Devanshu Bansode
Bridging the gap between development and security. I specialize in identifying vulnerabilities, building secure architectures, and advancing product security.
About Me
01. Who I Am
I am a third-year CSE (IoT & Cybersecurity) student at SIES GST with a relentless passion for breaking things to secure them. My foundation bridges software engineering and offensive security, giving me a unique perspective on secure application development.
02. What I Do
I specialize in Web Application Penetration Testing (VAPT), API security, and mobile security testing. With hands-on industry experience across real-world client applications, I excel at identifying, validating, and reporting vulnerabilities like SQLi, XSS, and IDOR through structured engagements.
03. Current Focus
- Preparing for the Practical Junior Penetration Tester (PJPT)
- Active Bug Bounty hunting on global platforms
- Researching AI vulnerabilities and prompt injection
04. Career Goal
My objective is to join a world-class security team as an Application Security Engineer, helping organizations build resilient products while continuing to contribute to the global cybersecurity community.
How I Approach Security
A structured, methodical approach to Vulnerability Assessment and Penetration Testing (VAPT) ensures comprehensive coverage and actionable results.
Reconnaissance
OSINT, attack surface mapping, discovering subdomains and endpoints.
Enumeration
Active scanning, identifying services, and mapping application logic.
Validation
Confirming potential vulnerabilities to eliminate false positives.
Exploitation
Ethical extraction of proof-of-concepts to demonstrate impact.
Risk Analysis
Assessing business impact, data exposure, and lateral movement potential.
CVSS Scoring
Standardized quantitative scoring based on severity metrics.
Reporting
Clear, actionable reports with reproduction steps and evidence.
Remediation
Re-testing patches to ensure vulnerabilities are fully resolved.
Experience
Key Responsibilities
- Assisted in security assessments and vulnerability analysis for internal and client applications.
- Contributed to the design and implementation of a VPN-based secure access solution using Twingate, including setup, CLI configuration, and access control management.
- Investigated attack vectors, analyzed security findings, and documented technical observations to support internal security reviews.
Key Impact
Successfully deployed a secure access solution and improved internal security posture through structured documentation of threat vectors.
Key Learnings
Gained practical insight into secure infrastructure design, enterprise VPN deployment, and analyzing real-world security findings in a corporate environment.
Technologies Used
Key Responsibilities
- Performed web, mobile, and API penetration testing on real-world client applications using Burp Suite, Postman, MobSF, SQLmap, and OWASP ZAP.
- Identified, validated, and documented vulnerabilities including SQL Injection, Cross-Site Scripting (XSS), IDOR, authentication flaws, and business logic vulnerabilities.
- Executed structured VAPT engagements covering reconnaissance, exploitation, vulnerability validation, CVSS-based reporting, and remediation verification.
Key Impact
Secured critical client infrastructure by proactively discovering and validating high-risk vulnerabilities before they could be exploited.
Key Learnings
Mastered end-to-end VAPT methodologies, from initial reconnaissance to standardized CVSS-based vulnerability reporting for high-severity logic flaws.
Technologies Used
Key Responsibilities
- Completed structured training aligned with the CompTIA Security+ (SY0-701) curriculum, covering Windows security, threat landscape, malware analysis, and social engineering.
- Performed hands-on labs focused on attack vectors, Indicators of Compromise (IoCs), threat actor behavior, and defensive security concepts.
- Built foundational knowledge in system hardening, Windows security, and security operations.
Key Impact
Strengthened foundational security knowledge to bridge the gap between offensive testing and defensive architectural hardening.
Key Learnings
Developed a strong defensive mindset, understanding threat actor behaviors, IoCs, and fundamental SOC operations.
Technologies Used
Key Responsibilities
- Organized cybersecurity workshops, awareness sessions, and hands-on Capture The Flag (CTF) events for students.
- Delivered sessions on web application security, practical attack demonstrations, and CTF fundamentals.
- Coordinated technical execution and participant support during cybersecurity competitions.
Key Impact
Successfully scaled campus cybersecurity awareness and engagement through well-executed CTF events and practical workshops.
Key Learnings
Enhanced technical communication and leadership skills by distilling complex attack demonstrations for broader student audiences.
