LAT 28.6139°N
LON 77.2090°E
NODE fa1c0n.xyz

fa1c0n

india · apac
Role
security researcher
Discipline
internet recon

I scan the internet for things people forgot were public — exposed APIs, leaking source maps, open inference endpoints, misconfigured infra — and write up what I find.

Currently focused on India's attack surface and on building tooling that uses AI as a reasoning layer, not a scanner.

scope · activerange /0tgt: in.surfacerev 04
Now · reconSweeping public OpenAPI / Swagger exposure across India · APAC ranges.
Now · pipelineWhen maps leak: rebuild clients, trace generated API calls, flag bulk-style routes.
Now · labAI-Hack-OS — clustering recon output so prioritisation isn't guesswork.
Now · complianceMapping findings into DPDP · ISO 27001 language for accountable disclosure.
Now · reviewTracing trust boundaries — bulk access & IDOR-class paths get a human pass.

Now · reconSweeping public OpenAPI / Swagger exposure across India · APAC ranges.

Now · pipelineWhen maps leak: rebuild clients, trace generated API calls, flag bulk-style routes.

Now · labAI-Hack-OS — clustering recon output so prioritisation isn't guesswork.

Now · complianceMapping findings into DPDP · ISO 27001 language for accountable disclosure.

Now · reviewTracing trust boundaries — bulk access & IDOR-class paths get a human pass.

/01

Research briefs

— published write-ups
/02

Dossier

— operator file · classified // open-source
FILEOPERATOR · fa1c0n// rev 04
FILE-001fa1c0n — operator portrait
Codename
fa1c0n

// brief

Independent security researcher focused on India and internet-scale reconnaissance, exposure analysis, scanning, building tooling, and publishing what surfaces.

My research targets India's digital attack surface — enormous, fast-growing, largely understudied. Most researchers focus on US/EU. I'm interested in what's happening here.

I build tools to automate the boring parts of recon so I can spend more time on the parts that need human reasoning. Current project — AI-Hack-OS — is an attempt to use AI as a reasoning layer over raw recon, not as another scanner.

If something I publish is useful to you — or wrong — I want to hear about it.

internet-scale recon EXP
attack surface mgmt EXP
api / openapi audit EXP
js + source map analysis ADV
ai-assisted hunting ADV
cloud exposure ADV
bug bounty automation ADV
technical writing EXP
// open channel

Send a signal.
I read everything.

Research questions, collaboration ideas, something interesting you found, or a bug you want a second pair of eyes on. Response time varies based on how deep into a scan I am.

[email protected]
/ open research index · esc close