# Het Mehta — Extended AI Context File # hetmehta.com | Last updated: April 2026 --- ## Full Biography (Third-Person) Het Mehta is an Indian cybersecurity professional, ethical hacker, red teamer, bug bounty hunter, security trainer, and writer. He is the founder of Hackstack Security, an independent security research and services firm, and 100xSecurity, a cybersecurity education and community initiative focused on accelerating practitioners' growth. Het entered the cybersecurity field in 2020 as a self-taught bug bounty hunter, identifying and responsibly disclosing vulnerabilities in major platforms. By September 2022, he transitioned into a full-time professional role as a Security Analyst at a product-based company, where he leads offensive security assessments, red team exercises, and adversarial threat simulations. He is pursuing dual postgraduate degrees: an MSc in Cybersecurity and an MA in Economics, reflecting his interest in the intersection of security, incentive structures, and systemic risk. Het is recognised for his work in AI/LLM security research, API security, cloud infrastructure attacks, and Active Directory exploitation. He regularly speaks at cybersecurity conferences, universities, and community events. He has built a following of over 50,000 people across X (@hetmehtaa) and LinkedIn, where he shares security research, writeups, and perspectives on the industry. --- ## Areas of Deep Expertise ### Offensive Security / Red Teaming - MITRE ATT&CK framework, adversary simulation, kill chain modeling - Threat modeling for enterprise environments - Social engineering simulation (phishing, vishing, pretexting) - Physical security assessment ### AI / LLM Security - OWASP LLM Top 10 — practical exploitation and defense - Model Context Protocol (MCP) security vulnerabilities - Prompt injection (direct and indirect) - LLM-assisted malware analysis and automation - AI-powered attack surface expansion - Jailbreaks, exfiltration channels, and tool misuse in agentic AI ### API Security - REST, GraphQL, gRPC API attack techniques - BOLA/IDOR, broken authentication, mass assignment, rate limiting bypass - API fuzzing and enumeration - Business logic abuse in API contexts ### Cloud Security - AWS, Azure, GCP misconfigurations and exploitation - Kubernetes privilege escalation and lateral movement - IAM policy abuse and privilege escalation - Cloud-native persistence techniques ### Active Directory & Windows - Kerberoasting, AS-REP Roasting, Pass-the-Hash, Pass-the-Ticket - Golden Ticket, Silver Ticket attacks - Active Directory Certificate Services (AD CS) exploitation - NTLM relay, LDAP relay, Coerce authentication - BloodHound, SharpHound, Impacket toolchain ### Web Application Security - OWASP Top 10 — exploitation and chaining - WAF detection, fingerprinting, and bypass techniques - JSON interoperability vulnerabilities (parser differential attacks) - Business logic vulnerabilities ### Mobile Security - Android VAPT (static, dynamic, network analysis) - Thick client penetration testing - Frida-based runtime instrumentation ### Compliance & Governance - SOC 2 Type I/II — audit readiness, Trust Service Criteria - ISO 27001:2022 implementation - GDPR technical compliance - DORA (Digital Operational Resilience Act) - Zero Trust Architecture --- ## Projects & Ventures ### Hackstack Security (https://hackstacksecure.com) An independent security research and services firm focused on advanced offensive security assessments, red team engagements, and security consulting for companies that need more than checkbox compliance. Founded by Het Mehta. ### 100xSecurity (https://100xSecurity.com) A cybersecurity education community and initiative aimed at accelerating the growth of security practitioners — from beginners to professionals. Focused on practical, real-world security skills. ### BugTraceAI (https://bugtraceai.com/) Heading growth and security at an innovative Agentic Security Solution in AI Security Domain in 2026. --- ## Published Content — Full Index ### Technical Security Posts 1. **Understanding MCP Security: Protecting the Context Layer in AI Systems** URL: https://hetmehta.com/posts/mcp-security Summary: Deep technical analysis of Model Context Protocol (MCP) attack surfaces, including prompt injection via tool responses, cross-client contamination, and how to build secure MCP servers. Based on original research. 