Available for research & senior offensive-security roles Offensive Security · AI Automation

Sachin Sharma

Offensive Security Engineer — Red Team & AI Security Automation

Six years red-teaming Fortune 500 networks, now building LLM-powered autonomous agents that scale reconnaissance, vulnerability discovery, and reporting. Creator of two open-source AI-security frameworks adopted by red teamers and bug-bounty hunters worldwide.

5,500+ GitHub stars 830+ forks Used by red teamers worldwide
SS
Sachin Sharma elementalsouls
0
Years red teaming
0
GitHub stars shipped
0
Exposed creds neutralized
operator@elementalsouls
# whoami
role   Offensive Security Engineer
focus AI-driven vuln discovery
certs OSCP, CRTO
ships
Profile

I sit at the intersection of offensive security and applied AI — an OSCP/CRTO red teamer who now designs the LLM agents that automate the work. Across roles at Grant Thornton and EY I've led red team operations for Fortune 500 clients, cut manual tradecraft by more than half with GenAI-driven workflows, and open-sourced the tooling behind it — now trusted by thousands of security practitioners on GitHub. I bring the same builder's instinct to any team investing in autonomous, AI-driven security.

01 — Open-source research

AI-security frameworks I build & ship.

Autonomous agent tooling that turns LLM assistants into full recon-to-report operators — adopted globally within months of release.

3,300+

Claude-BugHunter

Creator & Lead Developer

An AI agent skill framework that turns LLM coding assistants into autonomous bug-hunting & red-team operators.

Its evidence base curates 681 disclosed-vulnerability patterns from real HackerOne & Bugcrowd reports, driving a repeatable six-phase recon-to-report workflow that runs across Claude Code, Codex & OpenCode.

Research angleCan LLM agents reliably triage real vulnerability classes end-to-end — where do they succeed, and where do they silently fail?

82 security skills 15 workflow commands 24 vuln classes 460+ forks Burp · MCP · ProjectDiscovery
2,200+

Claude-OSINT

Creator & Lead Developer

A paired AI recon framework — 5,500+ lines of structured tradecraft turning LLMs into external reconnaissance operators.

Automates identity/SSO mapping (Entra, M365, Okta, ADFS), cloud & Kubernetes exposure discovery, and email-security auditing (SPF/DMARC/DKIM) — with sector packs for healthcare, finance, ICS/SCADA & government.

Research angleHow far can autonomous agents map an organization's external attack surface from open-source signal alone — and how noisy is that signal?

90+ recon modules 48 secret regexes 80+ search dorks 27 attack-path templates 372+ forks
02 — Where I'm headed

Research interests.

I want to study the systems I've been building by instinct: how autonomous offensive agents actually behave, where they break, and how to make them measurable and safe. Four threads I'd bring to a lab:

Autonomous LLM agents for vuln discovery and Attack Surface Management

Scaling recon-to-report pipelines with tool-calling agents — planning, orchestration, and reliability under real targets.

Adversarial ML & LLM red-teaming

Prompt injection, agent memory/RAG poisoning, and jailbreak strategy discovery from the attacker's seat.

AI-driven threat intelligence

Turning noisy open-source and dark-web signal into predictive, operational threat models.

Guardrails & agent security

Measuring and containing what autonomous offensive agents can actually do.

# Seeking a Graduate Research Assistantship, Fall 2027 —
# moving from enterprise consulting into rigorous research.

03 — Track record

Experience.

Aug 2024 — Present
Assistant Manager — Red Team & Offensive Security
Grant Thornton LLP · Gurgaon, India
  • Led internal & external red team operations for Fortune 500 clients, mapping critical attack paths across Active Directory, cloud & endpoint — reducing exploitable attack surface ~50%.
  • Pioneered GenAI-driven offensive workflows — LLM automation and custom AI skills into recon, reporting & dark-web monitoring — cutting manual tradecraft 50–60%.
  • Automated a dark-web monitoring program with N8N that surfaced 50,000+ exposed credentials before exploitation.
  • Engineered custom Windows tooling & PowerShell automation; ran phishing simulations that lifted employee reporting by 90%.
  • Simulated APT scenarios mapped to MITRE ATT&CK; sustained a 95% client satisfaction rate.
Aug 2021 — Mar 2023
Associate Consultant — Cyber Threat & Vulnerability Mgmt
Ernst & Young (EY) LLP · Mumbai, India
  • Executed 15+ red team & 40+ application-security engagements across BFSI, healthcare & energy verticals, uncovering critical and zero-day flaws.
  • Delivered Cyber Threat Intelligence reports that cut mean incident-response time by 25%.
  • Led web app & Active Directory pentests — lateral movement, privilege escalation, auth flaws — and reviewed firewall/network configs against ISO 27001 & CIS.
Sep 2020 — Jul 2021
Security Analyst
Indian Cyber Institute · Mumbai, India
  • Ran VAPT across web, infrastructure & endpoint systems for small & mid-sized enterprises.
  • Delivered prioritized remediation that measurably improved posture for resource-constrained clients.
04 — Recent activity

News.

2026

Seeking a Graduate Research Assistantship for Fall 2027 — reaching out to research groups working on autonomous AI security and adversarial ML.

2025

Claude-BugHunter crossed 3,300★ and Claude-OSINT 2,200★ — combined 5,500+ stars and 830+ forks from the security community.

2025

Awarded a Spot Award at Grant Thornton for AI-powered offensive tooling and the N8N dark-web monitoring program.

2024

Released Claude-BugHunter & Claude-OSINT — open-source AI-security frameworks now adopted by red teamers and bug-bounty hunters worldwide.

05 — Toolkit

Skills & expertise.

From LLM agent engineering to Active Directory attack paths.

AI & Security Automation

LLM Offensive ToolingAI Agent SkillsClaude CodeGenAI AutomationPrompt EngineeringAI Recon & Bug HuntingN8N

Offensive Security

Red TeamingAdversary SimulationBASWeb / API PentestActive DirectoryExploit DevOSINTPurple Teaming

Cloud & Infrastructure

AzureAWSKubernetesConfig ReviewEndpoint HardeningThreat ModelingSecure Code Review

Tooling

MetasploitSliverBloodHoundBurp SuiteNessusImpacketNmapProjectDiscovery

Frameworks & Standards

MITRE ATT&CKCyber Kill ChainOWASP Top 10NISTZero TrustISO 27001CIS

Programming

PythonBashPowerShellJavaScript
OSCPOffensive Security Certified Professional
CRTOCertified Red Team Operator
HTB · TCMRasta Labs · Pivoting · Windows PrivEsc
B.Tech, ITABES Engineering College · 2020
06 — Recognition

Awards.

2024 & 2025

Spot Award

Grant Thornton — for driving AI-powered tooling & N8N dark-web monitoring initiatives and sustained client success.

2022 & 2023

"I am Exceptional"

Ernst & Young — for delivering high-impact red team projects across multiple Fortune 500 clients.

Ongoing

5,500+ GitHub Stars

Community adoption of Claude-BugHunter & Claude-OSINT by red teamers and bug-bounty hunters worldwide.

07 — Let's talk

Building at the AI × security edge?

Open to senior offensive-security roles, research collaborations, and graduate research assistantships — and always up for a conversation about autonomous red teaming.