This space is dedicated to documenting passive vulnerability assessments, threat modeling, and responsible disclosure case studies.
As a cybersecurity practitioner specializing in offensive security and web application penetration testing, I use this repository to demonstrate practical methodology, attack chain mapping, and adherence to ethical disclosure standards.
Each assessment follows a consistent, passive-only workflow:
- Scoping — define target boundaries and rules of engagement.
- Passive recon / OSINT — enumerate exposed surface without active probing.
- Threat modeling — map likely attack chains against the enumerated surface.
- Reporting — document findings with severity, impact, and remediation.
- Responsible disclosure — report to the owner / relevant CERT.
| Date | Target Sector | Assessment Type | Status | Report Link |
|---|---|---|---|---|
| June 2026 | Public Sector Enterprise | Passive Web Enumeration / OSINT | Remediated / Reported to CERT-In | View Report |
Note: All assessments documented in this repository are strictly passive. Target identifiers are anonymized to protect infrastructure.