Mahesh Udaykar
Security · Automation2024-PresentOngoing

Vulnara

AI-Guided Security Audit Automation Platform

Vulnara

Overview

An engineered local-first, extensible security audit platform for automated validation of web applications, APIs, and software packages. Vulnara features a multi-module testing engine that integrates static analysis (Semgrep, Bandit), dynamic testing (OWASP ZAP, Nuclei), and dependency scanning (pip-audit, npm audit) into a unified pipeline. An AI orchestration layer utilizing local LLMs (Mistral, DeepSeek-Coder via Ollama) automates test strategy generation, payload creation, and vulnerability reasoning, producing exportable, actionable security reports.

"Vulnara bridges the gap between automated scanning and intelligent analysis by integrating local LLMs to reason about vulnerabilities directly within the testing pipeline."

Key Metrics

5+

Security Engines

Local LLMs

AI Integration

Unified

Pipeline Stage

Technologies

SemgrepBanditOWASP ZAPNucleiOllamaMistralDeepSeek-Coderpip-auditPython

Key Features

🔗

Unified Testing Pipeline

Seamlessly integrates SAST, DAST, and SCA tools into a single, repeatable, and structured assessment workflow.

🤖

AI Orchestration Layer

Uses local LLMs (Ollama) to autonomously generate test strategies, craft payloads, and reason about discovered vulnerabilities.

📄

Structured Reporting

Generates comprehensive, exportable security assessment reports focusing on actionable remediation insights.

Open to Opportunities

Available for remote, hybrid, and on-site roles in security analysis, SOC, and systems engineering.

maheshudaykar11@gmail.com

Security-first mindset, systems-level execution.

Final-year engineering student with practical experience in VAPT, phishing detection, automation tooling, and embedded control systems. Open for internships and full-time opportunities.

Let's Connect

Open to internships, full-time roles, and project collaboration in security and systems.

Currently available

Open to internships, graduate roles, and freelance security or systems projects.