Skip to content
View dark-warlord14's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report dark-warlord14

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dark-warlord14/README.md

Shantanu Ghumade - security research, AppSec, and AI automation

Shantanu Ghumade

I work in security assurance at Deriv, mostly around AppSec, secure code review, DevSecOps, cloud hardening, and the parts of AI automation that make security work less repetitive.

I like building practical things: archives, dashboards, recon helpers, CVE monitors, and small bits of automation that help engineers spot problems earlier. I also write about the messier parts of security work, where the useful lessons usually hide.

Current Focus

  • Leading security assurance work across application, API, mobile, cloud, and CI/CD surfaces
  • Using AI to speed up AppSec triage, threat intelligence, secure review, and security workflow automation
  • Building security tools that are boring in the best way: reliable, searchable, and useful under pressure
  • Writing public research, field notes, and learning material for people who like taking systems apart

Featured Work

  • SecurityJunky - AppSec, DevSecOps, cloud security, AI automation, and vulnerability research notes.
  • AI Vault - A home for projects, experiments, research, and shipped security-adjacent work.
  • Chromium VRP Archive - A searchable archive of disclosed Chromium VRP reports and bounty metadata.
  • QuiloBook Malware Analysis - A Deriv security writeup co-authored with Deriv's Head of Security on a supply-chain attack delivered through trusted vendor communications.
  • BeaverTail Malware Analysis - A deep dive into a fake recruiter campaign, malicious GitHub repo, and multi-stage payload chain.
  • OSWE Certification Journey - Notes from preparing for and passing OSWE on the first attempt.
  • PolyLens - A sharper workspace for Polymarket discovery and portfolio context.

Tools and Projects

  • CVENotifier - Custom CVE feed notifications for tracked technologies and products.
  • JSScanner - Bash tooling for JavaScript endpoint and secret discovery during recon.
  • ffufplus - Automation around ffuf for content discovery workflows.
  • ZDI Advisories - Searchable Zero Day Initiative advisory dashboard.
  • Unofficial OSWE Exam Notes - Notes and observations from OSWE preparation.

Credentials

  • OSWE, OffSec Web Expert
  • OSCP, OffSec Certified Professional

Elsewhere

GitHub followers LinkedIn Blog

Pinned Loading

  1. JSScanner JSScanner Public

    You can read the writeup on this script here

    Shell 273 64

  2. ffufplus ffufplus Public

    You can read the writeup on this script here

    Shell 191 43

  3. CVENotifier CVENotifier Public

    Customized CVE FEED Notifier

    Go 114 11

  4. CTF-Solutions CTF-Solutions Public

    CTF-Solutions

    EJS

  5. Unofficial-OSWE-Exam-Notes Unofficial-OSWE-Exam-Notes Public

    OSWE Exam Unofficial Format & Hidden Insights

    12 4