--:--

sky — security engineer · bug hunter · writer

Breaking & exploting the modern web.

I'm a security engineer who finds vulnerabilities in modern web applications, builds tooling to automate the boring parts, and writes my bugs somethimes in free time.

now breaking — APIsAuth flowsCloud misconfigs

found bugs in · 15 platforms

01

Writeups

/ recent posts
02

Pentesting Services

/ break it. fix it. secure it.
/ 01 black box

Web Application Pentesting

No source, no docs — we attack it the way bad actors do.

Every vulnerability class reachable from the outside gets tested: authentication & session management, access control & IDOR, injection (SQL, NoSQL, command, SSRF, XXE), file uploads, business logic, rate limiting and misconfigurations — mapped against the OWASP Top 10 & WSTG.

  • Authenticated & unauthenticated testing across every role
  • Web, API & mobile-backed endpoints in scope
  • Manual exploitation of every finding — no scanner-only results
// you provide

Just the application URL and a test account. We handle the rest.

Book a black box engagement
/ 02 white box

Web Application Testing — White Box

We go inside the codebase and hunt what black box can never reach.

Full source review for the flaws that hide in logic: broken authorization & privilege escalation, business-logic bypasses, injection sinks, crypto misuse, hardcoded secrets, dependency & supply-chain risks, and insecure architecture decisions.

  • Line-level findings tied to the exact code
  • Architecture & threat-model review included
  • SAST, dependency scanning & manual deep-dive combined
// you provide

Source code access — plus environment credentials if needed. We map the rest.

Book a white box review
included in both plans

Manual + Automated + AI

Human expertise, tooling and AI-assisted analysis on every engagement.

Detailed report

Comprehensive, prioritized findings with clear, actionable recommendations.

We fix with your team

We sit with your developers and work through remediations — not just a PDF.

Re-testing

We verify every fix actually holds before you call the engagement done.

03

About

/ whoami

Security isn't a checklist — it's a mindset. For 6.5+ years I've been finding the bugs before the bad guys do — so your users never have to.

Hi, I'm Akash — a Senior Product Security Engineer at ConnectWise and a former Cybersecurity Consultant at Ernst & Young, where I helped secure 60+ clients, mostly Nifty 50 companies. Across 160+ bug bounty reports, my findings have been acknowledged by Goldman Sachs, Google, OYOrooms, and Starbucks — and have helped protect the data of 3.2 million users, eight separate times.

From web and mobile apps to APIs and cloud, I hunt what scanners miss and fix what matters. I'm an OSCP, AWS Security Specialty, and CEH certified professional — but the credential I'm most proud of is the trust teams place in me to harden what they've built. If it runs on the internet, I want to make sure it survives it.

Web Pentest Android Pentest Bug Bounty Secure Code Review Cloud Security API Security Threat Modeling Mobile AppSec OSCP AWS Certified CEH
skypentest.typedream.app
Experience
6.5+ years
Bugs reported
160+ (60+ critical/high)
PII protected
3.2M users · 8 leaks
Leaderboard
#1 OYOrooms · 2020–2023
Status
Available
Coffee
Yes. Always.
160+
bugs reported
via real bug bounty programs
60+
critical & high severity
findings on live applications
3.2M
PII records protected
across 8 separate leaks
6.5+
years experience
appsec · VAPT · cloud security
#1
OYOrooms leaderboard
bug bounty · 2020–2023

certifications

OSCP

Offensive Security Certified Professional

Hands-on penetration testing — exploited live machines from zero to root.

OffSec
AWS

AWS Certified Security — Specialty

Designing & hardening cloud architectures against real-world threats.

Amazon Web Services
CEH

Certified Ethical Hacker

A hacker's toolkit, mastered — and used strictly on the right side.

EC-Council
04

Contact

/ say hi

Got a project or application which require pentest?

Security finding, research idea, or just want to trade bug bounty stories — my inbox is open.

pentest@skygroot.com