Web Application Penetration Testing
Authentication and session logic, access control across tenants and roles, business-logic abuse, injection, SSRF, file handling and the chains between them.
Boutique offensive security · Operating worldwide from India
Abhinav Cybersecurity is a manual-first penetration testing studio. No scanner dumps, no checkbox reports — just exploited, chained, business-impacting vulnerabilities, written up so your engineers can fix them on Monday.
Led by Abhinav Kumar — ranked #3 in India and #24 worldwide on the HackerOne Q3 leaderboard, winner of all four HackerOne India regional live hacking events, a U.S. Department of Defense Most Valuable Researcher of the Month, and credited in CVE-2023-22798.
NDA signed before scope is discussed · Fixed price · Free retest included
$ recon --target app.client.io --deep
[*] 214 endpoints · 38 auth flows · 6 tenants
CRIT IDOR in /v2/orgs/{id}/export
└─ chained → full cross-tenant takeover
HIGH OAuth redirect_uri → account takeover
HIGH GraphQL introspection → 41k PII records
MED JWT alg confusion on legacy endpoint
[+] report delivered · 9 working days
[+] retest: 4/4 fixed · attestation issued
Illustrative summary. Every finding ships with reproducible PoC steps, CVSS v3.1 scoring and a remediation path.
Vulnerabilities we found were fixed by
Organisations that have fixed vulnerabilities reported by Abhinav Cybersecurity: U.S. Dept of Defense, Adobe, Shopify, PlayStation, GitLab, Slack, Sony, Booking.com, Epic Games, Marriott, Twilio, Grab, Ubiquiti, Brave, Anthropic, Amazon, Microsoft, Instacart, Audible, Zomato, Flipkart, Meesho, Temu, OPPO, Logitech, Elastic, Netlify, Tinder, Nextcloud, DataStax, Freshworks, HackerOne.
Recognition earned through bug bounty and coordinated vulnerability disclosure programmes — a hall-of-fame record, not a client list, and not an endorsement by these organisations. All names and marks belong to their respective owners. Client names are confidential.
What we do
Every engagement is executed by hand. Automation is used to widen coverage — never to produce the findings.
Authentication and session logic, access control across tenants and roles, business-logic abuse, injection, SSRF, file handling and the chains between them.
REST, GraphQL and gRPC surfaces tested against the spec and against reality: broken object-level authorisation, mass assignment, introspection leakage, rate-limit and quota bypass.
Android and iOS binaries reverse-engineered and instrumented: insecure storage, certificate pinning bypass, deep-link hijacking, hardcoded secrets and the backend they talk to.
AWS, GCP and Azure configuration reviewed against attacker goals: IAM privilege escalation paths, exposed storage, metadata-service reachability, network segmentation and key sprawl.
Goal-driven, multi-vector operations against your real defences — external foothold, phishing with prior written consent, lateral movement and a defined objective such as customer data access.
Manual review of the code paths that matter — authentication, authorisation, cryptography, deserialisation and data access — with findings traced from source to sink and back to a request.
Assessments scoped and documented for SOC 2, ISO 27001, PCI-DSS and enterprise security reviews — delivered with a formal attestation letter your auditor and your customers will accept.
Launch a programme that attracts good researchers instead of noise: scope design, severity and reward tables, safe-harbour policy, triage workflow and internal SLAs — built by someone on the other side of it.
Why us
The bug bounty market is brutally honest: you are paid only for vulnerabilities that are real, novel and impactful — after every scanner and every previous tester has already been through the target. That is the standard we bring to paid engagements.
Start a conversationWe hunt the same way we hunt bounties: map the real attack surface, understand the business, then chain the medium-severity findings everyone else closed as informational into something that actually hurts.
No 300-page scanner export padded with TLS warnings. Every finding has reproducible steps, a working proof of concept, a CVSS v3.1 vector, real business impact and a concrete fix.
No sales engineer handing you to a junior. The founder runs the scoping call, does the testing, writes the report and joins the debrief with your engineers.
Vulnerabilities accepted and fixed by the U.S. Department of Defense, Adobe, Shopify, GitLab, PlayStation and Sony — organisations with mature internal security teams and years of prior testing.
You get the number before we start, and it does not move. One full retest within 90 days is included, with a reissued report marking every fix as verified.
How we work
Predictable process, transparent timeline, no surprises on the invoice.
NDA first. Then a call to understand your architecture, threat model and what would genuinely hurt your business. You receive a written scope, testing window, escalation contacts and a fixed price.
Output: signed SOW + rules of engagementEvery subdomain, endpoint, parameter, role, tenant and third-party integration in scope is enumerated and catalogued — including the forgotten staging host nobody remembered owning.
Output: attack-surface inventoryWe define what an attacker wants from you — customer PII, funds movement, tenant isolation, admin control — and build test cases backwards from those objectives instead of down a generic list.
Output: prioritised attack scenariosThe core of the engagement. Findings are proven, not theorised, then chained to establish maximum realistic impact. Critical issues are reported to you the same day, before the report exists.
Output: same-day critical alertsAn executive summary written for leadership and a technical report written for engineers, followed by a live walkthrough where your team can ask questions and challenge severity ratings.
