Skip to content
View manthanghasadiya's full-sized avatar
🎯
Focusing
🎯
Focusing

Organizations

@sys-adm1ns

Block or report manthanghasadiya

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
manthanghasadiya/README.md

Typing SVG

👤 HUNTER PROFILE

Name: Manthan Ghasadiya
Class: Offensive Security Engineer / AI Security Researcher
Rank: S-Class (TryHackMe Top 1% Global)
Guild: Jacobian Engineering | Syracuse University (MS Cybersecurity, 3.84 GPA)
Specialization: Red Team Ops, AI/LLM & MCP Security, Vulnerability Research
Shadow Soldiers Deployed: 8-VM Red Team Lab (Proxmox)
Confirmed Kills: 4 published CVEs (up to CVSS 9.8) + 15 reported MCP vulns

Coding

⚔️ ACTIVE QUESTS

  • 🗡️ Main Quest: Security Analyst @ Jacobian Engineering (web / mobile / cloud / API pentesting)
  • 🔮 Special Ability: AI/LLM & MCP security research and exploitation
  • ⚡ Power Level: Building offensive security tooling and automated testing frameworks
  • 🛡️ Domain: manthanghasadiya.me
  • 📚 Side Quests: GeeksNeuron (3.2K+) · HackyNerdz

🩸 CONFIRMED KILLS - PUBLISHED CVEs

Real, verifiable vulnerability research. Full technical writeups, root-cause analysis, and PoCs in my CVE writeups repo.

CVE Target Severity Class
CVE-2026-6942 radare2-mcp 9.8 CRITICAL RCE via shell escape
CVE-2026-42449 n8n-mcp 8.5 HIGH SSRF via IPv6 bypass
CVE-2026-35394 mobile-mcp 8.3 HIGH Prompt injection → Android intent
CVE-2026-47427 github-mcp-server 7.5 HIGH Nil-pointer DoS (pre-auth)

Plus 15+ reported vulnerabilities across MCP SDKs and servers, with fixes merged upstream into Anthropic's official MCP Python SDK, TypeScript SDK, and servers.

🛠️ SIGNATURE WEAPON - mcpsec

mcpsec · pip install mcpsec · 10K+ PyPI downloads

The first open-source security scanner for live MCP servers. Sends real exploit payloads and confirms exploitation instead of guessing.

  • scan - runtime exploitation against live servers
  • fuzz - protocol fuzzing (600+ cases) for crash discovery
  • audit - static analysis (149 Semgrep rules + tree-sitter AST) Every CVE above was found with it. Full list of discovered issues (with upstream links) is in the mcpsec README.

🗡️ SHADOW MONARCH'S ARSENAL

🔴 OFFENSIVE WEAPONS

⚔️ Primary Arsenal

Kali Linux Metasploit Burp Suite Wireshark Qualys Nmap Mimikatz Bloodhound Impacket

🛡️ Defensive Intelligence

Wazuh ELK Stack

☁️ Cloud Dominion

AWS Proxmox Docker Kubernetes

🤖 AI Shadow Soldiers

OpenAI LangChain TensorFlow n8n

🔬 Reverse Engineering Magic

IDA Pro Ghidra Radare2

📊 HUNTER STATISTICS

This Month Visitors

loading...

🏆 ACHIEVEMENTS UNLOCKED

🎯 Achievement 📊 Result
Published CVEs 4 (up to CVSS 9.8)
National Cyber League 77th / 8500
TryHackMe Global Top 1%
CNY Hackathon 2025 🥇 1st CTF · 🥉 3rd overall
NCAE CyberGames 🥈 2nd + MVP
Graylog SIEM CTF (BSidesROC) 🥈 2nd
sys_adm1ns CTF Team 30th USA / 373 global
Red Team Homelab 8-VM Proxmox (active)

💀 "𝐈𝐍 𝐓𝐇𝐄 𝐖𝐎𝐑𝐋𝐃 𝐎𝐅 𝐂𝐘𝐁𝐄𝐑𝐒𝐄𝐂𝐔𝐑𝐈𝐓𝐘, 𝐘𝐎𝐔 𝐀𝐑𝐄 𝐄𝐈𝐓𝐇𝐄𝐑 𝐓𝐇𝐄 𝐇𝐔𝐍𝐓𝐄𝐑 𝐎𝐑 𝐓𝐇𝐄 𝐏𝐑𝐄𝐘" 💀

Profile Views

Pinned Loading

  1. mcpsec mcpsec Public

    An AI-driven dynamic protocol fuzzer for the Model Context Protocol (MCP). Prove runtime exploitability by discovering state violations, transport crashes, and application-layer logic flaws (SSRF, …

    Python 27 3

  2. senshi senshi Public

    Python 1 1

  3. ghostmove ghostmove Public

    Zero-Dependency Cursor Manipulation for Red Team Operations

    Python 1

  4. Dir_Intruder Dir_Intruder Public

    Python 2 1

  5. Network-Scanner Network-Scanner Public

    This is a network scanner tool.

    Python 1

  6. writeups writeups Public

    JavaScript 1