Skip to content
View Chetan-Biranje's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Chetan-Biranje

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
chetan-biranje/README.md

LinkedIn HackerOne TryHackMe Portfolio Medium


┌──(shadex㉿kali)-[~/]
└─$ whoami

  > DevSecOps Engineer — securing code from commit to production
  > AppSec Researcher — Web/API/Android VAPT | OWASP Top 10
  > Bug Bounty Hunter — HackerOne · Bugcrowd · Intigriti
  > Acknowledged finding: WAF Bypass (Meesho Security Team)
  > Currently: Bug Bounty Hunter — HackerOne · Bugcrowd · Intigriti  | Pune, India

└─$ cat /etc/skills

  OFFENSIVE   → Web VAPT, API VAPT, Android VAPT, IDOR, SSRF,
                JWT Attacks, WAF Bypass, Auth Bypass, SQLi, XSS
  DEVSECOPS   → GitHub Actions, Semgrep, Bandit, Trivy, Gitleaks,
                OWASP ZAP, pip-audit, Docker, Kubernetes
  CLOUD/IAC   → AWS (EKS, IAM, S3), Terraform, Ansible, CIS Benchmarks
  TOOLS       → Burp Suite Pro, Nuclei, ffuf, Nmap, MobSF, Frida, JADX

🔴 Bug Bounty

Program Platform Finding Status
Meesho / Valmo HackerOne WAF Bypass — staging.valmo.in ✅ Acknowledged
DoorDash HackerOne Active Recon 🔍 In Progress
Flipkart / Myntra Bugcrowd API Recon 🔍 In Progress
Robinhood Bugcrowd Active Recon 🔍 In Progress
Platacard Intigriti Active Recon 🔍 In Progress

🛠 Featured Projects

🔒 DevSecOps Learning Lab

Flask + GitHub Actions + EKS + Terraform + Ansible
8-stage CI/CD: SAST → SCA → Secrets → DAST
→ Container scan → IaC scan → CIS L2 hardening

🔍 Security Recon Toolkit

Python 3.10+ | Subfinder | ffuf | Nuclei
7 modules: subdomain enum, JS secrets,
directory fuzzing, CVE lookup, HTML reports

🐍 PySecUtils

Python | AES-256-GCM | JWT | PyPI-ready
17 security classes | 40+ unit tests
Crypto, JWT handling, payload generation

⚙️ Secure CI/CD Pipeline

GitHub Actions | Bandit | Semgrep
Gitleaks | detect-secrets
Least-privilege gates blocking insecure builds

⚔️ Skills

Burp Suite OWASP AWS Kubernetes Terraform Docker Python GitHub Actions Semgrep Kali Linux


Popular repositories Loading

  1. web-rest-api-pentest-research web-rest-api-pentest-research Public

    Web and REST API penetration testing research and techniques

    2

  2. burp-extensions-lab burp-extensions-lab Public

    Burp Suite extension development lab and examples

    Python 2

  3. chetan-biranje chetan-biranje Public template

    Personal portfolio and profile repository

    HTML 1

  4. secure-pipeline secure-pipeline Public

    Python 1 1

  5. Java_Journey Java_Journey Public

    Forked from ntsvg/Java_Journey

    Java programming learning journey and practice projects

    Java 1

  6. 90-Days-Plan 90-Days-Plan Public

    90-day intensive learning and skill development roadmap

    1