About

Hi! I'm Shriyans, and I do offensive security research.

I study how modern web apps leak what their developers never meant to ship, from recovering the logic hidden in compiled JavaScript to finding the secrets and flaws it exposes. That work has been published at ASE 2026. Separately, I've found vulnerabilities in industrial control software (OpenPLC), which led to CVEs and a CISA ICS advisory.

Hacking is where I started, and I still do it: pentesting, bug bounties, and competitions. I also build open-source security tooling like JS Recon. I'm a BS in Cybersecurity student at Rochester Institute of Technology.

Publications, CVEs and advisories → Research · ORCID 0009-0008-6750-6424

Hero image

Certifications

I have completed Certified API Security Analyst Certification from APISecUniversity (Covers OWASP API Top 10, common API flaws, and exploitation methods). See credentials here

Contact:

You can either email me at shriyanss@ss0x00.com or use the form below

Let’s talk... 💬