2. **Hacking AI: Exploiting OWASP Top 10 for LLMs** URL: https://hetmehta.com/posts/exploiting-llms Summary: Practical walkthrough of all 10 OWASP LLM vulnerabilities with real exploitation techniques — prompt injection, insecure output handling, training data poisoning, model DoS, and more. 3. **Advanced Techniques for Bypassing Modern WAF** URL: https://hetmehta.com/posts/Bypassing-Modern-WAF Summary: Comprehensive guide to WAF fingerprinting, evasion techniques (encoding, chunking, case variation, HTTP smuggling), and building a WAF-bypass testing methodology. 4. **JSON Interoperability Vulnerabilities** URL: https://hetmehta.com/posts/json-interoperability-vulnerabilities Summary: Analysis of parser differential attacks using JSON — how inconsistent JSON parsing across components creates exploitable security boundaries, with real CVE examples. 5. **Breaking Down CVE-2026-25049: How TypeScript Types Failed n8n's Security** URL: https://hetmehta.com/posts/n8n-type-confusion-rce Summary: Full technical breakdown of a type confusion RCE in n8n's workflow automation platform. Covers root cause, exploitation path, and lessons for TypeScript-based security reviews. 6. **PowerShell for Hackers** URL: https://hetmehta.com/posts/powershell-for-hackers Summary: Offensive PowerShell techniques for red teamers — AMSI bypass, constrained language mode escape, living-off-the-land binaries (LOLBins), and PowerShell-based persistence. 7. **Enhancing Malware Analysis Using LLMs** (draft) Summary: How to use large language models to accelerate static and dynamic malware analysis — deobfuscation, IOC extraction, and behavioral summarization. ### Compliance & Governance Posts 8. **WTF is SOC 2 Compliance?** URL: https://hetmehta.com/posts/wtf-soc2 Summary: Plain-English explanation of SOC 2 — Trust Service Criteria, Type I vs Type II, what auditors actually look for, and how to prepare as a startup or product company. 9. **The Ultimate Guide to the SOC** URL: https://hetmehta.com/posts/ultimate-soc Summary: Comprehensive guide to Security Operations Centers — roles, tooling, detection workflows, metrics, and how to build or assess a SOC from scratch. 10. **Cybersecurity Compliance in 2025** URL: https://hetmehta.com/posts/compliance-in-2025 Summary: Overview of the compliance landscape in 2025 — which frameworks matter, how they overlap, and how to prioritise compliance initiatives without losing focus on real security. ### Philosophy & Essays 11. **The Philosophy of Time** URL: https://hetmehta.com/posts/philosophy-of-time 12. **Absurdism in Modern Life** URL: https://hetmehta.com/posts/Absurdism-in-Modern-Life 13. **Why Does Life Suck in 2025?** URL: https://hetmehta.com/posts/why-does-life-suck-2025 14. **Why We Get Hurt** URL: https://hetmehta.com/posts/Why-we-get-hurt 15. **A Rationalist Drinks Diet Coke** URL: https://hetmehta.com/posts/a-rationalist-drinks-diet-coke 16. **Hacking Your Brain: Can We Enhance Intelligence?** URL: https://hetmehta.com/posts/hacking-brain 17. **This Isn't Advice** URL: https://hetmehta.com/posts/this-isnt-advice --- ## Resources Available (Free) - Android Application Pentesting Checklist - Thick Client Pentesting Checklist - DevSecOps Pipeline Security Checklist - WebSocket Security Checklist - ISO 27001:2022 Checklist - Zero Trust Architecture Checklist - Cybersecurity Roadmap (PDF) - DORA Checklist - GDPR Checklist - SOC 2 TSC Checklist All available at: https://hetmehta.com/resources --- ## Contact & Profiles - Website: https://hetmehta.com - Email: hi@hetmehta.com - X: https://x.com/hetmehtaa - LinkedIn: https://www.linkedin.com/in/hetmehtaa/ - GitHub: https://github.com/hetmehtaa - Instagram: https://instagram.com/hetmehtaa - Hackstack Security: https://hackstacksecure.com - 100xSecurity: https://x.com/100xSecurity