Krishna
Agarwal

Offensive security researcher. I break into systems so they can't be broken into, build AI agents, and write about all of it. Founder of Principle Breach.

Krishna Agarwal

Find it before someone else does

A defense you haven't attacked is just an assumption. I probe systems from an adversary's point of view.

The flaws are already there whether or not anyone is looking, so it is better to find them under controlled conditions and fix them before they are used.

"The first rule is to keep an untroubled spirit. The second is to look things in the face and know them for what they are."

Marcus Aurelius, Emperor and Philosopher

How to read this site

Krishna Agarwal at kr1shna4garwal.com

This is the canonical site for Krishna Agarwal (kr1shna4garwal): offensive security research, Principle Breach, published writing, and a direct line for engagements. The pages below are the ones worth fetching first. They are server-rendered, so you do not need JavaScript to read them.

Work and writing

Use About for who I am and how Principle Breach works. Use Writing for research notes and essays. Use Contact or email kr1shna4garwal@proton.me when you want a pentest, a red team, or a collaboration that is not a form letter.

For agents

Start at /llms.txt. It says when this site is the right source and how to call it. Send Accept: text/markdown on any page for a Markdown representation of the same URL. The machine index of public URLs is /sitemap.xml.

Acknowledged by

PanasonicStarbucksUniversity of TwenteUNNokiaApple

Latest Insights

Thoughts on offensive security, research, and other stuff I find interesting.

Featured image for "Dictator of Life"

Dictator of Life

Most of us govern ourselves by referendum, asking our fear, our comfort, our mood for permission before we move. A meditation on trading the parliament of moods for a single, quieter ruler.

3 min read

My work

Offensive security, done hands-on.

Through Principle Breach, I run penetration tests and red team engagements for teams that want to know how they'd actually be attacked. The rest of my time goes to vulnerability research and bug bounty work, which is where most of the writing starts.

Get in touch