- 🛡️ 90+ security vulnerabilities reported across 30+ enterprise bug bounty programs
- 🏆 Hall of Fame: Apple Security · Google VRP · Microsoft MSRC
- ☁️ AWS Cloud Security — IAM auditing, GuardDuty, CloudTrail, Security Hub
- 🔴 Offensive Security — IDOR, SSRF, Auth Bypass, API Security, Mobile Pentesting
- 🎓 Bachelor of Computer Applications (BCA) — Tribhuvan University · 2023–2027
- 🌍 Identity: pwn4arn / manieshneupane · Based in Nepal
- Web Application Penetration Testing (OWASP Top 10)
- Broken Access Control · IDOR · Business Logic Flaws
- SSRF · Authentication Bypass · Session Management
- API & GraphQL Security Testing
- Android APK Static & Runtime Analysis (JADX · Genymotion)
- IAM Policy Auditing · Least Privilege Enforcement
- Privilege Escalation Path Analysis (
iam:PassRole·sts:AssumeRole) - CloudTrail Log Analysis · Root Account Monitoring
- Amazon GuardDuty Threat Detection
- AWS Security Hub · Foundational Security Best Practices
- S3 Bucket Security Auditing · Encryption & Access Controls
- MITRE ATT&CK Cloud Technique Mapping
"I find the vulnerabilities that automated scanners miss."



