Skip to content
View kakashi-kx's full-sized avatar

Block or report kakashi-kx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kakashi-kx/README.md


"The quieter you become, the more you are able to hear."


⟡ Profile

Abhijith S. — terminal profile card

⟡ Technical Arsenal

Languages




Core Competencies




Tools & Platforms




In Progress




⟡ Certifications

Advanced Diploma in Cyber Defense — Red/Blue Teaming, AD Red Teaming, ISMS/ISO 27001


⟡ Featured Project

APT Emulation Platform

Python MITRE ATT&CK Status License

Open-source Python platform simulating nation-state adversary techniques mapped to MITRE ATT&CK — built for red teams and researchers to emulate realistic threat-actor behavior in controlled environments.

├── Modular TTP execution engine
├── MITRE ATT&CK technique mapping
├── Configurable attack scenarios
├── JSON-based reporting output
└── Docker-ready deployment

⟡ Security Credits — Live

Auto-refreshed daily by a GitHub Action pulling directly from the GitHub Security Advisory API. New credits appear here automatically once GitHub publishes them — nothing manual after setup. See scripts/update_security_credits.py.

Advisory Severity Package CVE
repomix: Command Injection (RCE) via --remote-branch Argument Injection HIGH repomix (npm) CVE-2026-49987
Auth.js: Email normalizer validates address before Unicode normalization — homoglyph @ bypass CRITICAL @auth/core (npm) CVE-2026-73420

⟡ Research & Discoveries

ComOlho Bugcrowd HackerOne

Published ResearchMedium @kakashi4kx

  • "Why I Thought I Found a Zero-Day: The False Positive Trap in Bug Bounty" — the mental discipline and technical verification required when chasing critical vulnerabilities, and how to avoid wasting time on false positives.

⟡ Research Impact — Live

Auto-refreshed by the same GitHub Action that updates the credits table below — these are counted straight from data/security_credits.json and the live advisory API, not GitHub's commit-graph vanity metrics.


⟡ GitHub Activity


⟡ Ethics

All research, tools, and proof-of-concept code in these repositories are developed for authorized security testing and educational purposes only, following coordinated vulnerability disclosure. Never test systems without explicit written permission.


⟡ Connect

LinkedIn Medium GitHub Bugcrowd HackerOne



Pinned Loading

  1. ghostiam ghostiam Public

    Deploy decoy AWS IAM identities and catch attacker reconnaissance in seconds. Honeytoken framework with a live dashboard, MITRE ATT&CK journey mapping, and multi-platform mesh (AWS + GitHub + Okta).

    Go 2

  2. apt-emulation-platform apt-emulation-platform Public

    apt-emulation-platform

    Python 4 1

  3. WAFMANCER WAFMANCER Public

    🧠 WAFMANCER v2.0 — Next-Gen WAF Evasion Framework. AI-powered payload synthesis. Trust-based WAF manipulation. Bypassed Cloudflare. 50+ mutations. PoC generator. "Not a tool. A research weapon." 🔥

    Python 2

  4. AION AION Public

    Red Teaming Framework

    Python 3

  5. kakashi-kx kakashi-kx Public

    me as

    Python