00_Intro Open to pentest, bug bounty & research collabs

Security researcher & BlackHat trainer building tools that hunt secrets at internet scale.

currently: security researcher @ RedHunt Labs — Surat, IN

5×BlackHat stages
5+Tools shipped
4+Yrs offensive security
$50K+In bug bounties
01_Experience $ history | tail -n 3

Security Researcher

RedHunt Labs

2024 — Now[+]
  • Built an AI-powered exploit agent that monitors newly published CVE exploitation scripts and automatically converts them into Nuclei templates for vulnerability detection.
  • Developed cloud security & exposure management tools for AWS, GCP and Cloudflare — continuous discovery of misconfigurations, public assets and exposure risks across multi-cloud environments.
  • Manage and develop large-scale attack surface management (ASM) infrastructure — vulnerability scanners, host profilers and website correlation engines.
  • Built tools to monitor certificates, subdomains, DockerHub and secrets across GitHub, GitLab, Bitbucket and Postman — collecting 100,000+ exposed secrets monthly.
  • Performed internet-wide vulnerability scanning and threat-intelligence research, surfacing emerging exposure patterns across diverse technologies.
  • Migrated and optimized the entire scanning infrastructure to AWS, improving scalability and scan efficiency by 45%.
  • Created the public research dashboard research.redhuntlabs.com — interactive insights and datasets for the global infosec community.
ASMThreat IntelCloudGoAWS

Security Engineer

BugBase

2022 — 2024[+]
  • Conducted Vulnerability Assessment & Penetration Testing (VAPT) on Android and web applications, identifying and validating critical vulnerabilities that strengthened client security posture.
  • Developed in-house security tools to automate vulnerability discovery and streamline triaging and testing workflows — improving assessment efficiency by 30%.
  • Managed bug bounty programs for major technology companies — report triaging, validation and remediation guidance for fast, effective resolution.
  • Curated and engineered datasets to fine-tune the AI security models behind copilot.bugbase.ai, and built benchmarks to measure model accuracy and exploit-detection effectiveness.
VAPTAndroidTriageAI Security

Bug Bounty Hunter

Intigriti · HackerOne

2022 — Now[+]
  • Reported and responsibly disclosed critical vulnerabilities to major organizations including Microsoft, MongoDB, Salesforce, Cisco and EA Sports.
  • Identified high-impact issues: RCE, account takeover, Firebase database takeovers, CSRF leading to organization takeover, SSRF to local file read, and complex business-logic bypasses.
RCEATOSSRFLogic Bugs
02_Hall_of_Fame Reported critical bugs to
03_Arsenal All tools →
04_Writing Latest reads · all posts →
05_Contact Let's break something — responsibly
Email