root@offensive-security

Hi, I'm
Gaurav Patil

Offensive security specialist with hands-on experience across white-box, gray-box, and black-box security testing of web applications, APIs, and networks. I find high-impact vulnerabilities, simulate real adversaries, and turn findings into clear, prioritized remediation for technical teams and business stakeholders alike.

0
Years experience
0+
Vulnerabilities responsibly disclosed
0
Certifications
01.

About me

I'm a security professional based in Palghar, Maharashtra, India, focused on offensive security — penetration testing, red team operations, and adversary simulation across web applications, APIs, mobile platforms, networks, and cloud environments.

My work spans reconnaissance, enumeration, and attack-surface analysis through exploitation, post-exploitation, and reporting. I assess authentication mechanisms, access controls, business logic, and infrastructure configurations — delivering findings with clear remediation guidance.

Beyond client work, I conduct vulnerability research and responsible disclosure. I've been recognized by NCIIPC for government-site findings, acknowledged by bug bounty programs, and named in the Springer Nature Hall of Fame.

I believe security findings are only as valuable as the clarity they're communicated with. I report to technical teams and executives alike, and I'm committed to helping organizations understand risk and improve their security posture.

🔍

Recon & Attack Surface

Asset discovery, enumeration, and attack-surface mapping to understand exposure before exploitation.

🌐

Web & API Security

Authentication, authorization, business logic, and access-control testing across web applications and APIs.

📱

Mobile Security

Android application security testing — static analysis, dynamic testing, and API interception.

🎯

Red Team Operations

Adversary simulation, initial access assessment, and attack-path validation where authorized.

🎣

Social Engineering

Authorized phishing simulations and security-awareness testing to assess organizational defenses.

📝

Reporting & Remediation

Evidence-based documentation, risk-prioritized findings, and actionable remediation guidance.

02.

Experience

Deputy Manager CURRENT
Nov 2025 — Present
Protiviti India · Business Consulting Firm
  • Penetration testing across enterprise environments — web applications, APIs, mobile (Android & iOS), and internal network infrastructure.
  • Red team engagements simulating real adversaries across initial access, privilege escalation, lateral movement, and persistence.
  • Phishing simulations and social engineering assessments to evaluate user awareness and email security controls.
  • Identified and exploited IDOR, SQL Injection, XSS, authentication bypasses, and critical misconfigurations.
  • Technical reporting with attack-path documentation, business-impact analysis, and remediation guidance for development and security teams.
Associate Security Consultant
Mar 2024 — Nov 2025
KPMG India · Goregaon
  • Penetration testing of web applications hosted on Microsoft Azure, plus APIs and mobile applications.
  • Collaborated with developers to implement tailored mitigations and improve long-term security posture.
  • Wi-Fi and network penetration testing with detailed, actionable client reports.
  • Mentored new joiners and interns on penetration testing methodology and best practices.
Security Analyst
Sep 2023 — Mar 2024
Writer Information · Andheri
  • Web, API, and mobile application testing for multiple banking applications.
  • Source code reviews using SonarQube to identify security flaws and improve code quality.
  • End-to-end management of pentest reports — from assessment through delivery and client review.
  • Contributed to CERT-IN compliance and assessment program; awarded Employee of the Month twice.
Associate Security Consultant
Nov 2022 — Sep 2023
Redfox Cyber Security Inc · Andheri
  • Penetration testing of web applications and APIs with detailed reporting and developer remediation support.
  • Active Directory and network infrastructure testing with recommendations to enhance security posture.
  • Assessed international clients; responsible for end-to-end client delivery.
  • Provided remediation guidance and issue clarification; contributed to company cybersecurity blog.
03.

Selected Work

Sanitized examples of offensive-security assessment areas and security research themes. Engagement details are intentionally generalized to respect confidentiality.

WEB / API

Web Application & API Security

Focus: Authentication mechanisms, authorization controls, session management, business logic, and API security assessment.

Approach: Manual application testing combined with automated discovery, targeted validation, and attack-surface analysis.

Authentication Authorization Business Logic Access Control Input Validation
MOBILE

Mobile Application Security

Focus: Android application security assessment, API interception, and mobile-specific vulnerability classes.

Approach: Static analysis, dynamic testing, traffic interception, and backend API evaluation.

Android Static Analysis Dynamic Testing API Interception
INTERNAL

Network & Internal Security

Focus: Network penetration testing, service enumeration, internal attack-surface assessment, and privilege escalation.

Approach: Infrastructure enumeration, vulnerability validation, and attack-path analysis within authorized scope.

Network Enumeration Service Assessment Privilege Escalation Lateral Movement
INTERNAL

Active Directory Security

Focus: Domain environment security assessment, identity and privilege analysis, and attack-path evaluation.

Approach: Domain enumeration, configuration analysis, and identity-based attack-path validation where authorized.

Domain Enumeration Identity Analysis Attack-Path Analysis Configuration Review
RED TEAM

Red Team Operations

Focus: Adversary simulation, initial-access assessment, and security-control validation in controlled engagements.

