Boutique offensive security · Operating worldwide from India

We break your product the way a real attacker would.

Abhinav Cybersecurity is a manual-first penetration testing studio. No scanner dumps, no checkbox reports — just exploited, chained, business-impacting vulnerabilities, written up so your engineers can fix them on Monday.

Led by Abhinav Kumar — ranked #3 in India and #24 worldwide on the HackerOne Q3 leaderboard, winner of all four HackerOne India regional live hacking events, a U.S. Department of Defense Most Valuable Researcher of the Month, and credited in CVE-2023-22798.

NDA signed before scope is discussed · Fixed price · Free retest included

Illustrative summary. Every finding ships with reproducible PoC steps, CVSS v3.1 scoring and a remediation path.

#3 in India · #24 worldwide
HackerOne Q3 leaderboard
98 vulnerabilities found & resolved
verified on HackerOne
96 organisations have credited us
coordinated disclosure
96th percentile for real-world impact
platform-wide ranking

Vulnerabilities we found were fixed by

Organisations that have fixed vulnerabilities reported by Abhinav Cybersecurity: U.S. Dept of Defense, Adobe, Shopify, PlayStation, GitLab, Slack, Sony, Booking.com, Epic Games, Marriott, Twilio, Grab, Ubiquiti, Brave, Anthropic, Amazon, Microsoft, Instacart, Audible, Zomato, Flipkart, Meesho, Temu, OPPO, Logitech, Elastic, Netlify, Tinder, Nextcloud, DataStax, Freshworks, HackerOne.

Recognition earned through bug bounty and coordinated vulnerability disclosure programmes — a hall-of-fame record, not a client list, and not an endorsement by these organisations. All names and marks belong to their respective owners. Client names are confidential.

What we do

Security testing, end to end.

Every engagement is executed by hand. Automation is used to widen coverage — never to produce the findings.

Web Application Penetration Testing

Authentication and session logic, access control across tenants and roles, business-logic abuse, injection, SSRF, file handling and the chains between them.

  • OWASP Top 10
  • Multi-tenant IDOR
  • Business logic

API & GraphQL Security

REST, GraphQL and gRPC surfaces tested against the spec and against reality: broken object-level authorisation, mass assignment, introspection leakage, rate-limit and quota bypass.

  • OWASP API Top 10
  • BOLA / BFLA
  • Schema abuse

Mobile Application Testing

Android and iOS binaries reverse-engineered and instrumented: insecure storage, certificate pinning bypass, deep-link hijacking, hardcoded secrets and the backend they talk to.

  • OWASP MASVS
  • Frida / runtime
  • Deep links

Cloud & Infrastructure Review

AWS, GCP and Azure configuration reviewed against attacker goals: IAM privilege escalation paths, exposed storage, metadata-service reachability, network segmentation and key sprawl.

  • IAM privesc
  • CIS benchmarks
  • SSRF → IMDS

Red Team & Adversary Simulation

Goal-driven, multi-vector operations against your real defences — external foothold, phishing with prior written consent, lateral movement and a defined objective such as customer data access.

  • MITRE ATT&CK
  • Purple team option
  • Detection gaps

Secure Source Code Review

Manual review of the code paths that matter — authentication, authorisation, cryptography, deserialisation and data access — with findings traced from source to sink and back to a request.

  • Source-to-sink
  • Authz matrices
  • Crypto misuse

Compliance-Ready Pentests

Assessments scoped and documented for SOC 2, ISO 27001, PCI-DSS and enterprise security reviews — delivered with a formal attestation letter your auditor and your customers will accept.

  • SOC 2 · ISO 27001
  • PCI-DSS 11.4
  • Attestation letter

Bug Bounty & VDP Advisory

Launch a programme that attracts good researchers instead of noise: scope design, severity and reward tables, safe-harbour policy, triage workflow and internal SLAs — built by someone on the other side of it.

  • Scope & policy
  • Reward tables
  • Triage support

Why us

Most reports are noise. Ours are exploits.

The bug bounty market is brutally honest: you are paid only for vulnerabilities that are real, novel and impactful — after every scanner and every previous tester has already been through the target. That is the standard we bring to paid engagements.

Start a conversation
  • 01

    Attacker methodology, not a checklist

    We hunt the same way we hunt bounties: map the real attack surface, understand the business, then chain the medium-severity findings everyone else closed as informational into something that actually hurts.

  • 02

    Zero-fluff reporting

    No 300-page scanner export padded with TLS warnings. Every finding has reproducible steps, a working proof of concept, a CVSS v3.1 vector, real business impact and a concrete fix.

