Arpit
Toppo

Red Team Enthusiast · Bug Hunter · Web Pentester _

BCA student at JECRC University specializing in Cybersecurity. Focused on red teaming, bug hunting, and application security — exploring both offensive and defensive sides of the threat landscape.

Get in Touch View Resume
3+
CERTIFICATIONS
2+
YEARS STUDYING
BCA
CURRENT DEGREE
01

ABOUT ME

I'm passionate about ethical hacking, red teaming, and continuous learning in cybersecurity. Currently in my 2nd year of BCA at JECRC University with a specialization in Cybersecurity.

I work with tools like Kali Linux and Burp Suite, and experiment with C2 frameworks such as Sliver, Mythic, StarKiller, and Havoc for controlled lab research.

My goal is to become a skilled red team operator who understands technical depth and ethical responsibility.


Download Resume
whoami.sh
$cat profile.json
{
  "name": "Arpit Toppo",
  "role": "Red Team Enthusiast",
  "education": "BCA @ JECRC",
  "year": 2,
  "focus": [
    "Bug Hunting",
    "Web Pentesting",
    "AppSec",
    "Red Teaming"
  ],
  "status": "Learning & Growing"
}
$
02

SKILLS

⚔️
OFFENSIVE SECURITY

Red teaming workflows, controlled testing, and ethical exploitation methodologies.

Red Teaming Exploitation Evasion
🌐
WEB & APPSEC

OWASP Top 10, XSS, SSRF, IDOR, server misconfigurations and web pentesting.

XSS SSRF IDOR OWASP
🛠️
TOOLS & PLATFORMS

Kali Linux, Burp Suite Pro, PowerShell, Go, and SharpCollection for engagements.

Kali Linux Burp Suite PowerShell Go
🎯
C2 & PAYLOAD DEV

Havoc, StarKiller, Mythic, Sliver — encryption + obfuscation payloads, evasion research.

Havoc Mythic Sliver StarKiller
🔐
PRIVILEGE ESCALATION

UAC research, registry persistence, DLL hijacking, and service misconfigurations.

UAC Bypass DLL Hijack Persistence
📋
REPORTING & DOCS

Clear PoCs, responsible disclosure, and structured vulnerability reports.

PoC Writing Disclosure Reports
03

PROJECTS

PROJECT_001

GeoIP Bash

A simple and clean Bash script that retrieves geographic information of an IP address — including country, city, ISP, and coordinates. Lightweight, dependency-free, and built for quick OSINT recon.

Bash OSINT Recon Shell Scripting
↗ View on GitHub
04

CERTIFICATES

🛡️
EC-COUNCIL
EC-Council Certified Security Specialist (ECSS)

Demonstrates understanding of ethical hacking, network defense, and cybersecurity fundamentals.

↗ View Certificate
🎓
ACADEMOR
Cybersecurity Internship

Completed a 2-month internship (Oct–Nov 2024) gaining hands-on experience in practical cybersecurity tasks.

↗ View Certificate
🔒
EC-COUNCIL
Certified Network Defender (CND)

Knowledge of network security, defensive mechanisms, and threat detection — focused on securing enterprise networks through monitoring, incident response, and effective defense strategies.

↗ View Certificate
05

CONTACT

Let's Connect

Feel free to reach out for collaborations, bug bounty discussions, or just to talk about cybersecurity.