infrared security research

Garvit Kanojia // ORBIT

SOC analyst · web security · pentester.
Breaking systems, building tools, tracking adversaries.

soc trained web 240+ labs pentest AD · cloud
~/orbit — zsh
$ whoami
Orbit — security researcher
$ cat roles.txt
┌──────────────────────────────┐
│ SOC Analyst │
│ Web Security Researcher │
│ Pentester │
│ Tool Builder │
└──────────────────────────────┘
$ _
◆ EPISODE 01 Profile

Breaking things
to fix them

I'm a security researcher from India who works across the full stack — from SOC operations and web application security to internal pentesting and cloud infrastructure. I don't specialize in one thing; I connect the dots between them.

Trained in SIEM operations, log analysis, and incident response — I can spot an SQLi in Apache logs, trace a C2 beacon in a PCAP, and follow the NIST framework from detection to recovery.

On the offensive side, I've completed 240+ PortSwigger labs across every category, submitted vulnerability reports on 5 bug bounty platforms, found hardware-level flaws in IoT devices through coordinated disclosure, and built my own security tooling for recon and automation.

SOC/IR Web Security Pentesting IoT Cloud

🧪
0+
PortSwigger Labs
📋
0+
Vulnerability Reports
🎯
0
Bug Bounty Platforms
⚠️
P0
Highest Severity
◆ EPISODE 03 Findings

Security research

Coordinated disclosures and bug bounty findings across IoT, blockchain, cloud, and web. Full technical writeups at /writeups.

🏆 Hall of Fame

SOLARMAN IoT — 7 Vulnerabilities

Discovered multiple security flaws in an IoT data logger including hardcoded credentials, missing authentication, and unrestricted firmware upload. Coordinated disclosure — Hall of Fame recognition. Full details publishable June 2027.

◆ EPISODE 04 Stack

Specialties

Core domains with proficiency levels — built through labs, real-world findings, and hands-on training.

◆ EPISODE 05 History

The journey

Key milestones in security research.

2026
P1 Critical — Polygon Technology
ERC-4337 bundler key exploitation chain across 7 EVM chains.
2026
Hall of Fame — SOLARMAN IoT
7 vulnerabilities in IoT data logger including unauthenticated firmware RCE.
2026
First Bug Bounty Submission
Began hunting across 5 platforms — web, cloud, blockchain, IoT.
2025
Started Security Research
Self-taught offensive security, tool building, and vulnerability research.
2027
⌘ What's next
SOC analyst role — applying the full spectrum of skills in a professional environment.