  • 03

    You work with the person testing you

    No sales engineer handing you to a junior. The founder runs the scoping call, does the testing, writes the report and joins the debrief with your engineers.

  • 04

    Proven against the hardest targets

    Vulnerabilities accepted and fixed by the U.S. Department of Defense, Adobe, Shopify, GitLab, PlayStation and Sony — organisations with mature internal security teams and years of prior testing.

  • 05

    Fixed price. Free retest.

    You get the number before we start, and it does not move. One full retest within 90 days is included, with a reissued report marking every fix as verified.

How we work

A six-stage engagement.

Predictable process, transparent timeline, no surprises on the invoice.

  1. 01

    Scoping & rules of engagement

    NDA first. Then a call to understand your architecture, threat model and what would genuinely hurt your business. You receive a written scope, testing window, escalation contacts and a fixed price.

    Output: signed SOW + rules of engagement
  2. 02

    Reconnaissance & attack-surface mapping

    Every subdomain, endpoint, parameter, role, tenant and third-party integration in scope is enumerated and catalogued — including the forgotten staging host nobody remembered owning.

    Output: attack-surface inventory
  3. 03

    Threat modelling

    We define what an attacker wants from you — customer PII, funds movement, tenant isolation, admin control — and build test cases backwards from those objectives instead of down a generic list.

    Output: prioritised attack scenarios
  4. 04

    Manual exploitation

    The core of the engagement. Findings are proven, not theorised, then chained to establish maximum realistic impact. Critical issues are reported to you the same day, before the report exists.

    Output: same-day critical alerts
  5. 05

    Reporting & debrief

    An executive summary written for leadership and a technical report written for engineers, followed by a live walkthrough where your team can ask questions and challenge severity ratings.

    Output: full report + debrief call
  6. 06

    Retest & attestation

    Once you have shipped fixes, every finding is retested free of charge within 90 days. The report is reissued with verified-fixed status and a signed attestation letter for auditors and customers.

    Output: attestation letter

Every engagement ships with

  • Executive summary for non-technical stakeholders
  • Technical report with reproducible PoC for every finding
  • CVSS v3.1 vectors and business-impact narrative
  • Prioritised, concrete remediation guidance
  • Same-day alerting on critical findings
  • Live debrief with your engineering team
  • Free retest within 90 days
  • Signed attestation letter for auditors & customers

Track record

Publicly verifiable, not marketing.

Every number below can be checked on the public HackerOne profile — no self-reported metrics.

Live hacking events

🏆 4× regional winner

Winner of all four HackerOne India regional live hacking events — North, South, East and West. The India South event alone returned $9,500+ of its total bounty pool; the India North event was run against Epic Games. Also first place at the Zomato Live Hacking Event, a top earner at the HackerOne In-Person Meetup 2.0 in Pune ($7,154), and a 2023 Ambassador World Cup participant.

Leaderboard

#3 India

#24 worldwide on the HackerOne Q3 Cyber Security Leaderboard. Previously top 50 in India for Q1.

Published vulnerability

CVE-2023-22798

Open-redirect exposure in Brave's debouncing adblock rules, which stripped security-relevant redirect interceptors on third-party sites. CWE-601, CVSS 6.1.

Volume & consistency

98 resolved

98 vulnerabilities triaged, accepted and fixed. 100+ bounties awarded across 96 different organisations since December 2021.

Signal quality

96th percentile

96th percentile for impact platform-wide — a measure of how severe accepted findings are, not how many were submitted. 4,394 reputation.

Government recognition

DoD MVR

Named a Most Valuable Researcher of the Month by the U.S. Department of Defense for vulnerabilities reported through its Vulnerability Disclosure Program.

Microsoft MSRC

Top 100 global

Listed on the Microsoft Security Response Center 2025 Most Valuable Security Researcher leaderboard (July 2024 – June 2025), and ranked #25 on the 2024 Q4 researcher leaderboard.

Selected findings disclosed publicly by the researcher; targets remain confidential

Critical 10.0

JWT signature bypass via alg:none

Legacy verification path accepted unsigned tokens, allowing authentication as any user on a heavily tested target.

$3,000
High

Mass PII disclosure

Found by revisiting a previously closed report and bypassing the original fix — bulk personal data exposed in clear text.

$6,000
High 7.1

Cross-tenant IDOR

Object-level authorisation flaw permitting access to records belonging to other customer tenants.

$2,500
High

SQL injection → clear-text PII

Rated above a parallel IDOR because the exposed data was unhashed, materially raising real-world impact.

$3,000 + $1,342

Public HackerOne metrics for hackerone.com/kalkii, verified August 2026. Bounty figures are as publicly disclosed by the researcher.

