Garvit Kanojia // ORBIT
SOC analyst · web security · pentester.
Breaking systems, building tools, tracking adversaries.
Breaking things
to fix them
I'm a security researcher from India who works across the full stack — from SOC operations and web application security to internal pentesting and cloud infrastructure. I don't specialize in one thing; I connect the dots between them.
Trained in SIEM operations, log analysis, and incident response — I can spot an SQLi in Apache logs, trace a C2 beacon in a PCAP, and follow the NIST framework from detection to recovery.
On the offensive side, I've completed 240+ PortSwigger labs across every category, submitted vulnerability reports on 5 bug bounty platforms, found hardware-level flaws in IoT devices through coordinated disclosure, and built my own security tooling for recon and automation.
SOC/IR Web Security Pentesting IoT Cloud
Built to break
Open-source security tools for recon, defense, and automation. Projects I've built and contributed to.
LIDRA
Lightweight recon and automation framework. Domain discovery, port scanning, endpoint mapping — single pipeline for security assessments.
OBSIDIOS
Autonomous network security platform with AI-driven CVE mapping, attack path simulation, 3D dashboard, and Discord alerting.
HYNTEL
Security audit script that automates intel gathering and vulnerability identification during internal assessments. Map networks, surface risks.
Security research
Coordinated disclosures and bug bounty findings across IoT, blockchain, cloud, and web. Full technical writeups at /writeups.
SOLARMAN IoT — 7 Vulnerabilities
Discovered multiple security flaws in an IoT data logger including hardcoded credentials, missing authentication, and unrestricted firmware upload. Coordinated disclosure — Hall of Fame recognition. Full details publishable June 2027.
ERC-4337 Bundler Key — 7 Chains [writeup →]
Hardcoded Pimlico bundler API key in JS bundle with unrestricted eth_sendUserOperation across 7 EVM chains. Smart wallet factory exploitation chain.
Unauthenticated S3 Write
Production S3 bucket with public write policies — anyone could upload, modify, or delete objects in a live banking environment.
Specialties
Core domains with proficiency levels — built through labs, real-world findings, and hands-on training.
The journey
Key milestones in security research.