⚡Powered by ResumePortfolio.in
⚡ Recruiters are viewing this, unlock a premium theme to stand out · Upgrade →
Unlock themes →
M

Manohar Kosana

Security Researcher

Palakol, India

I am a Security Researcher with 0 years of experience at Hackerone/Bugcrowd, specializing in web infrastructure auditing and exploit development. I achieved a remarkable 76% anomaly detection accuracy with fewer false lockouts through One-Class SVM tuning, which has honed my skills in threat detection and security analysis. I am building toward a Cybersecurity Engineer role where I can leverage my foundational knowledge and passion for security to tackle complex challenges in the field.

Skills

Security OperationsAlert MonitoringThreat DetectionSecurity Event AnalysisLog AnalysisCloud & EndpointSplunkWazuhAWS SecurityIAMS3CloudTrailMicrosoft DefenderOffensive SecurityOWASP Top 10BOLA/IDORWeb EnumerationAPI SecuritySIEM & DetectionSIEM ConceptsAlert CorrelationSecurity TelemetryMITRE ATT&CKIDS MonitoringNetworking & AnalysisTCP/IPDNSFTPPacket AnalysisFirewall LogsWindows Event LogsSecurity ToolsBurp Suite ProMetasploitNmapScapyHydraNessus EssentialstcpdumpProgramming & AutomationPythonBashPowerShellSQLSecurity ScriptingLinux System

Projects

DDoS Detection & Automated Response Platform

Captured traffic using Scapy and tcpdump to detect SYN floods and unauthorized port scans. Applied Python logic to validate security events and reduce false positive alert rates in testing. Automated containment using iptables to simulate incident response and block network attacks. Visualized attack telemetry in Splunk to monitor containment status and identify threat trends.

FakeBeacon – Wireless Security Research Tool

Developed a wireless deception tool using Scapy to generate custom 802.11 frames and rogue APs. Implemented whitelist validation to prevent unauthorized rogue wireless network activity in labs. Simulated rogue beacon activity in Linux to evaluate IDS alert generation and alert monitoring. Analyzed IDS alerts during rogue AP simulation to identify gaps in threat detection mechanisms.

View Source Code

Endpoint Device Control & Monitoring System

Built a Linux access control system using udev rules to restrict unauthorized USB peripherals. Implemented whitelist validation to restrict unauthorized peripherals in lab testing environments. Forwarded udev logs to Splunk to track and visualize unauthorized USB access attempts in labs. Automated policy enforcement using Bash scripting and Linux system-level security controls.

View Source Code

Zero-Input Behavioral Biometric Authentication

Built a continuous authentication system using mouse dynamics to detect anomalous user activity. Built an Android monitoring app integrated with Flask for remote security management tasks. Optimized a One-Class SVM model to improve detection accuracy and minimize false lockouts. Captured intrusion snapshots during anomaly-triggered events to support forensic reporting.

Experience

Hackerone / Bugcrowd

Jan 2026 – Present

Evaluated BOLA flaws in production APIs to identify unauthorized manipulation of sensitive PII records. Bypassed WAF implementations using JA3 fingerprinting & request normalization to evade detection. Analyzed race conditions and business logic flaws in financial APIs to prevent critical data leakage. Performed manual fuzzing and source code audits to discover hidden vulnerabilities in web assets.

Certifications

Google Cybersecurity Certificate

ISO/IEC 27001:2022 Lead Auditor

Endpoint Security

Shell Scripting

Education

Bharath Institute of Higher Education and Research

Bachelor of Technology – Computer Science • 2022 – 2026

8.2/10.0

Publications & Research

Behavior Based Continuous Authentication and Remote Security Management System

Journal Volume 12, Issue 11

Engineered a continuous authentication system using mouse dynamics to detect anomalous activity. Integrated a real-time Android monitoring app with a Flask backend for remote security management. Applied One-Class SVM tuning, achieving 76% anomaly detection accuracy with fewer false lockouts. Captured forensic snapshots during anomaly-triggered lock events to support incident reporting.

Get in Touch

Interested in collaboration or just want to say hello? Feel free to reach out!

✨ Stand out to recruiters: unlock all themes + remove branding · ₹49Upgrade Plan →