About

Bikramjeet Singh | UnixSingh

Lead Penetration Tester, learning in public. I think like an adversary, document like a consultant.

My expertise lies in conducting targeted cyber security assessments across various environments - web applications, APIs, network infrastructure, Active Directory, cloud, AI and more. I focus on realistic, goal-driven testing rather than checkbox scanning.

I combine automation with manual tradecraft to find complex issues, validate real risk, and help teams harden their environments instead of chasing noise. The deliverable that matters is a clear report a developer or defender can act on the same week.

Never give up. Never back down - constantly learning, constantly breaking, constantly improving.

How I work

I map my work to recognised industry standards so findings connect directly to risk and controls: the OWASP Testing Guide, MITRE ATT&CK, CWE, SANS Top 25 and CIS Benchmarks. My priorities are enumeration depth over speed, chaining weaknesses into real compromise paths, and reporting that's genuinely actionable.

Focus areas

Web Apps & APIs Infrastructure Active Directory Cloud Config Reviews Gen AI App Testing Thick Client Mobile System Breakout Phishing Wireless
Capability map

MITRE ATT&CK coverage

Where my offensive work maps across the ATT&CK Enterprise matrix - breadth from reconnaissance through to impact. Hover any technique for its ID and coverage level.

Strong: routine in engagements Working: solid, deepening Exploring: actively learning ↔ scroll horizontally for all 14 tactics

Now

Current
Offensive security tradecraft

Deepening my testing methodology and hands-on offensive skills.

Current
Writing & publishing

Blogs, labs, tools and methodologies, including a new Threats & Exploits series.

In progress
AI / LLM security

Digging into how models actually work and how they fail, with a focus on practical, hands-on attacks on LLM apps.

Toolbox

A working selection - tools serve the method, not the other way around.

Burp Suite Nmap BloodHound Impacket CrackMapExec Metasploit sqlmap ffuf Nuclei Hashcat Responder Mimikatz MobSF / Frida ScoutSuite / Pacu Kube-bench Ghidra

Certifications

OSCPOffensive Security Certified Professional
PNPTPractical Network Penetration Tester
CASACertified Application Security Analyst

Training

CKSKubernetes Security Specialist course · KodeKloud (completed)
Get in touch ▸ Read the blog