fir3fly.com

Shalabh Devliyal

Security Researcher

Breaking to Secure. Security Researcher specializing in attack surface management, digital risk protection, web application security, vulnerability assessment, and penetration testing.

Press Ctrl+K to open command palette.

operator@fir3fly
fir3fly terminal v1.0
Type `help` to explore.
fir3fly$

About

Security research with operational context.

Focused on finding real exposure, explaining impact clearly, and helping teams close risk without theatre.

Security Researcher specializing in attack surface management, digital risk protection, web application security, vulnerability assessment, and penetration testing.

Shalabh works across attack surface management, digital risk protection, manual security testing, and client advisory. The emphasis is practical: identify what is exposed, validate what matters, and communicate remediation in a way engineering teams can act on.

Achievements

HackTheBox Pro Hacker
Best Global Rank #393
TryHackMe Top 5%

Expertise

Core security domains.

Attack Surface Management

Mapping exposed assets, prioritizing risk, and helping teams reduce internet-facing security drift.

Digital Risk Protection

Monitoring brand, domain, credential, and shadow exposure signals before they become incidents.

Web Application Security

Manual testing for authentication, authorization, business logic, API, and client-side flaws.

Vulnerability Assessment

Clear triage, reproduction, impact analysis, and remediation guidance for exploitable weaknesses.

Penetration Testing

Focused adversarial testing with professional reporting and pragmatic client advisory.

Experience

Professional work.

Security Researcher

Security Brigade

September 2024 - Present
Attack Surface Management
Manual Security Testing
Client Security Advisory
Digital Risk Protection
Managed Security Services

Projects

Research-driven builds.

Portfolio-ready examples of how security work is systematized into repeatable workflows.

External Exposure Monitor

A workflow for finding newly exposed assets, risky services, stale DNS, and misconfigured cloud endpoints.

ASMReconRisk Scoring

Web App Test Playbooks

Reusable methodology notes for authentication, authorization, input handling, session, and API testing.

AppSecManual TestingOWASP

Digital Risk Watchlist

Structured monitoring for brand impersonation, credential exposure, lookalike domains, and public leaks.

DRPThreat IntelMonitoring

Security Dashboard

Operational research surface.

A compact dashboard view of the security disciplines behind the portfolio.

fir3fly telemetry
Live placeholders
24/7

Attack Surface Management

Continuous discovery and exposure tracking across public assets.

CVSS

Vulnerability Research

Reproduction-first analysis with clean impact narratives.

Signals

Digital Risk Protection

Brand, credential, domain, and leak intelligence workflows.

Intel

Threat Intelligence

Contextual enrichment for real-world attacker behavior.

OWASP

Web Security

Manual assessment for app, API, auth, and logic vulnerabilities.

Certifications

Validated fundamentals.

Certified AppSec Practitioner

The SecOps Group

Digital Forensics Essentials

EC-Council

Cybersecurity Essentials

Cisco

Contact

Security conversations, clearly scoped.

Available for security research collaboration, advisory work, and practical application security discussions.

Reach out for attack surface management, digital risk protection, web application testing, or vulnerability assessment engagements.

contact@fir3fly.com