Skip to content
View SujalMeghwal's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report SujalMeghwal

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
SujalMeghwal/README.md

Sujal Meghwal Penetration Tester & Founder, NullStrike Security

I run NullStrike Security a penetration testing firm focused on web/API security and cloud infrastructure. I work with real clients on real systems: finding what their scanners miss, before attackers do.


What I Do

Web & API Penetration Testing Depending on Scope my Each Engagement Last around 1-4 week. and Currenlty able to offer compliance drive penetration Testing in HIPPA, ISO 27001, SOC 2 Type II..

Cloud Penetration Testing Primary focus: GCP. Also AWS and Azure. Misconfigurations, overprivileged service accounts, lateral movement, privilege escalation to org-level access.

Bug Bounty Large public programs as real-world R&D realistic, messy targets at scale that labs cannot replicate.

Custom Tooling Payloads, offensive scripts, and runbooks in Python, C, and C++ when existing tools fall short or leave too much noise.


Current Focus

  • Cloud identity attacks GCP service accounts, workload identity, IAM privilege escalation
  • AI / LLM security prompt injection, model abuse, insecure integrations
  • Building NullStrike's practice in healthcare and regulated industries

Direction

3-4 years in cloud and web pentesting, then deeper into cloud red teaming and Active Directory / cloud identity attack chains.


Contact


Stack

Python C C++ Bash GCP AWS Azure Linux Docker Burp Suite

pacman contribution graph

Pinned Loading

  1. SidePeek.js SidePeek.js Public

    SidePeek.js is a curated set of JavaScript payloads for browser-based recon. Run them in DevTools or as bookmarklets to uncover hidden APIs, DOM sinks, secrets, and client-side attack surfaces. Bui…

    21 6

  2. ExploitForge ExploitForge Public

    Comprehensive automation for exploitation, privilege escalation, and post-exploitation techniques in penetration testing. This repository contains scripts and tools designed for building, exploitin…

    Python 1

  3. PowerOpsToolKit PowerOpsToolKit Public

    Offensive PowerShell toolkit for red teams and internal assessments — WMI, recon, lateral movement, and access testing at scale.

    PowerShell