Skip to content
View 0xParth's full-sized avatar
😶‍🌫️
😶‍🌫️

Block or report 0xParth

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xParth/README.md

Parth Shukla — 0xParth

Building autonomous offensive security tooling at the intersection of AI agents and real-world infrastructure.
Creator of Pinaka · Speaker at 13+ international security conferences · AI Security Village Host @ BSides Luxembourg 2026


Research Focus

  • Agentic AI Security — attacking and defending AI agents with tool access in production environments
  • LLM Red Teaming — prompt injection, confused deputy attacks, excessive agency exploitation
  • MCP Security — Universal Socket MCP Server architecture, agentic attack surface mapping
  • API Security — OWASP API Top 10, attack surface management, automated exploit testing

Notable Findings

Target Severity Type
Emergent Critical Cloud infrastructure misconfiguration
RedBull Critical Autonomous agent finding — PII leakage
Porter High Sensitive data exposure

Projects

Pinaka — MCP-native autonomous penetration testing platform powered by Claude. Autonomous external recon agents, Shadow AI hunting, auto-bounty generation, Hunter dashboard. Has produced confirmed Critical findings against real-world production targets with zero human involvement.

coraza-leet-normalize — Open source transformation plugin for the Coraza WAF. Strips leet speak, Cyrillic/Greek homoglyphs, and zero-width Unicode characters before regex matching to catch WAF evasion attempts. Now officially listed on the Coraza plugins page.

Cyfer — Full-stack subdomain discovery and API attack surface tool. Flask, React, MongoDB, Shodan integration with ML-based misconfiguration detection.

LLM Red Team Ranger — Continuous LLM vulnerability testing via adversarial conversation simulation with severity classification and automatic halt on critical discovery.

PromptGuard — LLM system prompt vulnerability scanner aligned to OWASP LLM Top 10.

Intent Sentinel — LLM-aware AI firewall for chat interfaces using GPT-3.5 for intent classification and trust filtering.


Speaking

AI Security Village Host — BSides Luxembourg 2026 (May 6–8)
Curating a 2-day village with 12 sessions covering offensive AI, agentic risk, defensive tooling, and AI-as-a-Service security.

Featured Speaker at:
AI Dev World · API World · HOUSE SEC CON · InfoSec Nashville · BSides Cayman Islands · BSides Seattle · BSides Luxembourg · BSides SLC · BSides Pittsburgh · OWASP BASC · ISACA GRC · CyberJutSuCon · DASH by Datadog


Certifications

  • Certified AppSec Practitioner (CAP) — The SecOps Group
  • Certified AI/ML Pentester (C-AI/MLPEN) — The SecOps Group
  • MS in Cybersecurity — Northeastern University

Community

Bug XS (2019) — Founded and scaled a cybersecurity community. Trained 700+ students in web application security and bug bounty hunting across multiple colleges in Gujarat.

2nd Place — TCS Global Best Ethical Hacker Competition
Innovation Pride Award Q1 — Tata Consultancy Services


Connect

LinkedIn X Pinaka

Popular repositories Loading

  1. CEH-Practical-Guide CEH-Practical-Guide Public

    This Repo will help you to prepare better for CEH - Practical Exam

    53 11

  2. All-Bug-Dorks All-Bug-Dorks Public

    Google dorks to find Bug Bounty Programs.

    1

  3. SecLists SecLists Public

    Forked from danielmiessler/SecLists

    SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

    PHP 1

  4. nuclei-templates nuclei-templates Public

    Forked from projectdiscovery/nuclei-templates

    Community curated list of templates for the nuclei engine to find security vulnerabilities.

    JavaScript 1

  5. awesome-llm-apps awesome-llm-apps Public

    Forked from Shubhamsaboo/awesome-llm-apps

    Collection of awesome LLM apps with AI Agents and RAG using OpenAI, Anthropic, Gemini and opensource models.

    Python 1

  6. tools tools Public

    Installs tools

    Shell 1 3