Abhinav Kumar

Founder & Principal Security Researcher

@kalkii · Patna, Bihar, India

  • Rank#3 India · #24 worldwide
  • Live event wins4× India regional
  • Active sinceDecember 2021
  • Reports resolved98
  • Organisations96
  • CertificationeJPT (INE), 2024–27
  • CVECVE-2023-22798

The person behind the work

Medical school dropout. Full-time adversary.

Abhinav left medical entrance preparation to pursue security full time — a decision that looked reckless right up until the reports started getting paid. Since December 2021 he has worked as an independent security researcher, reporting vulnerabilities to organisations ranging from the U.S. Department of Defense to Shopify, Adobe, GitLab, PlayStation and Sony.

That work has produced 98 resolved vulnerabilities across 96 organisations, over 100 paid bounties, a published CVE in the Brave browser, and a clean sweep of the HackerOne India live hacking circuit — first place at the North, South, East and West regional events, plus the Zomato Live Hacking Event. The U.S. Department of Defense has named him a Most Valuable Researcher of the Month, and Microsoft listed him among its top 100 researchers worldwide for 2025. On the most recent quarterly leaderboard he ranked #3 in India and #24 worldwide.

Abhinav Cybersecurity exists to bring that methodology to companies directly — the same adversarial testing, on your schedule, under NDA, with a report your engineers can act on.

Recognition on HackerOne

  • 🏆 4× India regional LHE winner
  • 🛡️ U.S. DoD Most Valuable Researcher
  • 🪟 Microsoft MSRC top 100 (2025)
  • 🥇 Zomato LHE winner
  • 🏅 Bounty Hunter — 100 bounties
  • 🎯 Belle of the Ball — top-ranked Hacktivity report
  • 🛡️ Hacked HackerOne itself
  • 🌍 Diversity — 20+ programmes
  • 🧬 Insecticide — 50 resolved
  • 🚩 TrailBlazer — first reporter
  • 🏆 Ambassador World Cup 2023
  • 📈 Community Milestone L1–L3

Vulnerability classes with verified findings

  • Broken Access Control
  • Broken Authentication
  • Injection / SQLi
  • Sensitive Data Exposure
  • Cross-Site Scripting
  • Business Logic Abuse

Engagement models

Pick the depth you need.

Every model is fixed-price and quoted after a free scoping call. No hourly billing, no scope creep.

Focused Assessment

For a single application, API or new feature release.

3–5 working days of testing

  • One application or API surface
  • Authenticated testing, up to 2 roles
  • Full technical report + exec summary
  • Free retest within 90 days
  • Attestation letter
Request a quote

Continuous Security Partner

For teams shipping weekly who need testing that keeps up.

Retained, monthly

  • Recurring testing cycles per release
  • Bug bounty / VDP programme management
  • Triage support & severity validation
  • Direct Slack or email access
  • Quarterly attestation letters
Talk to us

FAQ

Questions we get asked first.

How long does a penetration test take?

Most web or mobile application tests run 5 to 15 working days of active testing, plus 2 to 3 days for reporting. Scope determines the number — and you get the timeline and the price in writing before anything begins.

What do I actually receive at the end?

An executive summary for leadership, a full technical report with reproducible proof-of-concept steps and CVSS v3.1 ratings for every finding, prioritised remediation guidance, a live debrief with your engineers, a free retest of every fix, and a signed attestation letter you can hand to auditors and customers.

Is the retest included, or extra?

Included. One full retest of all findings within 90 days of report delivery, at no additional cost. The report is reissued with each fixed issue marked verified.

Will this satisfy our SOC 2, ISO 27001 or PCI-DSS auditor?

Yes. Engagements are scoped and documented to meet SOC 2, ISO 27001, PCI-DSS and enterprise vendor-security requirements, and you receive a formal attestation letter stating scope, methodology, dates and outcome.

Do you sign NDAs?

Always — before any scope details are exchanged. We work under your NDA or ours. All findings, credentials and collected data are destroyed on request at the end of the engagement.

Can you test production without breaking it?

Yes. Rules of engagement are agreed in writing first: testing windows, request rate limits, forbidden actions, emergency contacts and a kill-switch. Destructive or denial-of-service testing is never performed without explicit written approval.

What do you need from us to start?

A signed NDA and SOW, a list of in-scope hosts and applications, test accounts for each user role, and a technical point of contact. Architecture diagrams and prior reports help but are not required.

Do you work with startups?

Yes — a large share of our work is seed to Series B companies facing their first enterprise security review. The Focused Assessment tier exists precisely for that moment.

Get started

Find out what an attacker would find.

Tell us what you have built. You will get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will actually do the testing.

Your message opens in your mail client — nothing is stored on this site.