eternalsec:~$ ./init_portfolio.sh
boot
AVAILABLE FOR RESEARCH & COLLABORATION · MUMBAI, IN

DURGESH WAINGANKAR

// aka @EternalSec — root operator
$

Results-driven cybersecurity professional specializing in VAPT, red teaming, and digital forensics — across web, network, Android, and Active Directory environments. Recognized for responsible vulnerability disclosure and hands-on defensive training for ISRO scientists & Cyber Commandos.

0CYBERCRIME CASES
0VULNS DETECTED
0CERTIFICATIONS
0DEVICES FORENSICS
0x1F [ AES-256 ] </>
EternalSec.id
Durgesh Waingankar
HANDLE @EternalSec
FOCUS RED TEAM / VAPT
CLEARANCE CRTS v2 · CEH v13
LOCATION MUMBAI, IN
$ cat whoami.txt
01 / 08
~/about/whoami.txt

I'm a Cybersecurity & Digital Forensics postgraduate (M.Sc., Rashtriya Raksha University) who lives in the offensive side of security — breaking systems to make them stronger.

My work spans vulnerability assessment & penetration testing across network, web, Android, and Active Directory environments, paired with real-world cyber forensics experience supporting 20+ police investigations.

I build my own tooling, automate recon & exploitation pipelines, and translate deep technical findings into clear executive-level reports. I'm recognized for responsible disclosure and have trained ISRO scientists and Cyber Commandos in defensive operations.

VAPTRed TeamingDigital Forensics OSINTActive DirectoryMobile Security ReportingTool Development
$ tail -f experience.log
02 / 08

Cybersecurity Analyst

[ REDACTED ] · Mumbai · Full Time
2026 — PRESENT
  • Conduct Vulnerability Assessment and Penetration Testing (VAPT) across systems, applications, and infrastructure to identify and remediate security risks.
  • >Perform in-depth web application penetration testing - including OWASP Top 10, business logic flaws, and API security across client environments.
  • Execute network penetration testing covering reconnaissance, enumeration, exploitation, and post-exploitation across internal and external network perimeters

Cybersecurity Associate Intern

[ REDACTED ] · Mumbai · Private
JAN 2026 — APR 2026
  • Performed VAPT on network/infrastructure environments; identified misconfigurations, exposed services, and security weaknesses.
  • Conducted security testing on web and Android apps covering authentication, access control, and input validation.
  • Prepared technical & executive-level reports with risk ratings, impact analysis, and remediation recommendations.

Cyber Forensics & OSINT Intern

MBVV Cyber Police Station · Mumbai
DEC 2023 — JUL 2024
  • Assisted in 20+ cybercrime investigations (phishing, account compromise, financial fraud); performed evidence correlation.
  • Performed mobile forensic extractions on 10+ devices using Cellebrite UFED, producing court-ready evidence reports.
  • Conducted OSINT, social media investigations, and Android APK analysis for threat attribution.
$ cat education.cfg
03 / 08
M.Sc.CGPA 7.4 · 2026

Cybersecurity & Digital Forensics

Rashtriya Raksha University · Gandhinagar

Specialized postgraduate program in offensive security, digital forensics, and critical-infrastructure defense.

B.C.A.CGPA 7.5 · 2024

Bachelor of Computer Applications

K.B.P. Hinduja College of Commerce · Mumbai

Foundations in computing, programming, and information systems — the launchpad into security.

$ ls -la ~/projects/
04 / 08
PROJ_01TOOL
VulnScan
Web & Network Vulnerability Scanner + POC Generator

Automated network vulnerability scanner with severity classification, POC generation, and a GUI + CLI dashboard for real-time monitoring.

Generates HTML/CSV reports with detailed evidence — detected 30+ vulnerabilities across test environments, used as real client deliverables.

PythonNmap NSECustomTkinterYAML
PROJ_02OFFENSIVE
ReconVAPT
VAPT & Reconnaissance Framework

Modular framework automating end-to-end recon, scanning & exploitation; integrates 10+ tools for SQLi, XSS, SSRF, and LFI/RFI detection.

AI-based CVE and tech-stack detection with automated subdomain/directory enumeration, drastically reducing manual recon time.

PythonNucleiSQLMapDalfoxSubfinderAmassFFUF
PROJ_03DEFENSIVE
Endpoint Intruder Detection
Tamper-proof Unauthorized-Access Capture System

Captures webcam images of unauthorized access attempts and emails the evidence automatically — works in online & offline/isolated environments.

PowerShellWebcam AutomationSMTPTask Scheduler
$ ./list --skills --tools
05 / 08

offensive_security

VAPTRed TeamingWebNetwork Active DirectoryAndroidOSINT

techniques

XSSIDORSQLiSSRFCORS Auth BypassMITRE ATT&CKNetwork EnumAD AttacksMobile Security

tools

Burp SuiteNmapMetasploitNucleiMimikatz BloodHoundImpacketMobSFFridaHydraCellebrite UFED

reporting_and_platforms

VAPT ReportsExecutive SummariesSOP Development Risk RatingRemediation DocsLinuxWindowsPython
$ cat certifications/*
06 / 08
2026CRTS v2Cyberwarfare Labs
2026CEH v13EC-Council
2025CRTACyberwarfare Labs
2025ADRTSCyberwarfare Labs
2025ISO/IEC 27001 LAMastermind
2025CNSPSecOps
2025Cyber EssentialsCisco NetAcad
2024Digital ForensicsEC-Council
$ git log --achievements
07 / 08
Training Assistant — NCIIPC SecEx 2025

Supported national cyber exercises for critical infrastructure (RRU–NCIIPC, Apr 2025); assisted Blue Team training.

Blue Team Assistant — Joint NSCS–ISRO–RRU Cyber Defense Program

Supported hands-on defense operations for 40 ISRO/DOS scientists (Sep 2025).

CTF Trainer — Cyber Commando Training Program, RRU

Delivered practical CTF & defensive cyber exercises for 30 Cyber Commandos (Jan 2025).

High-Severity Vulnerability — Cybersec Expo India

Reported a high-severity vulnerability; received recognition and an exclusive delegate invitation.

Responsible Disclosure — HackwithIndia Bug Bounty

Recognized for responsible vulnerability disclosure during the competition.

AI Treasure Hunt CTF — Finalist

School of IT, AI & Cybersecurity, Rashtriya Raksha University.

$ ./connect --secure
08 / 08
eternalsec:~$ whoami --contact
> Let's secure something together.

Open to roles in offensive security, VAPT, red teaming, and forensics. Ping me on any channel — encrypted or otherwise.

status: ● ONLINE — Mumbai, IN
response_time: < 24h