Skip to content
View ChetanBiranje's full-sized avatar
๐ŸŽฏ
Focusing
๐ŸŽฏ
Focusing

Block or report ChetanBiranje

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
ChetanBiranje/README.md

Hi there, I'm Chetan Biranje ๐Ÿ‘‹

Typing SVG

๐Ÿ” About Me

Coding

  • ๐Ÿ›ก๏ธ Application Security Engineer specializing in manual penetration testing
  • ๐Ÿ› Discovered 15+ critical vulnerabilities affecting 5,000+ users
  • ๐Ÿค– Building Python automation tools for security testing
  • ๐Ÿ“š Currently pursuing BCA in Information Technology at D.Y. Patil University
  • ๐ŸŽฏ Working towards OSCP certification
  • ๐Ÿ’ก Creator of 365 Days of Application Security
  • ๐ŸŒฑ Active on TryHackMe (65% completion) & Hack The Box (6+ boxes)
  • ๐Ÿ’ฌ Ask me about OWASP Top 10, API Security, JWT vulnerabilities
  • โšก Fun fact: Electronics background โ†’ Perfect for IoT/Hardware security!


๐Ÿ› ๏ธ Technical Arsenal

๐Ÿ”’ Security Testing

๐Ÿ’ป Programming & Scripting

๐ŸŒ Web Development & APIs

โ˜๏ธ Cloud & DevSecOps


๐Ÿ“Š GitHub Statistics

GitHub Streak

๐Ÿ† Achievements & Impact

๐ŸŽฏ Achievement ๐Ÿ“Š Metric
Critical Vulnerabilities 15+ Discovered
Users Protected 5,000+
Remediation Rate 95%
Efficiency Gain 30% through automation
Security Debt Reduced 40%
TryHackMe Progress 65%
HTB Boxes Rooted 6+

๐Ÿš€ Featured Projects

Complete year-long roadmap from beginner to professional AppSec Engineer

๐Ÿ“Œ Highlights:

  • โœ… Day-by-day structured learning plan
  • โœ… 100+ free resources curated
  • โœ… OWASP Top 10 complete coverage
  • โœ… Certification guides (Security+, eJPT, OSCP)
  • โœ… Career preparation included

๐Ÿ”ง Tech Stack: Educational Content ยท Security Resources ยท Free Labs
Stars


Python-based comprehensive security testing framework for REST APIs

๐Ÿ“Œ Highlights:

  • โœ… JWT Token Analysis & Exploitation
  • โœ… IDOR Vulnerability Scanner
  • โœ… API Fuzzing Engine
  • โœ… Authentication/Authorization Testing
  • โœ… CI/CD Integration Ready

๐Ÿ”ง Tech Stack: Python ยท Burp Suite API ยท JWT ยท REST APIs
๐Ÿ“ˆ Impact: 30% reduction in manual testing time


Production-grade secure authentication system with JWT and role-based access control

๐Ÿ“Œ Highlights:

  • โœ… Secure JWT Implementation
  • โœ… Granular RBAC System
  • โœ… Comprehensive Security Headers
  • โœ… Rate Limiting & DDoS Protection
  • โœ… OWASP Best Practices

๐Ÿ”ง Tech Stack: Node.js ยท Express.js ยท MongoDB ยท JWT ยท bcrypt
๐Ÿ“ˆ Impact: 30% fewer vulnerabilities vs industry baseline


Detailed walkthroughs and methodologies from TryHackMe, Hack The Box, and VulnHub

๐Ÿ“Œ Highlights:

  • โœ… Step-by-step enumeration guides
  • โœ… Exploitation techniques documented
  • โœ… Privilege escalation methods
  • โœ… Screenshots and proof
  • โœ… Lessons learned section

๐ŸŽฎ Platforms: TryHackMe ยท HackTheBox ยท VulnHub


๐Ÿ’ผ Professional Experience

๐Ÿ” Cyber Security Analyst

Codec Technologies India | Nov 2025 - Dec 2025

  • ๐ŸŽฏ Discovered 15+ critical/high severity vulnerabilities (IDOR, broken authorization, privilege escalation, JWT misconfigurations)
  • ๐Ÿ“ˆ Achieved 95% remediation rate through clear PoC exploits and developer collaboration
  • โšก Reduced analysis time by 30% via Python automation for API fuzzing
  • ๐Ÿ›ก๏ธ Performed comprehensive authorization testing with Burp Suite Pro
  • ๐Ÿ“„ Authored professional reports with CVSS scoring

