Security researcher & BlackHat trainer building tools that hunt secrets at internet scale.
currently: security researcher @ RedHunt Labs — Surat, IN
Security Researcher
RedHunt Labs
Security Researcher
RedHunt Labs
- Built an AI-powered exploit agent that monitors newly published CVE exploitation scripts and automatically converts them into Nuclei templates for vulnerability detection.
- Developed cloud security & exposure management tools for AWS, GCP and Cloudflare — continuous discovery of misconfigurations, public assets and exposure risks across multi-cloud environments.
- Manage and develop large-scale attack surface management (ASM) infrastructure — vulnerability scanners, host profilers and website correlation engines.
- Built tools to monitor certificates, subdomains, DockerHub and secrets across GitHub, GitLab, Bitbucket and Postman — collecting 100,000+ exposed secrets monthly.
- Performed internet-wide vulnerability scanning and threat-intelligence research, surfacing emerging exposure patterns across diverse technologies.
- Migrated and optimized the entire scanning infrastructure to AWS, improving scalability and scan efficiency by 45%.
- Created the public research dashboard research.redhuntlabs.com — interactive insights and datasets for the global infosec community.
Security Engineer
BugBase
Security Engineer
BugBase
- Conducted Vulnerability Assessment & Penetration Testing (VAPT) on Android and web applications, identifying and validating critical vulnerabilities that strengthened client security posture.
- Developed in-house security tools to automate vulnerability discovery and streamline triaging and testing workflows — improving assessment efficiency by 30%.
- Managed bug bounty programs for major technology companies — report triaging, validation and remediation guidance for fast, effective resolution.
- Curated and engineered datasets to fine-tune the AI security models behind copilot.bugbase.ai, and built benchmarks to measure model accuracy and exploit-detection effectiveness.
Bug Bounty Hunter
Intigriti · HackerOne
Bug Bounty Hunter
Intigriti · HackerOne
- Reported and responsibly disclosed critical vulnerabilities to major organizations including Microsoft, MongoDB, Salesforce, Cisco and EA Sports.
- Identified high-impact issues: RCE, account takeover, Firebase database takeovers, CSRF leading to organization takeover, SSRF to local file read, and complex business-logic bypasses.
IAMX↗
Multi-cloud IAM enumeration CLI — effective permissions across 400+ AWS services, 4000+ GCP permissions, 2000+ Azure operations.
Varunastra↗
Detects and mitigates vulnerabilities across Docker containers and images — secrets, CVEs, misconfigs.
Agneyastra↗
Firebase misconfiguration detection toolkit built for bug bounty hunters and researchers.
Cyclops↗
Free serverless alternative to Burp Collaborator — catch SSRF and blind XSS callbacks without infrastructure.
Echoes of AI Exposure↗
Thousands of secrets leaking through vibe-coded sites — Project Resonance, Wave 15.
The State of the Web↗
The tech powering the Tranco Top 1 Million — and the vulnerabilities underneath. Project Resonance, Wave 12.
Concurrent Tasks with Goroutines & WaitGroups→
Golang's goroutines and waitgroups — and how they help you write dramatically faster tooling.