HI! I'M ISHAANI

|

ABOUT ME

I played my first CTF pretty randomly, with absolutely no idea what I was doing. I found a flag I was convinced was right and thought, “Wait, is this really what everyone says is so nerve-wracking?” Then I submitted it. Wrong flag.

I was immediately humbled. I spent the entire afternoon trying to find the right coordinates to some random place, and when I finally saw “CORRECT FLAG”, it genuinely felt like a next-level achievement. Next thing I knew, I was up all night trying to find as many flags as I could.I guess that's how it started.

Since then, CTFs turned into security research, bug hunting, red teaming, and eventually building my own gamified AI/ML security CTF platform www.ishaani.tech and security tools.

Right now, I'm finishing my degree, doing security research, building things, and still chasing that high of finding a vulnerability, a bug, or whatever else that shouldn't be there.

WHAT I DO

AI / ML SECURITY

AI Red TeamingPrompt InjectionJailbreak AttacksAdversarial MLModel EvasionData PoisoningLLM Threat ModelingOWASP Top 10 for LLMs

APPLICATION SECURITY

API SecurityWeb SecuritySSRFIDORXSSSQLiVulnerability AnalysisPenetration TestingBug BountyAuthentication & Access ControlSecure SDLC

SECURITY RESEARCH

Vulnerability ResearchResponsible DisclosureGovernment PortalsEnterprise Applications

SECURITY TOOLING

Security AutomationLLM Red TeamingAI DLPMCP SecuritySecurity ProxiesCTF Platforms

CTFs & CHALLENGE DESIGN

Web ExploitationOSINTCryptographyForensicsAI/ML SecurityChallenge Design

MY WORK

FlightZone Red Labs

Gamified AI/ML security CTF platform featuring 10+ progressive adversarial challenge tracks.
Covers prompt injection, data poisoning, model theft, insecure outputs & context obfuscation attacks.
AI SecurityCTFLLM Red Teaming

PasteGuard

Zero-server AI DLP browser extension for detecting and preventing sensitive data leaks in AI chatbots.
Uses lightweight ML classification with real-time automatic redaction and intent-aware filtering.
AI SecurityDLPMachine Learning

Adaptive LLM Red Team Scanner

Automated testing framework evaluating AI chatbots and agentic workflows across REST, SSE & WebSockets.
Employs genetic fuzzing and LLM-as-a-Judge validation to discover multi-turn prompt injection vulnerabilities.
LLM SecurityRed TeamingAutomation

Blockade

Security proxy intercepting communications between AI coding assistants and Model Context Protocol (MCP) servers.
Combines real-time risk scoring, taint tracking, tool-schema validation, and human-in-the-loop action approvals.
AI SecurityMCPApplication Security

WHAT I USE

Python
JavaScript
SQL
Docker
Linux
Burp Suite
OWASP ZAP
Postman
OpenAI
Scikit-learn
Pandas
NumPy
Streamlit
Jupyter
MCP
GitHub
SQLite
Python
JavaScript
SQL
Docker
Linux
Burp Suite
OWASP ZAP
Postman
OpenAI
Scikit-learn
Pandas
NumPy
Streamlit
Jupyter
MCP
GitHub
SQLite
Python
JavaScript
SQL
Docker
Linux
Burp Suite
OWASP ZAP
Postman
OpenAI
Scikit-learn
Pandas
NumPy
Streamlit
Jupyter
MCP
GitHub
SQLite
Python
JavaScript
SQL
Docker
Linux
Burp Suite
OWASP ZAP
Postman
OpenAI
Scikit-learn
Pandas
NumPy
Streamlit
Jupyter
MCP
GitHub
SQLite

ACHIEVEMENTS

CTFs

TOP 5% Consistent CTF Performance
TOP 4

IIITB CTF

TOP 10

Eschaton CTF

TOP 20

Illuminate CTF

TOP 20

CREST CTF

Vulnerability Disclosures

Application Security Testing across major private enterprises and government portals
Critical Vulnerability Disclosure through Bugcrowd, CERT-In & NCIIPC
Organizations Assessed:
Global Technology Enterprise
IT & Software Services
FoodTech & Vending
4+ Government Portals

CONTACT ME

Get In Touch

I’m interested in AI/ML security research, vulnerability research, and CTF collaborations. If you’re working on a security problem or research project, feel free to reach out!

LocationMumbai, India