Output: full report + debrief callOnce you have shipped fixes, every finding is retested free of charge within 90 days. The report is reissued with verified-fixed status and a signed attestation letter for auditors and customers.
Output: attestation letterTrack record
Every number below can be checked on the public HackerOne profile — no self-reported metrics.
Live hacking events
🏆 4× regional winner
Winner of all four HackerOne India regional live hacking events — North, South, East and West. The India South event alone returned $9,500+ of its total bounty pool; the India North event was run against Epic Games. Also first place at the Zomato Live Hacking Event, a top earner at the HackerOne In-Person Meetup 2.0 in Pune ($7,154), and a 2023 Ambassador World Cup participant.
Leaderboard
#3 India
#24 worldwide on the HackerOne Q3 Cyber Security Leaderboard. Previously top 50 in India for Q1.
Published vulnerability
CVE-2023-22798
Open-redirect exposure in Brave's debouncing adblock rules, which stripped security-relevant redirect interceptors on third-party sites. CWE-601, CVSS 6.1.
Volume & consistency
98 resolved
98 vulnerabilities triaged, accepted and fixed. 100+ bounties awarded across 96 different organisations since December 2021.
Signal quality
96th percentile
96th percentile for impact platform-wide — a measure of how severe accepted findings are, not how many were submitted. 4,394 reputation.
Government recognition
DoD MVR
Named a Most Valuable Researcher of the Month by the U.S. Department of Defense for vulnerabilities reported through its Vulnerability Disclosure Program.
Microsoft MSRC
Top 100 global
Listed on the Microsoft Security Response Center 2025 Most Valuable Security Researcher leaderboard (July 2024 – June 2025), and ranked #25 on the 2024 Q4 researcher leaderboard.
alg:noneLegacy verification path accepted unsigned tokens, allowing authentication as any user on a heavily tested target.
$3,000Found by revisiting a previously closed report and bypassing the original fix — bulk personal data exposed in clear text.
$6,000Object-level authorisation flaw permitting access to records belonging to other customer tenants.
$2,500Rated above a parallel IDOR because the exposed data was unhashed, materially raising real-world impact.
$3,000 + $1,342Public HackerOne metrics for hackerone.com/kalkii, verified August 2026. Bounty figures are as publicly disclosed by the researcher.
Founder & Principal Security Researcher
@kalkii · Patna, Bihar, India
The person behind the work
Abhinav left medical entrance preparation to pursue security full time — a decision that looked reckless right up until the reports started getting paid. Since December 2021 he has worked as an independent security researcher, reporting vulnerabilities to organisations ranging from the U.S. Department of Defense to Shopify, Adobe, GitLab, PlayStation and Sony.
That work has produced 98 resolved vulnerabilities across 96 organisations, over 100 paid bounties, a published CVE in the Brave browser, and a clean sweep of the HackerOne India live hacking circuit — first place at the North, South, East and West regional events, plus the Zomato Live Hacking Event. The U.S. Department of Defense has named him a Most Valuable Researcher of the Month, and Microsoft listed him among its top 100 researchers worldwide for 2025. On the most recent quarterly leaderboard he ranked #3 in India and #24 worldwide.
Abhinav Cybersecurity exists to bring that methodology to companies directly — the same adversarial testing, on your schedule, under NDA, with a report your engineers can act on.
Engagement models
Every model is fixed-price and quoted after a free scoping call. No hourly billing, no scope creep.
For a single application, API or new feature release.
3–5 working days of testing
For SaaS platforms going through SOC 2, ISO 27001 or enterprise security review.
8–15 working days of testing
For teams shipping weekly who need testing that keeps up.
Retained, monthly
FAQ
Most web or mobile application tests run 5 to 15 working days of active testing, plus 2 to 3 days for reporting. Scope determines the number — and you get the timeline and the price in writing before anything begins.
An executive summary for leadership, a full technical report with reproducible proof-of-concept steps and CVSS v3.1 ratings for every finding, prioritised remediation guidance, a live debrief with your engineers, a free retest of every fix, and a signed attestation letter you can hand to auditors and customers.
Included. One full retest of all findings within 90 days of report delivery, at no additional cost. The report is reissued with each fixed issue marked verified.
Yes. Engagements are scoped and documented to meet SOC 2, ISO 27001, PCI-DSS and enterprise vendor-security requirements, and you receive a formal attestation letter stating scope, methodology, dates and outcome.
Always — before any scope details are exchanged. We work under your NDA or ours. All findings, credentials and collected data are destroyed on request at the end of the engagement.
Yes. Rules of engagement are agreed in writing first: testing windows, request rate limits, forbidden actions, emergency contacts and a kill-switch. Destructive or denial-of-service testing is never performed without explicit written approval.
A signed NDA and SOW, a list of in-scope hosts and applications, test accounts for each user role, and a technical point of contact. Architecture diagrams and prior reports help but are not required.
Yes — a large share of our work is seed to Series B companies facing their first enterprise security review. The Focused Assessment tier exists precisely for that moment.
Get started
Tell us what you have built. You will get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will actually do the testing.