Approach: Full-kill-chain simulation within authorized scope — reconnaissance, initial access, escalation, and persistence.

Adversary Simulation Initial Access Attack-Path Validation Security-Control Testing
RED TEAM

Social Engineering Assessment

Focus: Authorized phishing simulations and security-awareness testing to assess organizational email security and user awareness.

Approach: Controlled simulation scenarios designed to test email security controls and user response — always within explicit authorization.

Phishing Simulation Security Awareness Email Security Credential Phishing
04.

Certifications

APP SEC

Certified AppSec Practitioner v2 (CAP)

The SecOps Group

Hands-on application security assessment skills covering the OWASP Top 10.

Issued June 2025
CLOUD

Multi-Cloud Red Team Analyst

CyberWarFare

Adversary simulation and attack techniques across cloud environments.

Issued Feb 2025
RED TEAM

Certified Red Team Professional

Altered Security

Red team operations — initial access, pivoting, privilege escalation, and evasion.

Issued Nov 2024
API SEC

API Penetration Testing

APIsec University

Security assessment of REST APIs — authentication, authorization, and injection flaws.

Issued Feb 2023
FOUNDATIONS

Cyber Security & Penetration Testing

Hacktify Cyber Security

Core penetration testing methodology, tooling, and reporting fundamentals.

Issued April 2021
FOUNDATIONS

Cyber Security & Ethical Hacking

Hacktify Cyber Security

Ethical hacking foundations — reconnaissance, exploitation, and defense mindset.

Issued March 2021
05.

Achievements

GOVERNMENT RECOGNITION

NCIIPC Recognition

National Critical Information Infrastructure Protection Centre

Recognized for discovering security vulnerabilities in government websites — demonstrating responsible disclosure and excellence in vulnerability research.

Since 2021 · Vulnerability Research
BUG BOUNTY · 69+ VULNERABILITIES

Outstanding Researcher Certificate

Open Bug Bounty

Reported and helped fix 69+ security vulnerabilities across various platforms. Earned 2 Coordinated and Responsible Disclosure badges.

View profile ↗
Active Researcher
PROGRAM ACKNOWLEDGEMENTS

Appreciations

Shaadi · OnePlus · NoBroker · MagicBricks

Acknowledged by major programs for security findings — recognition that my testing delivers real value to real products used by millions.

Bug Bounty & Vulnerability Research
HALL OF FAME

Springer Nature

Global Academic Publisher

Named in the public security disclosure Hall of Fame for responsibly reported vulnerabilities.

View disclosure page ↗
Responsible Disclosure
POC DEMONSTRATIONS

Bug Bounty Proof-of-Concept Videos

YouTube Playlist

Proof-of-concept walkthroughs demonstrating discovered vulnerabilities and exploitation techniques end-to-end.

Watch POCs ↗
Ongoing
06.

Skills & Toolkit

$Web & API Security

# web-and-api-assessment
Web Applications APIs · REST/SOAP Authentication Testing Authorization Testing Business Logic Testing Session Management Access Control Testing

$Mobile Security

# mobile-assessment
Android Static Analysis Dynamic Testing API Interception

$Network & Internal Security

# network-and-infrastructure
Network Penetration Testing Internal Security Assessment Wi-Fi Security Service Enumeration Privilege Escalation

$Active Directory

# identity-and-access
AD Security Assessment Domain Enumeration Identity Analysis Attack-Path Analysis

$Cloud Security

# cloud-assessment
Cloud Security Assessment IAM Review Configuration Review Exposure Analysis

$Red Team / Social Engineering

# adversary-simulation
Phishing Simulation Security Awareness Testing EvilGoPhish Adversary Simulation Initial Access Assessment Credential Phishing

$Vulnerability Research

# research-and-analysis
Vulnerability Research PoC Development Root-Cause Analysis Exploit Analysis

$Scripting & Automation

# automation-and-tooling
Python Bash JavaScript Recon Tooling Web-based Scripting

$Web & API Tools

# arsenal-web
Burp SuiteSQLMapNuclei OWASP ZAPGoBusterFFuF Dirsearchjwt-toolPostman SoapUIHttpxCyberChef NiktoWhatWafWappalyzer

$Recon & Infrastructure Tools

# arsenal-recon
NmapAmassSublist3r MetasploitNessus

$Mobile Tools

# arsenal-mobile
FridaAPKToolMobSF GhidraObjectionJADX adbAndroid Studio

$Communication & Delivery

# the-human-layer
Technical Report Writing Executive Summaries Remediation Guidance Client Delivery Blog Writing Mentoring

$Hands-on Labs

# continuous-learning
TryHackMeHackTheBoxPortSwigger WSA InsecureBank v1/v2DVWAWebGoat OWASP Juice Shop
07.

Contact

Let's secure something together.

Whether you're hiring, have a program to test, or just want to talk offensive security — my inbox is open. I'll get back to you quickly.

🐞
Open Bug Bounty
Please enter your name.
Please enter a valid email address.
Please write a message (min. 10 characters).
Opening your email client…