amansploit@sec:~$
AVAILABLE FOR ENGAGEMENTS — Q3 2026

  

I'm Aman Sonkamble — a security engineer and full-stack developer. I penetration-test web apps and APIs, build security automation that catches real incidents, and build software that assumes it will be attacked.

CEH MasterCompTIA Security+Certified Network DefenderECSS
// SERVICES

Hire the person who attacks systems to build yours.

Four ways to engage. Every one ends with a deliverable you can act on — not a slide deck of vague advice.

01

Web & API Penetration Testing

Full-scope offensive assessment of your web apps, REST APIs, and infrastructure — OWASP Top 10 and beyond: IDOR, auth/session flaws, injection, misconfigurations.

  • Report-grade findings with reproduction steps
  • Severity-ranked remediation guidance
  • Free retest & verification round
02

Security Automation & SIEM Tooling

Custom monitoring and detection engineering: log-pipeline health monitors, alert automation, dark-web exposure monitoring — the tooling that catches incidents before your clients do.

  • Production Python tooling, documented
  • Severity-classified alerting & reporting
  • Least-privilege access design
03

Secure Full-Stack Development

Web applications built security-first: Next.js/TypeScript + Supabase/PostgreSQL with server-side authorization, Row Level Security, secret scanning in CI, and hardened deployments.

  • Security-reviewed, production-ready code
  • CI/CD with secret scanning (Gitleaks)
  • Threat-modeled architecture
04

AI / ML Engineering

Applied machine learning with a security bent: malware classification, sequence models, embeddings, anomaly detection — built, evaluated, and shipped with honest metrics.

  • Trained & evaluated models (AUC, CM)
  • Clean data pipelines
  • Deployment-ready inference
// SELECTED WORK

Proof, not promises.

SOC AUTOMATION

SIEM Log-Source Monitor

PythonREST APIsSIEMCloudflare AccessSMTP

ProblemAn MSSP's client log feeds were failing silently — dead log sources went unnoticed for days, discovered only mid-investigation.

BuiltPython platform verifying hourly, per client, that every SIEM log source is alive: REST API interrogation, sliding-window volume analysis, severity classification, and emailed HTML/Excel reports. Least-privilege service accounts with Cloudflare Zero Trust reachability.

ResultDetection cut from days to under one hour. First pilot caught a live Domain Controller feed outage (26,548 msgs/hr → 0) the same day it happened.

THREAT INTELLIGENCE

dwcollector — Dark-Web Exposure Monitor

PythonasyncioTorSQLitesimhash

ProblemCommercial dark-web monitoring platforms cost six figures and hold your watchlist data. Clients wanted the capability — self-hosted, evidence-only.

Built24/7 async Tor crawler with a clone-detection trust model: simhash fingerprinting, union-find clustering, PGP/allowlist trust anchoring. Five matching modes, checksum-validated PII detectors, secrets masked at capture. Full analyst triage layer with findings, dispositions, and cases.

ResultLive infrastructure crawling thousands of onion URLs — a phishing mirror can never be mistaken for a real marketplace, and leaked secrets are never stored.

SECURE SDLC

ACS FRAT — Flight Risk Assessment Platform

Next.jsTypeScriptSupabaseGitHub ActionsGitleaks

ProblemAn aviation team needed pre-flight risk assessment digitized — where a tampered score could mean a wrong GO decision.

BuiltSecurity lead on a Next.js/Supabase platform: server-calculated GO/Caution/NO-GO decisions, role-separated access control, server-side validation against score manipulation, Row Level Security, Git-history secret audits, and Gitleaks CI scanning.

ResultA production safety platform where the risk decision cannot be forged from the client side — and no secret or crew record ever entered source control.

APPLIED ML

Dynamic Malware Detection

PythonWord2VecBiGRUAttentionSMOTE

ProblemStatic signatures miss novel malware. Behavior doesn't lie — but API-call sequences need real sequence modeling.

BuiltEnd-to-end pipeline: sandboxed execution, API-call sequence logging, Word2Vec/API2Vec embeddings, and a Bidirectional GRU with attention. SMOTE for class imbalance; evaluated on accuracy, AUC, and confusion matrix.

ResultA working behavioral classifier separating malicious from benign executions — the AI capability, proven on a security problem.

// HOW IT WORKS

A clear engagement. No surprises.

01

Scope

A short call. We define targets, rules of engagement, and what success looks like. You get a fixed quote — no surprises.

02

Execute

The work happens: testing, building, or both. You get progress updates in plain language, not jargon.

03

Report

Findings with reproduction steps and prioritized fixes — or shipped code with documentation. Deliverables you can hand to your team as-is.

04

Verify

I retest what you fixed, free. The engagement ends when the risk is actually gone, not when the invoice is sent.

// ABOUT

The person you actually want on a hard problem.

Most security freelancers either break things or build them. I do both — which means when I test your app, I understand the code underneath it, and when I build your app, I already know how it gets attacked.

I work with startups, MSSPs, and product teams who want senior-grade work without a senior-grade headcount. Clear scope, honest reporting, and deliverables your team can use the day I hand them over.

aman@sec: ~
 
Aman Sonkamble — Security Analyst by day, freelance builder always.
 
offensive security · security automation · secure full-stack · applied AI/ML
 
Building multi-client SOC tooling. Top 1% on TryHackMe. On the AWS
cloud-security track. Shipping software that assumes it will be attacked.
 
Certs open doors. Evidence gets you hired. Everything I claim, I can show.
 
// START A PROJECT

Got something that needs to be built or broken?

Tell me what you're working on. I reply within 24 hours with honest scope and a fixed quote — no sales calls, no fluff.

Pune, India · Remote worldwide