๐Ÿ’ป Full-Stack Developer

ai4sees private ltd | Dec 2025 - Present

  • ๐Ÿ—๏ธ Designed secure web architecture with OWASP controls
  • ๐Ÿ”ง Built reusable REST API libraries reducing vulnerabilities by 30%
  • ๐Ÿ”„ Integrated SAST/DAST in CI/CD, reducing security debt by 40%
  • โœ… Implemented secure coding: input validation, parameterized queries, session management
  • ๐Ÿ‘จโ€๐Ÿ’ป Conducted security code reviews focusing on OWASP Top 10

๐Ÿ Python Developer

Codec Technologies India | Nov 2025 - Dec 2025

  • ๐Ÿค– Developed security automation scripts and API testing tools
  • โฑ๏ธ Reduced manual effort by 2+ hours/week through automation utilities
  • ๐Ÿ“Š Built log parsing, data extraction, and workflow automation tools
  • ๐Ÿ” Created reusable libraries for API fuzzing and auth analysis

๐ŸŽ“ Certifications & Continuous Learning

๐Ÿ… Certification ๐Ÿข Provider ๐Ÿ“… Status
Application Security Training Various Providers โœ… Completed
Cyber Security Architecture v1 Various Providers โœ… Completed
Commonwealth Bank - Cybersecurity Simulation Forage โœ… Completed
AIG - Shields Up: Cybersecurity Forage โœ… Completed
Deloitte Australia - Cyber Simulation Forage โœ… Completed
CompTIA Security+ CompTIA ๐ŸŽฏ In Progress
eJPT eLearnSecurity ๐ŸŽฏ Preparing
OSCP Offensive Security ๐ŸŽฏ Goal 2026

๐Ÿ“š Active Learning Platforms

  • TryHackMe: 65% Junior Penetration Tester Path | 50+ rooms completed
  • Hack The Box: 6+ machines rooted | Active member
  • PortSwigger Academy: Continuous practice on all vulnerability types
  • OWASP Juice Shop, DVWA: Regular practice on intentionally vulnerable apps

๐Ÿ“ˆ Activity Graph

Activity Graph

๐Ÿ“ซ Connect With Me

LinkedIn GitHub Email Twitter

๐Ÿ“ Pune, Maharashtra, India
๐Ÿ“ง chetanchandrakantbiranje@gmail.com
๐Ÿ”— linkedin.com/in/chetanbiranje


๐Ÿ’ก Security Quote

"Security is not a product, but a process."
โ€” Bruce Schneier

"The only system which is truly secure is one which is switched off and unplugged, locked in a titanium lined safe, buried in a concrete bunker, and is surrounded by nerve gas and very highly paid armed guards. Even then, I wouldn't stake my life on it."
โ€” Gene Spafford


๐ŸŽฏ Current Focus (2026)

class ChetanBiranje:
    def __init__(self):
        self.role = "Application Security Engineer"
        self.current_focus = [
            "OSCP Certification Preparation",
            "Bug Bounty Hunting (Google VRP, HackerOne)",
            "Advanced API Security Research",
            "Security Automation with Python",
            "Contributing to Open Source Security Tools"
        ]
        self.learning = [
            "Cloud Security (AWS, Azure, GCP)",
            "Mobile Security (Android, iOS)",
            "Container Security (Docker, Kubernetes)",
            "Active Directory Security"
        ]
        self.goals_2026 = [
            "OSCP Certification โœ…",
            "Land Application Security role at FAANG",
            "Contribute to 10+ open source security projects",
            "Publish security research papers",
            "Reach 1000+ GitHub stars"
        ]
    
    def say_hi(self):
        print("Thanks for visiting! Let's make the web more secure together!")

me = ChetanBiranje()
me.say_hi()

๐ŸŒŸ Show some โค๏ธ by starring repositories you find useful!

Profile Views

GitHub followers


๐Ÿ’ช Consistency Streak: Committed to learning every single day!
๐ŸŽฏ Mission: Making the digital world safer, one vulnerability at a time!


Popular repositories Loading

  1. ChetanB ChetanB Public template

    JavaScript

  2. webapp-pentest-framework webapp-pentest-framework Public

    Python-based automated penetration testing framework for web application security assessment

  3. api-security-suite api-security-suite Public

    Specialized security testing suite for REST API vulnerability assessment and OWASP API Top 10 testing

  4. security-automation-toolkit security-automation-toolkit Public

    Collection of Python security automation scripts for penetration testing workflows

  5. CTF-Writeups CTF-Writeups Public

  6. Bug-Bounty-Scripts Bug-Bounty-Scripts Public