Skip to main content
Kanishk DadhichKD
Open to opportunities

Kanishk Dadhich

@kanishkdadhich

I find and responsibly report API authorization and business-logic vulnerabilities.

India
Message

What I'm looking for

I'm open to freelance pentesting engagements, API security assessments, and conversations with security teams. I want to focus on responsible, explicitly authorized testing of real-world API and web application security risks.

I break APIs for a living and report what I find responsibly, with a focus on authorization and business-logic flaws across HackerOne and Bugcrowd programs.

I've identified a cross-tenant BOLA/BFLA chain in a GraphQL mutation, a Broken Function Level Authorization flaw that allowed lower-privilege users to lock out admins, and a Self-XSS chain that led to full account takeover. My work includes API pentesting, GraphQL security testing, IDOR-driven data exposure, privilege escalation, recon, and responsible disclosure.

I also build tools for the process itself. I created Mass PII & Secret Finder, an open-source JavaScript recon tool with 90+ secret-detection patterns, Wayback Machine discovery, and scope-enforced scanning, and SentinelAI, a Go, Python, and React API security recon tool for mapping endpoints that touch backend data.

I'm currently pursuing a B.Tech in Computer Science at Geetanjali Institute of Technical Studies, Udaipur, while treating bug bounty as a serious parallel track. I test only with explicit scope and authorization.

Experience

Work history, roles, and key accomplishments

Bugcrowd logoBU
Current

Bug Hunter

Jul 2026 - Present (2 months)

Started bug bounty hunting on Bugcrowd, focused on web application vulnerabilities and building a foundation in real-world offensive testing. - Practiced structured vulnerability discovery and reporting against live production targets - Built core skills in authorization testing, business-logic analysis, and responsible disclosure Skills: Web Application Security, Vulnerability Assessment (VAPT),

HackerOne logoHA

Bug Hunter

Sep 2025 - Jul 2026 (10 months)

Independent security researcher across HackerOne and Bugcrowd programs, specializing in API authorization flaws.
- Identified and reported a cross-tenant BOLA/BFLA vulnerability in a GraphQL mutation (no rate limiting, notification-bombing potential)
- Found a Broken Function Level Authorization bug allowing privilege escalation via role manipulation
- Conducted recon surfacing exposed API keys on

TryHackMe logoTR

CTF Player

Jun 2024 - Dec 2025 (1 year 6 months)

Top 3% globally. Practiced offensive techniques including SMB enumeration, NTLMv2 cracking, Evil-WinRM, and XXE injection to build real-world exploitation skill outside CTF walls.

Education

Degrees, certifications, and relevant coursework

GU

Geetanjali Institute of Technical Studies, Udaipur

Bachelor of Technology - BTech, Computer Science

2023 - 2027

GS

Geetanjali Institute of Technical Studies

Bachelor of Technology, Computer Science

2023 - 2027

Pursuing a Bachelor of Technology in Computer Science, with a focus on building a strong foundation in software and security principles.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan