture and development for client projects using Next.js, Node.js, PostgreSQL, and modern frontend frameworks to build secure, scalable applications.
- Own development workflows end-to-end: Git version control, CI/CD pipelines, code reviews, and cloud/VPS deployment.
- Ship on company strategy, branding, and go-to-market β service packaging, proposal writing, and technical client presentations.
Founder β Shadownik Β· Freelance Venture (Jun 2024 - Present)
- Built and scaled a multi-service freelance venture across cybersecurity, full-stack engineering, cloud deployment, and digital operations.
- Delivered secure production systems and offensive security assessments for real-world clients.
- Leading product development for ApiSecPlatform and multiple automation-focused services.
- Developing responsive production web apps and scalable backend APIs.
- Building integrations, database workflows, and cloud-ready deployment pipelines.
- Performing web application security assessments (OWASP Top 10, Burp Suite, Metasploit), threat modeling, and red-team simulations.
- Contributing to large-scale IT infrastructure defense: intrusion detection monitoring, vulnerability triage, and security reporting.
- Identified and mitigated XSS vulnerabilities in production web applications; authored remediation reports.
- Designed practical security lab environments simulating real-world attack scenarios.
| Contributions | 3,003 in 2026 Β· 631 last week Β· 174 active days this year |
| Pull Requests | 134 authored Β· 95 merged |
| Repos on GitHub | 243 Β· 230 built from scratch Β· 770+ total stars |
| Organizations | 3 orgs Β· 20 repos (Shadownik Β· Cuboidsoft Β· CuboidPilot) |
Active contributor to major upstream projects:
- TheAlgorithms/Python β reversort generic & odd-even transposition generic β merged
- freeCodeCamp β truthy/falsy curriculum fix β merged
- pandas β GroupBy.agg MultiIndex bug (open)
- scipy β duplicate CSR entries in bipartite matching (open)
- SymPy β solve domain fix (open)
- EbookFoundation/free-programming-books β dead-link repair via Wayback (open)
- CEH (EC-Council)
- CNSP (The SecOps Group)
- Practical Ethical Hacking (TCM Security)
- Patent filed: A Self-Cleaning Glasses Case System (Application No: 202421032123)



