I'm Sharan, an Independent Security Researcher. I hunt real‑world vulnerabilities, write PoC exploits, and I'm working toward my first conference talk.

Reporting on HackerOne and writing on Medium

Download resume
Sharan Kumar VR
Selected work

Some of these never leave my own lab. Others turn into tools and disclosures worth sharing — here are a few.

AI Trust Boundaries

Tested HubSpot's Breeze AI across 17 attack vectors and found its email and CRM-note pipelines treat trust differently — opening an indirect prompt-injection path. Reported through HackerOne and written up in full.

AI securityPrompt injectionHackerOne
Read case study →
HubSpot Breeze AI security assessment — attack surface and testing methodology map

WAVE

Web Automation Vulnerability Explorer — a Kali CLI scanner for bug-bounty recon: XSS, SQLi, NoSQLi, command injection, SSRF and access-control checks, plus subdomain/API discovery and automated HTML & JSON reports.

PythonBashBug bounty
See it in action →
Live scanWAVE running an XSS scan and reporting a confirmed payload

WNSA

Wireless Network Security Analyzer — a Linux-native 802.11 workbench: AP and client discovery, monitor-mode capture, WPA2/WPA3 handshake assessment and packet analysis in one PySide6 interface, for authorized labs.

PySide6802.11airodump-ng
See it in action →
Live captureWNSA dashboard with detected networks and a handshake capture

NeuralOps

An AI-powered Security Operations Center. It ingests security events, triages them with an AI analyst, maps activity to MITRE ATT&CK, and streams real-time incident alerts to a live command dashboard.

PythonGeminiMITRE ATT&CK
See it in action →
Live dashboardNeuralOps command center — alerts, volume and threat timeline

Echo Defend

Security-operations automation that handles authorized command retrieval, local CLI execution, result capture and webhook delivery — a lightweight ops pipeline for controlled, authorized environments.

PythonAutomationWebhooks
See it in action →
Echo Defend architecture — fetch a command file over HTTP, execute locally, deliver results to a webhook

Capture the Flag

Competing across campus, national and online events — a few podiums, plenty still in progress. 1st at Flagwars, top 10 at SIMLE, and 88th of 180,000+ at the TryHackMe Industrial CTF. Still grinding.

CTF
See my CTF journey →
Holding up a handful of medals — CTF wins
Scripts & PoCs — proof-of-concept exploits and offensive scripts: a terminal with xss, sqli, recon, automation and write-ups folders, and a Find / Test / Verify / Document workflow