Security Analyst

Komal Prasad

Ethical Hacker · Penetration Tester

As a Security Analyst with over 1.5 years of hands-on experience, I specialize in penetration testing across web applications, mobile (iOS & Android), APIs, and network infrastructure. I'm driven by a passion for breaking things — methodically — so they can be built back stronger.

// quick profile
⚡ Experience 1.8 Years
🎯 Web Apps Tested 30+
🔬 API Assessments 5
🚩 TryHackMe Top 7%
eJPT APISec CCEP
scroll
// who i am

About Me

01 Security Analyst
B.Tech Computer Science
🛡️
Komal Prasad
SECURITY ANALYST · eJPT
Penetration Testing85%
Cookie Compliance Check90%
Web App Security90%
Mobile App Security70%
API Testing95%

As a Security Analyst with 1.8 years of hands-on experience, I specialize in web application penetration testing and API security assessments. I've pentested over 30 web applications and conducted 5 API security assessments, uncovering vulnerabilities across diverse technology stacks and business domains.

Currently, I work on Cookie Compliance management using OneTrust — ensuring organizations meet global privacy regulations through comprehensive cookie scanning, consent management, and compliance reporting. This has given me deep insight into the intersection of privacy, compliance, and security.

I hold certifications including eJPT, APIsec Certified Practitioner, and Certified Cybersecurity Educator Professional (CCEP). I actively solve TryHackMe rooms (Top 7%) to sharpen my skills and stay current with the evolving threat landscape. I'm driven by a passion for continuous learning and hands-on problem-solving — always exploring new tools, techniques, and automation to improve efficiency.

eJPT Certified THM Top 7%
// capabilities

Skill Arsenal

02 5 Core Domains
12+ Tools & Frameworks
🎯
Web Application Security
CORE COMPETENCY
Web App Pentesting (Burp Suite)90%
OWASP Top 10 Assessment88%
Manual Security Testing85%
🔗
API & Backend Security
ACTIVE RESEARCH
API Security Testing (Postman)85%
JWT / OAuth Analysis75%
📱
Mobile Application Security
GROWING EXPERTISE
Android Pentesting (JADX, MobSF)75%
iOS App Analysis (Pacifist)70%
🌐
Network & Infrastructure
SOLID FOUNDATION
Network Pentesting (Nmap, CLI)85%
Metasploit Framework75%
🛡️
Compliance & Automation
PRODUCTION READY
Cookie Compliance (OneTrust)90%
Python / Bash Scripting80%
// operation logs

Notable Operations

03 2 Active Projects
Automation & Writeups
subrecon · RECONACTIVE
subrecon — Multi-Source Subdomain Enumeration
Modular Python tool that aggregates subdomains from Certificate Transparency logs (crt.sh), Wayback Machine, AlienVault OTX, URLScan.io, and DNS brute-force with 800+ common names. Features DNS resolution with wildcard detection, HTTP probing with 40+ tech fingerprints, rich HTML/JSON reports, and a Flask web dashboard with scan history.
PythonFlaskDNSOSINTReconHTML Report
ACTIVE DEPLOYMENTVIEW ON GITHUB →
WRITEUPS · THMACTIVE
TryHackMe Writeups & Walkthroughs
Detailed step-by-step walkthroughs of TryHackMe rooms covering web exploitation, privilege escalation, Active Directory attacks, and OSINT challenges. Published on GitHub Pages for the security community.
TryHackMeCTFWalkthroughWriteupEducation
REGULARLY UPDATEDVISIT SITE →
// career path

Work Experience

04 1.8 Years Experience
Security Analyst
2024 — Present
Security Analyst
  • Performing Cookie Compliance management using OneTrust — scanning, consent management, and regulatory reporting
  • Conducted penetration testing on 30+ web applications and 5 API assessments
  • Built subrecon — multi-source subdomain enumeration toolkit with Flask web UI and automated reporting
  • Active on TryHackMe (Top 7%) — continuously sharpening offensive security skills
// let's connect

Say Hello

05 Open to Opportunities
Globally Available

Available for penetration testing engagements, bug bounty collaborations, and security consulting. Let's build something secure together.