HI, I'M PARTHA

Partha Bishwas – Offensive Application Security Engineer

Offensive Application Security Engineer

  • 10+ Years
  • 200+ Apps Tested
  • 100+ Criticals Found
  • Banking, FinTech, Govt, Telecom

Offensive security professional specializing in mobile, API, and web application security. Experienced in conducting full-scope VAPT, business logic testing, and secure architecture reviews for financial and enterprise systems. Passionate about breaking complex systems responsibly and strengthening security before attackers do.

Partha Bishwas holographic cybersecurity avatar

Skills

SKILLS
Business Logic Testing 90%
API Security 86%
AI-Augmented Testing 85%
Network Security 80%
Reverse Engineering 78%
Malware Analysis 74%

Achievements

ACHIEVEMENTS
COORDINATED DISCLOSURE CHANNELS
Secure uplink required
Awaiting secure handshake...

Capabilities

CAPABILITIES
OFFENSIVE SECURITY WORKS
ACTIVE MODULES
Awaiting secure handshake...
WEB
APPLICATION
VAPT
MOBILE
APPLICATION
VAPT
AI-AUGMENTED
OFFENSIVE
TESTING
API
SECURITY
ASSESSMENT
BUG BOUNTY
&
DISCLOSURE

Field Reports

FIELD REPORTS
OPERATIONS LOG
Career track · selected engagements, identities withheld under NDA
Decrypting case files...
  1. 2017 –Bug Bounty HunterPrivate & Public Programs
  2. 2018 – 2019Cyber Security ResearcherOrangeBD
  3. 2018 – 2021Founder & CTOInnerLoop
  4. 2021 – 2025Cyber Security EngineerDotlines Bangladesh Ltd.
  5. 2025 –Senior Security EngineerBRAC IT Services Ltd.
CEH v11 · EC-Council M.Sc. Computer Science · Jahangirnagar University B.Sc. CSE · BUBT
Enterprise · ERP 2022

Employee records service

Findings
Actuator exposedPermissive CORSVerbose errorsBOLA refuted
Impact
Runtime detail leaked; a suspected mass-authorization gap was tested and refuted.
Outcome
Hygiene defects fixed; access-control model confirmed sound.
Misconfiguration HIGH
Public Sector · Admissions 2023

Admission & payment portal

Findings
LFI → RCEUnauth SQLiPayment IDORExposed gateway keys
Impact
Server compromise and applicant data exposure; a prior third-party breach surfaced.
Outcome
Coordinated disclosure with remediation guidance.
Injection · IDOR CRITICAL
FinTech · Payroll 2024

Payroll & HR platform

Findings
Disbursement raceSoD collapseApproval fail-openCross-module BOLA
Impact
Duplicate bank payments and single-actor money movement with no second approver.
Outcome
Money-path controls rebuilt; verified on retest.
Business-logic abuse CRITICAL
Enterprise · Documents 2025

Document management portal

Findings
Vertical priv-escUnauth data breachSSRFDoS cascade
Impact
Read-only user to admin in one call; whole repository readable without login.
Outcome
Server-side authorization enforced; bypass battery passed.
Broken access control CRITICAL

Sanitised to finding class and impact. No client, product, or system identifiers. Full reports available under NDA.

Arsenal

ARSENAL
PUBLIC TOOLING
Built from knowing what attackers leave behind
Repository online

Vestigium

v2.0.0 MIT CI passing

Cross-platform live-response evidence collection for Linux and Windows.

Turns a live endpoint into a self-verifying evidence package: a timestamped evidence tree, provenance for every copied file, a SHA256 inventory, a JSON manifest, and one archive with its own hash sidecar. YARA scanning and offline IOC matching produce a single severity-ranked findings report for both platforms. Nothing is installed on the host, and nothing leaves it.

  • Linux · Windows
  • Bash · PowerShell
  • 19 + 17 collection modules
  • YARA + IOC matching
  • Order of volatility
  • Air-gap ready
  • Anti-tamper verify
# stage once, on a machine with internet
$ git clone https://github.com/parthabishwas/vestigium.git
$ sudo ./vestigium.sh setup

# on the host under investigation
$ sudo ./vestigium.sh --case-id IR-2026-014 --output /media/evidence
$ ./vestigium.sh verify /media/evidence/<host>_<ts>.tar.zst
github.com/parthabishwas/vestigium