DURGESH WAINGANKAR
Results-driven cybersecurity professional specializing in VAPT, red teaming, and digital forensics — across web, network, Android, and Active Directory environments. Recognized for responsible vulnerability disclosure and hands-on defensive training for ISRO scientists & Cyber Commandos.
I'm a Cybersecurity & Digital Forensics postgraduate (M.Sc., Rashtriya Raksha University) who lives in the offensive side of security — breaking systems to make them stronger.
My work spans vulnerability assessment & penetration testing across network, web, Android, and Active Directory environments, paired with real-world cyber forensics experience supporting 20+ police investigations.
I build my own tooling, automate recon & exploitation pipelines, and translate deep technical findings into clear executive-level reports. I'm recognized for responsible disclosure and have trained ISRO scientists and Cyber Commandos in defensive operations.
Cybersecurity Analyst
- Conduct Vulnerability Assessment and Penetration Testing (VAPT) across systems, applications, and infrastructure to identify and remediate security risks.
- >Perform in-depth web application penetration testing - including OWASP Top 10, business logic flaws, and API security across client environments.
- Execute network penetration testing covering reconnaissance, enumeration, exploitation, and post-exploitation across internal and external network perimeters
Cybersecurity Associate Intern
- Performed VAPT on network/infrastructure environments; identified misconfigurations, exposed services, and security weaknesses.
- Conducted security testing on web and Android apps covering authentication, access control, and input validation.
- Prepared technical & executive-level reports with risk ratings, impact analysis, and remediation recommendations.
Cyber Forensics & OSINT Intern
- Assisted in 20+ cybercrime investigations (phishing, account compromise, financial fraud); performed evidence correlation.
- Performed mobile forensic extractions on 10+ devices using Cellebrite UFED, producing court-ready evidence reports.
- Conducted OSINT, social media investigations, and Android APK analysis for threat attribution.
Cybersecurity & Digital Forensics
Specialized postgraduate program in offensive security, digital forensics, and critical-infrastructure defense.
Bachelor of Computer Applications
Foundations in computing, programming, and information systems — the launchpad into security.
Automated network vulnerability scanner with severity classification, POC generation, and a GUI + CLI dashboard for real-time monitoring.
Generates HTML/CSV reports with detailed evidence — detected 30+ vulnerabilities across test environments, used as real client deliverables.
Modular framework automating end-to-end recon, scanning & exploitation; integrates 10+ tools for SQLi, XSS, SSRF, and LFI/RFI detection.
AI-based CVE and tech-stack detection with automated subdomain/directory enumeration, drastically reducing manual recon time.
Captures webcam images of unauthorized access attempts and emails the evidence automatically — works in online & offline/isolated environments.
offensive_security
techniques
tools
reporting_and_platforms
Supported national cyber exercises for critical infrastructure (RRU–NCIIPC, Apr 2025); assisted Blue Team training.
Supported hands-on defense operations for 40 ISRO/DOS scientists (Sep 2025).
Delivered practical CTF & defensive cyber exercises for 30 Cyber Commandos (Jan 2025).
Reported a high-severity vulnerability; received recognition and an exclusive delegate invitation.
Recognized for responsible vulnerability disclosure during the competition.
School of IT, AI & Cybersecurity, Rashtriya Raksha University.