01APPLICATION SECURITY / OFFENSIVE SECURITYKOLKATA, INDIA

> scope --primary

VAPT &
Application
Security

I test web applications, APIs, and mobile applications to uncover exploitable vulnerabilities, validate real-world impact, and provide actionable remediation guidance.

Breaking applications before attackers do.01—07 / scroll to inspect
02ABOUT THE PRACTICE

Test the real attack surface.

I approach security assessments as an investigation: start with reconnaissance, understand how the application behaves, then test the boundaries where trust can fail.

My work combines manual validation, authorized exploitation, evidence collection, risk assessment, and professional reporting. The result is a finding a development team can reproduce, prioritize, and fix.

03CORE SERVICES

Where I look for failure.

Focused testing across the application layers that carry identity, data, and business value.

01

Web Application VAPT

Authentication, authorization, session management, input validation, injection, XSS, CSRF, SSRF, business logic, and security misconfiguration.

02

API Security Testing

Authentication, authorization, BOLA / IDOR, rate limiting, input validation, API abuse, sensitive-data exposure, and business logic vulnerabilities.

03

Mobile Application Security

Android assessment, static and dynamic analysis, API testing, authentication, local data storage, reverse engineering, and runtime instrumentation.

04

Reconnaissance & Attack Surface

Asset discovery, subdomain enumeration, endpoint discovery, technology fingerprinting, exposure analysis, and attack-surface mapping.

05

Vulnerability Validation

Reproduction, exploit validation, impact assessment, evidence collection, and severity classification grounded in observed behavior.

06

Security Reporting

Executive summary, technical findings, proof of concept, business impact, severity, remediation, and retest validation.

04SELECTED SECURITY WORK

Evidence over adjectives.

Selected responsible-disclosure work and attack-surface research, presented as concise security case studies.

01 / HALL OF FAMEWEB APPLICATION

Zepto Security Hall of Fame

Recognised after responsibly disclosing validated security findings to help strengthen platform security.

TestedProduction web platformMethodManual vulnerability researchStatusResponsible disclosure
Source
02 / VALIDATED FINDINGWEB APPLICATION

Zerodha Security Finding

Reported a validated vulnerability through a responsible disclosure programme.

TestedWeb application attack surfaceMethodReproduction and impact analysisStatusResponsible disclosure
Programme
03 / DISCLOSUREANDROID / DATA EXPOSURE

Paytm Android Security Assessment

Responsible disclosure of a production mobile-app security issue involving sensitive-data exposure.

TestedAndroid applicationMethodStatic analysis and validationStatusResponsible disclosure
Evidence
04 / RESEARCH PROGRAMWEB / API

Continuous Attack Surface Research

Independent assessment of web applications and APIs, with emphasis on reconnaissance, misconfiguration, and access-control issues.

TestedWeb applications and APIsMethodReconnaissance and manual validationStatusOngoing research
Independent research
05 / HALL OF FAMEWEB APPLICATION

Yatra Security Finding

A finding validated by the Infosec team through responsible disclosure.

TestedWeb applicationMethodVulnerability discovery and validationStatusResponsible disclosure
Source
05ASSESSMENT METHOD

From signal to fix.

01

Reconnaissance

Map the attack surface and identify exposed assets.

02

Enumeration

Discover endpoints, technologies, parameters, APIs, and authentication boundaries.

03

Assessment

Systematically test security controls and application behavior.

04

Validation

Manually reproduce and validate vulnerabilities.

05

Exploitation

Demonstrate realistic impact within authorized testing boundaries.

06

Reporting

Document evidence, severity, business impact, and remediation.

07

Retesting

Verify that remediation actually resolves the vulnerability.

06EXPERIENCE

Practice in context.

JUL 2026 — PRESENT
RAJARHAT · ON-SITE

Information Security Intern · Digi Samurai

Gaining full-time, hands-on office experience alongside security professionals on live client engagements and day-to-day Information Security operations.

  • Supporting security operations and client engagements
  • Hands-on VAPT for web applications, APIs, and mobile applications
  • Security research, risk analysis, and technical documentation
  • Reconnaissance, vulnerability validation, reporting, and remediation recommendations
  • Cross-functional collaboration on security posture, incident response, compliance, and information security management
JAN 2026 — PRESENT
REMOTE · FREELANCE

Bug Bounty Hunter · Com Olho

Conducting independent security research across web applications and APIs through ethical, coordinated disclosure programmes.

  • Reconnaissance and attack-surface analysis
  • Vulnerability discovery, validation, and impact analysis
  • Validated findings and responsible disclosure
  • Tools and automation workflows for testing and analysis
  • Application security, infrastructure misconfigurations, and OSINT-driven reconnaissance
NOV 2025 — DEC 2025
KOLKATA · HYBRID

App Developer Intern · AZMTH

Contributed to Flutter-based mobile application development within an AI-driven communication platform.

  • API integrations, application testing, and secure authentication workflows
  • Scalable application features and performance optimization
  • Collaboration with development and AI teams
08PROFESSIONAL DEVELOPMENT

Certifications,
kept in context.

A record of completed certifications and technical learning. The practice remains VAPT-led.

TRYHACKME / 09

SOC Level 1 · SOC Level 2 · Security Engineer · DevSecOps · Jr Penetration Tester · AI Security · Web Fundamentals · Pre Security · Advanced Endpoint Investigations

CISCO / 03

Certified Ethical Hacker (CEH) · Python Essentials 1 · Python Essentials 2

AWS / 03

Cloud Security · Compute · Introduction to Cloud

RED TEAM LEADERS / 03

Certified Red Team Operations Management (CRTOM) · Foundations of Log Analysis for Cyber Defense · Certified LLM Security Expert (CLLMSE)

OTHER / 03

SQL Injection Attacks — Code Red · Python Programming Fundamentals · Fundamental Cloud & DevOps

09FIELD TOOLKIT

A focused toolkit.

WEB / API TESTING

Burp Suite · OWASP ZAP · Nmap · Nuclei · ffuf · Gobuster · SQLmap · Metasploit · Nikto · WPScan

RECONNAISSANCE

Subfinder · Amass · httpx · Katana · gau · Wayback · Arjun

MOBILE SECURITY

MobSF · Frida · Objection · JADX · Apktool · ADB

AUTOMATION

Python · Bash · Linux

SECONDARY CAPABILITIES

SOC / Threat Detection · Cloud Security

OPERATING MODEL

Understand the system before testing it.

Prove the behavior with reproducible evidence.

Explain risk in terms teams can act on.

10PRACTICE NOTES

Questions,
answered.

A short briefing on how I approach assessments and responsible disclosure.

What does a security assessment include?

Scope alignment, reconnaissance, testing, evidence collection, risk context, and a clear report with practical remediation guidance.

How do you validate a vulnerability?

By manually reproducing the behavior, documenting evidence, assessing realistic impact, and communicating the conditions required to reproduce it.

Can you help with responsible disclosure?

Yes. I have reported validated findings through coordinated disclosure programmes and can help teams understand, reproduce, and remediate issues.

11BACKGROUND

Research,
communication.

AUG 2023 — JUN 2026

University of North Bengal

B.A. English Language and Literature, General · 7.81 CGPA

  • Analytical thinking, research, communication, and presentation
  • Active in volleyball, cricket, table tennis, chess, extempore speaking, and quiz competitions
2008 — 2023

Saint Paul's School, Jalpaiguri

Secondary Education (ICSE) and Higher Secondary Education (ISC), Arts