Two engineers building offensive security tooling, running live engagements, and designing every CTF from scratch.
Founder of Nexploit and the person who ends up in every stack trace at 2 AM before a CTF launch. Ayush leads offensive engineering at Nexploit — penetration testing, exploit development, and building attack-chain challenges from the ground up. CCNA certified, self-taught through hundreds of hours on HackTheBox, and hooked on the moment a system finally gives up its root shell.
A running log of engagements, disclosures, and challenges — real targets, real chains.
Authorized testing across the platform's GraphQL API for IDOR issues, plus XSS probing with Burp Suite.
Vulnerability research engagement against production targets under Coinbase's responsible disclosure program.
Discovered network security exposures on-site and reported them through proper disclosure channels.
Built a full attack chain combining PHP type juggling with cron job log injection for privilege escalation.
Machine built around a Joomla CVE (CVE-2023-23752) exploitation chain.
A multi-stage attack chain — from a web application foothold all the way to root on Linux.
A hard reverse-engineering challenge built around a custom bytecode VM with anti-debug protections.
A web exploitation challenge chaining JWT "alg:none" forgery into server-side template injection.
An OSINT-meets-web hybrid challenge, themed around Mr. Robot's fictional security firm.
Founder of Nexploit and the reason the platform stays up while Ayush is busy breaking things. Akshay owns the cloud infrastructure — deployments, uptime, and everything that keeps CTFd instances, subdomains, and SSL running without a hitch during live events — alongside the business side of Nexploit: partnerships, operations, and keeping the studio moving.
The infrastructure and business backbone that lets Nexploit ship on time.
Manages the cloud environment powering Nexploit's CTF platform, keeping every event live and stable end to end.
Handles the business side of Nexploit — partnerships, event logistics, and operations — so the technical team can focus on building.
Ensures the platform holds up under load when hundreds of participants hit the CTF at once.
CTO at Nexploit, handling identity, network, and endpoint security across the platform. Background in enterprise IT support and MSP/MSSP environments — from Microsoft 365 and Active Directory to endpoint monitoring with SentinelOne and Splunk.
Hands-on IT support and infrastructure roles across MSP, hospitality, and enterprise environments.
Resolving global multi-channel helpdesk tickets within SLA, administering Microsoft 365 and Entra ID/Active Directory, and managing Cisco Meraki network infrastructure — VLANs, VPNs, and firewalls — alongside endpoint security monitoring via SentinelOne and Splunk.
Delivered onsite IT support across 100+ endpoints, ran full-cycle user onboarding and OS upgrades with zero downtime, and maintained network infrastructure across Windows and MacOS environments.
Delivered onsite technical support and hardware troubleshooting, managed device provisioning and OS deployments, and ran e-procurement workflows on GeM and CPPP alongside statutory ESI/EPF compliance filings.
We're always up for a good security conversation — or a good CTF idea.
Get in touch →