Skip to content
View lucky-om's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report lucky-om

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
lucky-om/README.md

💀 Luckyyy 🔐

📍 India  ·  🎯 Focusing  ·  🟢 Open to Bug Bounty, Pentesting Gigs & Freelance Web Dev


🧠 About

name: Lucky (Om)
role: BCA (Cyber Security) Student
tagline: "Hey! Lucky here!!! Welcome to my universe!"
focus: Offensive Security / Penetration Testing
learning: Real-world labs + CTFs + Bug Bounty
goal: Break systems ethically, build clean code, ship real tools

  • 🔭 Currently building WebFox into a full recon-to-report pipeline (subdomain enum → port/service scan → tech fingerprint → CVE match → auto-report)
  • 🧪 Running a purple-team lab with Wazuh SIEM against a vulnerable target app
  • 🎯 Career track: Offensive Security / Pentester, alongside bug bounty & freelance web dev
  • 🎮 Beyond the terminal: gaming, space/sci-fi, and travel

🏆 Trophies

🥇 Achievements

Quickdraw Pull Shark Pair Extraordinaire


🧨 Findings & Responsible Disclosure

Target VNSGU Website
Vulnerability IDOR — Insecure Direct Object Reference
Impact Unauthorized access to restricted user data

⚔️ Arsenal

Web: XSS SQL Injection IDOR Recon: OSINT Subdomains DNS Tools: Burp Suite Nmap SQLmap Metasploit Hydra John the Ripper Wireshark Defense: Log Analysis SIEM Basics (Wazuh) Traffic Analysis Systems: Kali Linux Networking


📚 Currently Learning

  • 🎯 Advanced Red Teaming & Purple Team operations
  • 🛡️ SIEM workflows with Wazuh (detection + log correlation)
  • 🐛 Bug bounty methodology & vulnerability report writing
  • 🤖 AI/ML fundamentals

🛠️ Featured Projects

Project What it does
🦊 WebFox Python recon tool — subdomain enum, port scanning, URL extraction from JS/robots.txt via CLI
👻 NetPhantom Real-time packet sniffer & analyzer with deep packet inspection through a clean GUI
🎣 PhishGuard Threat-intel engine (React 19 + Python) using heuristics to catch suspicious URLs & homograph attacks
🌐 Spherewalk Immersive virtual walkthrough platform — built for SCET Surat's SCETATHON 2026
🔊 SoundLux Premium audio e-commerce UI with dark-mode glassmorphism — built for INFERNO'26: HACKOVERFLOW
📞 NUM-OSINT Web app + CLI gathering public OSINT on mobile numbers — carrier, geo hints, linked profiles

All original tools are proprietary — All Rights Reserved by Lucky.


🧪 Practice Grounds


📊 GitHub Stats


🐍 Contribution Snake


💬 Quotes

💀 Security is just a myth 💀 It's not about hacking fast, it's about thinking deeper 💀 I break systems, not hearts


🔗 Connect

Pinned Loading

  1. PhishGuard PhishGuard Public

    PhishGuard is a cybersecurity awareness platform and threat intelligence engine. Built with React 19 and Python, it leverages heuristic-based algorithms to analyze suspicious URLs, detect homograph…

    JavaScript 1

  2. NetPhantom NetPhantom Public

    NetPhantom is a modern network packet sniffer and analyzer that provides real-time traffic visibility, protocol insights, and deep packet analysis through a clean GUI interface.

    Python 1 1

  3. WebFox WebFox Public

    Webfox is a lightweight Python reconnaissance tool that automates subdomain enumeration, intelligent port scanning, URL crawling and extraction from JavaScript/robots.txt, offering a CLI for script…

    Python 5 1

  4. Spherewalk Spherewalk Public

    SphereWalk is a high-end, immersive virtual walkthrough solution built for Sarvajanik College of Engineering & Technology (SCET), Surat. Developed for SCETATHON 2026, this platform solves the probl…

    JavaScript 4

  5. SoundLux SoundLux Public

    SoundLux is a premium, high-performance audio e-commerce platform built for the INFERNO'26: HACKOVERFLOW hackathon. It features a modern dark-mode UI with glassmorphism, real-time product synchroni…

    JavaScript 3

  6. NUM-OSINT NUM-OSINT Public

    NUM-OSINT — a lightweight web app and CLI that gathers publicly available OSINT for mobile numbers (carrier, geo hints, linked profiles, and public mentions).

    HTML 2