Attack Surface Management
Mapping exposed assets, prioritizing risk, and helping teams reduce internet-facing security drift.
Security Researcher
Breaking to Secure. Security Researcher specializing in attack surface management, digital risk protection, web application security, vulnerability assessment, and penetration testing.
Press Ctrl+K to open command palette.
About
Focused on finding real exposure, explaining impact clearly, and helping teams close risk without theatre.
Security Researcher specializing in attack surface management, digital risk protection, web application security, vulnerability assessment, and penetration testing.
Shalabh works across attack surface management, digital risk protection, manual security testing, and client advisory. The emphasis is practical: identify what is exposed, validate what matters, and communicate remediation in a way engineering teams can act on.
Achievements
Expertise
Mapping exposed assets, prioritizing risk, and helping teams reduce internet-facing security drift.
Monitoring brand, domain, credential, and shadow exposure signals before they become incidents.
Manual testing for authentication, authorization, business logic, API, and client-side flaws.
Clear triage, reproduction, impact analysis, and remediation guidance for exploitable weaknesses.
Focused adversarial testing with professional reporting and pragmatic client advisory.
Experience
Security Brigade
Projects
Portfolio-ready examples of how security work is systematized into repeatable workflows.
A workflow for finding newly exposed assets, risky services, stale DNS, and misconfigured cloud endpoints.
Reusable methodology notes for authentication, authorization, input handling, session, and API testing.
Structured monitoring for brand impersonation, credential exposure, lookalike domains, and public leaks.
Security Dashboard
A compact dashboard view of the security disciplines behind the portfolio.
Continuous discovery and exposure tracking across public assets.
Reproduction-first analysis with clean impact narratives.
Brand, credential, domain, and leak intelligence workflows.
Contextual enrichment for real-world attacker behavior.
Manual assessment for app, API, auth, and logic vulnerabilities.
Research
Professional security writeups, methodology notes, and research briefs.
1 min read
A practical approach to identifying, validating, and communicating public exposure.
1 min read
How to separate useful external risk signals from noisy monitoring feeds.
1 min read
A concise web application testing checklist focused on authentication, authorization, APIs, and logic flaws.
Certifications
The SecOps Group
EC-Council
Cisco
Contact
Available for security research collaboration, advisory work, and practical application security discussions.