naveen.sec boot console

>
>
>
>
>
inject() → path_traversal
watson.analyze(target)
SSRF → 169.254.169.254
consent_id replay :: escalated

// Offensive Security Engineer

NAVEENSINGH

AI Security · Cloud-Native Pentesting · Tool Builder

Turning offensive depth into defensive_

SCROLL TO EXPLORE
01

-// about.log

From Analyst to Adversary Emulator

Seven-plus years in product offense, identity abuse testing, and AI-integrated security engineering.

  1. Kenvue

    enterprise appsec

    Lead Security Analyst

    2023 - Present

    Leading threat-led offensive validation for customer-facing platforms and AI-assisted approval flows.

  2. EY

    consulting

    Application Security Consultant

    2021 - 2023

    Drove secure SDLC adoption and attack-surface reduction programs across regulated global environments.

  3. Atos

    cloud security

    Security Engineer

    2019 - 2021

    Built cloud security baselines and offensive test playbooks for large distributed systems.

  4. CoreCard

    payments

    Security Analyst

    2017 - 2019

    Performed deep web/API assessments, threat modeling, and incident-driven hardening for payment workloads.

02

-// capability.matrix

Capability Surfaces

ai

AI & Agentic Security

Control model behavior under adversarial pressure.

LLM threat modeling

./probe

prompt injection

./probe

RAG poisoning

./probe

agent sandbox escape

./probe

03
04

-// attack.scenarios

Breach Flow Diagrams

SSO Chaining → Account Takeover

critical
01

Token Discovery

Enumerate token relay points and weak trust assertions between identity providers.

02

Relay Forge

Craft a forged relay flow that preserves valid session artifacts during redirect.

03

Session Graft

Bind the forged token stream into a victim-linked session context.

04

Privilege Lift

Escalate role scope through federated mapping drift and stale claims.

⚠ impact

Full account takeover across federated tenants.

05

-// operator.history

Operator History

High-impact offensive programs across enterprise platforms, cloud workloads, and identity surfaces.

2023 - Present

Kenvue

Lead Security Analyst

  • Scaled appsec controls across enterprise product lines.
  • Modeled AI-assisted workflow abuse for high-risk approvals.
  • Reduced exploitability in identity and API entry points.
SemgrepBurp SuiteNucleiKubernetesAWS

2021 - 2023

EY

Application Security Consultant

  • Embedded threat modeling into engineering planning cycles.
  • Built offensive test playbooks for regulated workloads.
  • Improved release confidence through targeted abuse testing.
OWASP ASVSDASTIaC scanningJira

2019 - 2021

Atos

Security Engineer

  • Hardened cloud baselines for multi-region deployments.
  • Introduced pipeline security checks for critical services.
  • Validated controls with internal adversary emulation.
TerraformAzureGCPPythonGo

2017 - 2019

CoreCard

Security Analyst

  • Performed deep web and API assessments for fintech products.
  • Partnered with developers on vulnerability closure velocity.
  • Documented repeatable exploit chains for secure coding training.
Burp SuiteffufSQLMapPostman
06

-// hall.of.impact

Notable Findings

SSO Token Chaining → Account Takeover

critical

Chained SSO misconfiguration across identity providers to expose tokens and achieve account takeover.

XXE via Document Upload

critical

Triggered XML entity resolution in document processing to read internal files and backend metadata.

SSRF → Cloud Metadata Exfiltration

critical

Server-side fetch path reached cloud metadata endpoint and exposed role credentials.

OAuth Flow Misconfiguration

high

Redirect and session handling weaknesses enabled privilege escalation paths.

Prompt Injection in Agentic Workflow

high

Injected instruction chain overrode policy and drove unauthorized tool invocation.

Business Logic Funds Manipulation

critical

Multi-step workflow abuse allowed unauthorized transaction intent mutation.

07

-// tech-stack

Arsenal

Languages

5
PythonGoTypeScriptBashRust

Cloud

5
AWSGCPAzureKubernetesTerraform

Frameworks

4
FastAPINext.jsSpringNode.js

AI Security

4
LangChainLlamaIndexGuardrailsRebuff

Offensive

5
Burp SuiteNucleiSemgrepffufCaido

Certifications

OSCP

CEH

CISSP (in progress)

AWS Security Specialty

08

-// contact.sh

Open a Channel

terminal

$ help

help | whoami | ls /skills | cat /contact | connect <msg> | clear