Technologies Used
Key Responsibilities
- Designed and developed web security challenges for an intercollegiate Capture The Flag competition.
- Conducted cybersecurity workshops covering web application vulnerabilities and practical attack techniques.
- Assisted in deployment, technical coordination, and execution of the competition.
Key Impact
Provided practical, competitive learning environments that tested participants' analytical reasoning and exploitation skills.
Key Learnings
Gained hands-on experience in challenge infrastructure deployment and engineering intentionally vulnerable applications.
Technologies Used
Projects
AnomalyX
Network Intrusion Detection & Analyst Dashboard
A SOC-style Network Intrusion Detection Dashboard using a Random Forest–based detection engine to classify network traffic and provide interactive analyst dashboards.
CICADA 3301
CTF Challenge Development
Designed and developed 5 web security challenges covering SQL Injection, XSS, IDOR, authentication bypass, and business logic vulnerabilities.
X'Ploitathon 2025 CTF
Intercollegiate Capture The Flag
Developed 9+ web security challenges for an intercollegiate Capture The Flag competition organized by the OWASP Student Chapter and PODS Technology Solutions.
Wi-Patrol
WiFi Intrusion Detection System
Led a 4-member team to develop an ESP32 + Python-based Wi-Fi intrusion detection system for identifying rogue wireless devices through real-time scanning.
Encrypter
Flask-based Encryption Tool
Led a 4-member team to develop a Flask-based encryption and data transformation platform with authentication, secure file uploads, and MySQL-backed operation history.
Password Vault
Encrypted Credential Manager
Developed a Python-based password manager featuring AES encryption, secure authentication, password generation, and an intuitive Tkinter desktop interface.
Skills & Security Toolkit
Security Toolkit by Workflow
Reconnaissance
- Nmap
- Gobuster
- Sublist3r
- OSINT Framework
Testing & Exploitation
- Burp Suite
- Metasploit
- SQLmap
- OWASP ZAP
- Hydra
- Aircrack-ng
Analysis & Reporting
- Wireshark
- Scapy
- Markdown
- LaTeX
Development
- Python Scripts
- Flask
- Arduino IDE
Technical Proficiency
Programming
Application Security
Networking
Operating Systems
Databases
Cloud & Infra
Achievements & Impact
Top 25 Finalist (Team CODEXA)
SAMVED Smart Governance Hackathon 2026
Secured Top 25 out of 509 teams nationwide for developing Sanrakshak Sentinel Hub, an IoT-based safety solution for sanitation workers.
1st Place Winner (Rank 1)
SwapITLab CTF 2025
Secured the absolute top position by successfully exploiting complex vulnerabilities and demonstrating advanced offensive security skills.
Top 10% Rank (138/1527)
MetaCTF Flash CTF
Competed globally against 1,500+ participants, solving advanced web, cryptography, and forensics challenges.
1st Place Winner
CSI Cybersecurity Workshop CTF
Secured the top position by successfully exploiting web vulnerabilities and solving reverse engineering challenges under strict time constraints.
Certifications
Bug Bounty & Web Security Testing
zSecurity
Advanced techniques in web application hacking, finding and exploiting bugs in real-world scenarios.
Detect & Defend
Secured Bharat
Hands-on exposure to basic digital forensics, threat identification, and evidence analysis.
Learn Ethical Hacking From Scratch
zSecurity
Comprehensive foundation in ethical hacking, network scanning, exploitation, and wireless attacks.
Ethical Hacking [SDP]
SIES GST
Core networking and web security basics with TryHackMe labs and Burp Suite practicals.
Community & Leadership
I strongly believe in giving back to the cybersecurity community. Sharing knowledge and building challenges helps both the community and my own understanding grow.
GDG On Campus
Cybersecurity Co-ordinator
Leading a community of students passionate about security. Organizing events and workshops to foster a culture of secure development.
CTF Development
Challenge Creator
Designing real-world inspired Capture The Flag challenges to provide practical, hands-on vulnerability exploitation experience.
Security Workshops
Speaker & Organizer
Delivering technical sessions on Web Security, OWASP Top 10, and penetration testing methodologies to engineering students.
Global Security Community
Active Member
Engaging with global cybersecurity communities, participating in bug bounties, and staying updated with the latest threat landscapes.