// Live Threat Simulation — simulated data
SweshInfoSec
MY BIO
Security Researcher · VAPT · Bug Bounty · Penetration Testing
10+ years in offensive security, vulnerability research, and enterprise security assessments. Identifying real-world weaknesses across web applications, infrastructure, cloud environments, mobile apps, and smart contracts.
Web AppSec Network Pentest Cloud Security Mobile Security Red Teaming Malware Analysis Reverse Engineering Smart Contracts Threat Modeling Risk Assessment Exploit Development
10+
Years
12
Domains
AWS
Azure · GCP
OWASP
WSTG · CWE
For more information about me click the "About Me" button. About Me
// Recent Walkthroughs
GuardianLeaks on pentest-ground.com — Web App Pentest Walkthrough
Aug 30, 2026 · 13 min read
Step-by-step web-app pentest of GuardianLeaks — SQLi to a full credential dump, SSRF into cloud metadata, an easy-to-miss stored XSS, and an exposed Werkzeug debugger. 3 criticals + full kill chain.
DVGA on pentest-ground.com — GraphQL Pentest Walkthrough
Aug 29, 2026 · 19 min read
Step-by-step: unauthenticated GraphQL introspection to full RCE on DVGA — 2 criticals, one HIGH SSRF, full kill chain.
Test
May 14, 2026 · 1 min read
Test Sub
Welcome to SweshInfoSec
May 13, 2026 · 1 min read
Security research walkthroughs, VAPT findings, and bug bounty reports — documented with BlackOps.