Arpit
Toppo

Red Team Enthusiast · Bug Hunter · Web Pentester _

BCA student at JECRC University specializing in Cybersecurity. Focused on red teaming, bug hunting, and application security — exploring both offensive and defensive sides of the threat landscape.

Get in Touch View Resume
4+
CERTIFICATIONS
3+
YEARS STUDYING
BCA
CURRENT DEGREE
01

ABOUT ME

I'm passionate about ethical hacking, red teaming, and continuous learning in cybersecurity. Currently in my 3rd year of BCA at JECRC University with a specialization in Cybersecurity.

I work with tools like Kali Linux and Burp Suite, and experiment with C2 frameworks such as Sliver, Mythic, StarKiller, and Havoc for controlled lab research.

My goal is to become a skilled red team operator who understands technical depth and ethical responsibility.


Download Resume
whoami.sh
$cat profile.json
{
  "name": "Arpit Toppo",
  "role": "Red Team Enthusiast",
  "education": "BCA @ JECRC",
  "year": 3,
  "focus": [
    "Bug Hunting",
    "Web Pentesting",
    "AppSec",
    "Red Teaming"
  ],
  "status": "Learning & Growing"
}
$
02

SKILLS

⚔️
OFFENSIVE SECURITY

Red teaming workflows, controlled testing, and ethical exploitation methodologies.

Red Teaming Exploitation Evasion
🌐
WEB & APPSEC

OWASP Top 10, XSS, SSRF, IDOR, server misconfigurations and web pentesting.

XSS SSRF IDOR OWASP
🛠️
TOOLS & PLATFORMS

Kali Linux, Burp Suite Pro, PowerShell, Go, and SharpCollection for engagements.

Kali Linux Burp Suite PowerShell Go
🎯
C2 & PAYLOAD DEV

Havoc, StarKiller, Mythic, Sliver — encryption + obfuscation payloads, evasion research.

Havoc Mythic Sliver StarKiller
🔐
PRIVILEGE ESCALATION

UAC research, registry persistence, DLL hijacking, and service misconfigurations.

UAC Bypass DLL Hijack Persistence
📋
REPORTING & DOCS

Clear PoCs, responsible disclosure, and structured vulnerability reports.

PoC Writing Disclosure Reports
03

PROJECTS

PROJECT_001

GeoIP Bash

A simple and clean Bash script that retrieves geographic information of an IP address — including country, city, ISP, and coordinates. Lightweight, dependency-free, and built for quick OSINT recon.

Bash OSINT Recon Shell Scripting
↗ View on GitHub
PROJECT_002

RedForge

An open-source, Python-based Red Team Operations Workbench designed to help security professionals organize engagements, manage evidence, document findings, and generate professional reports — all in one place.

Python PySide6 Red Teaming SQLite Pentesting
↗ View on GitHub
04

CERTIFICATES

🛡️
EC-COUNCIL
EC-Council Certified Security Specialist (ECSS)

Demonstrates understanding of ethical hacking, network defense, and cybersecurity fundamentals.

↗ View Certificate
🎓
ACADEMOR
Cybersecurity Internship

Completed a 2-month internship (Oct–Nov 2024) gaining hands-on experience in practical cybersecurity tasks.

↗ View Certificate
🔒
EC-COUNCIL
Certified Network Defender (CND)

Knowledge of network security, defensive mechanisms, and threat detection — focused on securing enterprise networks through monitoring, incident response, and effective defense strategies.

↗ View Certificate
EC-COUNCIL
Certified Ethical Hacker (CEH)

Knowledge of ethical hacking methodologies, penetration testing, and vulnerability assessment — focused on identifying, exploiting, and securing systems through industry-standard offensive security techniques.

↗ View Certificate
05

ACHIEVEMENTS

🏆
PRAGYAN 2026 · HACKATHON

2nd Place Winner

🥈 RUNNER-UP

Secured 2nd place at Pragyan 2026 by developing and presenting a digital forensics solution, demonstrating practical investigation techniques, analytical thinking, teamwork, and problem-solving under hackathon conditions.

Pragyan 2026 — 2nd Place

// PRAGYAN_2026 · TEAM_PHOTO

06

CONTACT

Let's Connect

Feel free to reach out for collaborations, bug bounty discussions, or just to talk about cybersecurity.