▸ identity verified · uid=1000
ASTIK RAWAT
$ ahrixia // senior security consultant @ swarmnetics
▸ singapore offsec community ambassador
I break things on purpose so attackers can't. Half the time I'm not entirely sure what I'm doing — honestly more than half my job is troubleshooting, and somehow that works out. I'll keep at it until I can buy a patch of land, retire, and farm in Kuantan.
- [OSCE3]
- [OSCP+]
- [OSWE]
- [OSEP]
- [CRTO]
- [PNPT]
- [eMAPT]
- [OSWP]
- CVEs disclosed
- 15+
- clients secured
- 110+
- certifications
- 46+
- article views
- 70K+

▸ ./services --list
offensive capabilities
End-to-end offensive security across application, infra, mobile, cloud and AI surfaces — delivered with reproducible PoCs and remediation guidance.
- [WAPT]
Web Application
OWASP Top 10, business logic, auth bypass.
- [MAPT]
Mobile App
Android & iOS — static, dynamic, runtime.
- [NWPT]
Network
Internal & external infra, AD, lateral movement.
- [WLAN]
Wireless
WPA2/3, Evil Twin, rogue AP, segmentation.
- [TAPT]
Thick Client
Binary, IPC, traffic & local-storage abuse.
- [HCR]
Host Config Review
CIS benchmarks, hardening, drift detection.
- [PHSH]
Phishing
Spear, vishing & adversary-simulation campaigns.
- [LLM]
AI / LLM / Chatbot
Prompt injection, jailbreaks, OWASP LLM Top 10.
- [SCR]
Source Code Review
SAST + manual review across modern stacks.
- [WAF]
WAF Testing
Bypass research, rule tuning, false-positive triage.
- [CLD]
Cloud VAPT
AWS only — IAM, misconfig, privesc & escalation paths. Azure & GCP on the roadmap.
- [CCR]
Cloud Config Review
AWS/Azure/GCP baseline & CIS benchmark review — IAM, networking, logging, KMS.
- [OT]
OT Pentest
ICS / SCADA — Purdue model, protocol & segmentation review.
- [IOT]
IoT Pentest
Firmware, hardware, radio & companion-app attack surface.
- [CINF]
Critical Infrastructure
SWIFT systems, AS/400, mainframes and other legacy industrial platforms.
projects & research_
▸ selected work — research, community contributions and engagements.
open-source · k8s
k8s-enum.sh
github.com/ahrixia · Feb 2026 – present
LinPEAS-style Kubernetes enumeration scripts for pentesters and red teamers — color-coded output highlighting privesc vectors and misconfigurations.
vuln-research
15+ CVE Discoveries
MITRE / NVD
Disclosed SQLi, XSS, CSRF, RCE, auth-bypass and DLL-injection issues in production software (CVE-2024-57426, CVE-2023-44811, CVE-2023-45542, …).
program
OffSec Ambassador — Singapore
Offensive Security
Public speaking, mentoring OSCP / OSWE candidates and technical knowledge sharing for the Singapore cybersecurity community.
writing
Write-ups & Cert Reviews
Medium · @astikrawat
Real-world experiences with offensive certifications, hands-on tools and CTFs.
responsible-disclosure
Bug Bounty — Gov Platforms
SG · MY · APAC
Reported high-severity issues in regional government platforms, including PII exposure and zero-click full account takeover.
consulting
Enterprise VAPT Engagements
Swarmnetics
Delivered VAPT for 110+ clients across web, mobile, network, wireless, thick-client and cloud — black-box and grey-box, on-site, remote and hybrid.