Security Researcher
I break things so they can be rebuilt stronger — offensive security across web, mobile, API, cloud and Web3.
$ whoami
Deepak Raj — Cybersecurity Researcher
$ cat skills.txt
VAPT | Red Teaming | OSINT | Web3 Security | API Security
$ echo $CURRENT_ROLE
Deputy Manager @ Protiviti
Type help and hit Enter to explore ↓
Years Experience
Security Tests
HTB Global Rank
I'm a cybersecurity researcher with a passion for discovering vulnerabilities, understanding exploit techniques, and researching emerging threats. Security isn't just about finding bugs — it's about understanding the attacker's mindset.
Currently a Deputy Manager at Protiviti, I run comprehensive security assessments across web applications, mobile apps, APIs, cloud infrastructure, and emerging technologies like Web3.
I thrive on continuous learning — contributing to the security community through writeups, tool development, and knowledge sharing, from manual penetration testing to threat intelligence and red team operations.
Web, Mobile, API, Network, Cloud, Thick Client, Web3
Threat modeling and offensive security assessments
0-day exploits, CVE analysis, and threat intelligence
Guest lectures, training delivery, community contribution
Protiviti India Member Firm, Bengaluru
Jan 2026 – Present
Accenture, Bengaluru
Sep 2024 – Oct 2025
Protiviti India Member Firm, Bengaluru
Dec 2023 – Aug 2024
Accubits Technologies Inc, Kerala
Sep 2022 – Dec 2023
West Advanced Technologies, Inc, Hyderabad
Oct 2021 – Aug 2022
Powerful Google Dork search automation tool for security researchers and penetration testers
Scrapes Google dork entries from Exploit-DB, searches against target domains, crawls discovered URLs, and supports export functionality with retry/resume logic.
View on GitHubModular reconnaissance tool integrating multiple recon utilities into a single command
Integrates assetfinder, subjack, CloudFail, Arjun, and Smuggler. Supports targeted or full-scope engagements with proper output logging for bug bounty hunters and red teamers.
View on GitHubActive bug bounty hunter with recognized security vulnerabilities reported
Hall of Fame recognition from BMW Group and Synack targets. Live bug bounty hunting session at Nullcon invited by Airtel. Active contributor identifying security flaws across platforms.
Contact for DetailsWalking through an access-control flaw that escalated from a minor info leak into a complete account takeover.
Read on blog ReconHow I stitch subdomain enumeration, CORS checks and request smuggling probes into one recon pipeline.
Read on blog Web3A field guide to the reentrancy, access-control and oracle bugs I keep finding in Web3 audits.
Read on blogRecognized by BMW Group and Synack targets for submitting valid security bugs
Ranked among top 500 globally on HackTheBox platform
Delivered cybersecurity lecture at Dr. NGP College of Arts and Science
Organized and conducted Capture The Flag event at Dr. NGP College
Invited by Airtel for live bug bounty hunting session at Nullcon
CAP, eWPTX, RastaLabs Pro, PentesterLab certifications
Coimbatore, Tamil Nadu, India