About me
I'm a security professional based in Palghar, Maharashtra, India, focused on offensive security — penetration testing, red team operations, and adversary simulation across web applications, APIs, mobile platforms, networks, and cloud environments.
My work spans reconnaissance, enumeration, and attack-surface analysis through exploitation, post-exploitation, and reporting. I assess authentication mechanisms, access controls, business logic, and infrastructure configurations — delivering findings with clear remediation guidance.
Beyond client work, I conduct vulnerability research and responsible disclosure. I've been recognized by NCIIPC for government-site findings, acknowledged by bug bounty programs, and named in the Springer Nature Hall of Fame.
I believe security findings are only as valuable as the clarity they're communicated with. I report to technical teams and executives alike, and I'm committed to helping organizations understand risk and improve their security posture.
Recon & Attack Surface
Asset discovery, enumeration, and attack-surface mapping to understand exposure before exploitation.
Web & API Security
Authentication, authorization, business logic, and access-control testing across web applications and APIs.
Mobile Security
Android application security testing — static analysis, dynamic testing, and API interception.
Red Team Operations
Adversary simulation, initial access assessment, and attack-path validation where authorized.
Social Engineering
Authorized phishing simulations and security-awareness testing to assess organizational defenses.
Reporting & Remediation
Evidence-based documentation, risk-prioritized findings, and actionable remediation guidance.
Experience
- Penetration testing across enterprise environments — web applications, APIs, mobile (Android & iOS), and internal network infrastructure.
- Red team engagements simulating real adversaries across initial access, privilege escalation, lateral movement, and persistence.
- Phishing simulations and social engineering assessments to evaluate user awareness and email security controls.
- Identified and exploited IDOR, SQL Injection, XSS, authentication bypasses, and critical misconfigurations.
- Technical reporting with attack-path documentation, business-impact analysis, and remediation guidance for development and security teams.
- Penetration testing of web applications hosted on Microsoft Azure, plus APIs and mobile applications.
- Collaborated with developers to implement tailored mitigations and improve long-term security posture.
- Wi-Fi and network penetration testing with detailed, actionable client reports.
- Mentored new joiners and interns on penetration testing methodology and best practices.
- Web, API, and mobile application testing for multiple banking applications.
- Source code reviews using SonarQube to identify security flaws and improve code quality.
- End-to-end management of pentest reports — from assessment through delivery and client review.
- Contributed to CERT-IN compliance and assessment program; awarded Employee of the Month twice.
- Penetration testing of web applications and APIs with detailed reporting and developer remediation support.
- Active Directory and network infrastructure testing with recommendations to enhance security posture.
- Assessed international clients; responsible for end-to-end client delivery.
- Provided remediation guidance and issue clarification; contributed to company cybersecurity blog.
Selected Work
Sanitized examples of offensive-security assessment areas and security research themes. Engagement details are intentionally generalized to respect confidentiality.
Web Application & API Security
Focus: Authentication mechanisms, authorization controls, session management, business logic, and API security assessment.
Approach: Manual application testing combined with automated discovery, targeted validation, and attack-surface analysis.
Mobile Application Security
Focus: Android application security assessment, API interception, and mobile-specific vulnerability classes.
Approach: Static analysis, dynamic testing, traffic interception, and backend API evaluation.
Network & Internal Security
Focus: Network penetration testing, service enumeration, internal attack-surface assessment, and privilege escalation.
Approach: Infrastructure enumeration, vulnerability validation, and attack-path analysis within authorized scope.
Active Directory Security
Focus: Domain environment security assessment, identity and privilege analysis, and attack-path evaluation.
Approach: Domain enumeration, configuration analysis, and identity-based attack-path validation where authorized.
Red Team Operations
Focus: Adversary simulation, initial-access assessment, and security-control validation in controlled engagements.
Approach: Full-kill-chain simulation within authorized scope — reconnaissance, initial access, escalation, and persistence.
Social Engineering Assessment
Focus: Authorized phishing simulations and security-awareness testing to assess organizational email security and user awareness.
Approach: Controlled simulation scenarios designed to test email security controls and user response — always within explicit authorization.
Certifications
Certified AppSec Practitioner v2 (CAP)
Hands-on application security assessment skills covering the OWASP Top 10.
Multi-Cloud Red Team Analyst
Adversary simulation and attack techniques across cloud environments.
Certified Red Team Professional
Red team operations — initial access, pivoting, privilege escalation, and evasion.
API Penetration Testing
Security assessment of REST APIs — authentication, authorization, and injection flaws.
Cyber Security & Penetration Testing
Core penetration testing methodology, tooling, and reporting fundamentals.
Cyber Security & Ethical Hacking
Ethical hacking foundations — reconnaissance, exploitation, and defense mindset.
Achievements
NCIIPC Recognition
Recognized for discovering security vulnerabilities in government websites — demonstrating responsible disclosure and excellence in vulnerability research.
Outstanding Researcher Certificate
Reported and helped fix 69+ security vulnerabilities across various platforms. Earned 2 Coordinated and Responsible Disclosure badges.
View profile ↗Appreciations
Acknowledged by major programs for security findings — recognition that my testing delivers real value to real products used by millions.
Springer Nature
Named in the public security disclosure Hall of Fame for responsibly reported vulnerabilities.
View disclosure page ↗Bug Bounty Proof-of-Concept Videos
Proof-of-concept walkthroughs demonstrating discovered vulnerabilities and exploitation techniques end-to-end.
Watch POCs ↗Skills & Toolkit
$Web & API Security
$Mobile Security
$Network & Internal Security
$Active Directory
$Cloud Security
$Red Team / Social Engineering
$Vulnerability Research
$Scripting & Automation
$Web & API Tools
$Recon & Infrastructure Tools
$Mobile Tools
$Communication & Delivery
$Hands-on Labs
Contact
Let's secure something together.
Whether you're hiring, have a program to test, or just want to talk offensive security — my inbox is open. I'll get back to you quickly.