Skip to content
View D3v4nshPat3l's full-sized avatar
🚀
Work Hard + Caffeine + Discipline + Hell
🚀
Work Hard + Caffeine + Discipline + Hell

Highlights

  • Pro

Block or report D3v4nshPat3l

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
D3v4nshPat3l/README.md
Devansh Patel — offensive security, recon automation, binary forensics

LinkedIn TryHackMe Medium Repositories


Profile views Followers Focus Track

█░  01 — IDENTITY

whoami --verbose: handle D3v4nshPat3l, offensive security, OSINT, CTF player, based in Gujarat India

I build tooling that turns raw reconnaissance into findings someone can actually act on — and I write the report that proves it. Most of my work sits at the seam between automation and evidence: collect broadly, validate ruthlessly, document so it reproduces on the first try.

  • Break it — web exploitation, auth/authz logic, API surface, misconfiguration, Linux privesc.
  • Automate it — recon pipelines, enrichment, triage, and reporting that survive being run twice.
  • Prove it — reproduction steps, captured evidence, false-positive elimination, severity that holds up.
  • Fix it — findings translated into config, code, and process changes, not just a ticket.

Scoped, authorized testing only. Every tool here exists to make defensive work faster.

█░  02 — OPERATING PROCEDURE

Pipeline: scope, recon, enumerate, exploit, validate, document, report, harden

Phase What actually happens
Scope Confirm boundaries, permission, and assumptions in writing before a single packet leaves.
Recon Passive and active collection — WHOIS, DNS, certificate transparency, archives, exposed surface.
Enumerate Map services, endpoints, parameters, auth flows, and trust relationships into something queryable.
Exploit Bounded, non-destructive validation. Confirm the path, never wander outside the agreed blast radius.
Validate Reproduce twice, strip false positives, capture the evidence that makes it undeniable.
Document Steps to reproduce, impact, affected assets, severity rationale, and the raw artifacts.
Report Written for two audiences at once: the engineer who fixes it and the person who funds the fix.
Harden Turn each finding into a concrete configuration, code, or process change — then re-test it.

█░  03 — FIELD PROJECTS

ReconTitan — self-hosted recon, OSINT and bounded pentest simulation platform Dork Ripper — categorized search-operator arsenal for authorized recon and bug bounty
HexForge Studio — local-first hex editor, PE analysis and binary forensics Interview Hub — 5000+ curated cybersecurity interview questions with answers
▸  SUPPORTING REPOSITORIES
Repository What it is Domain
Linux-CIS-Hardening-Auditor Bash CLI auditing Linux against 104 CIS Benchmark controls — filesystems, services, networking, logging, SSH, accounts. Hardening
Secure-QR-Code-Generator Input-validated QR generator for text, URL, phone, SMS, email, WhatsApp, Wi-Fi, vCard and UPI payloads. Tooling
Port-Swigger-Labs-Solved Solved PortSwigger Web Security Academy labs, each with the reasoning — not just the payload. Web Security
RingZero-CTF-Writeups Deep, step-by-step RingZer0 CTF writeups covering the dead ends as well as the solution. CTF
Pico-CTF-Writeups picoCTF challenge writeups across web, crypto, forensics and reversing. CTF

█░  04 — ARSENAL

Capability matrix across web security, recon and OSINT, automation, network, forensics and blue team

LANGUAGES Python Bash PowerShell Go Rust C C++ TypeScript
WEB & API FastAPI Flask Node.js React Nginx Postman
INFRA & DATA Docker MongoDB Redis Celery Git GitHub Actions Cloudflare
PLATFORMS Kali Linux Ubuntu Debian Linux Windows Tor
RECON & OSINT Nmap Amass Subfinder httpx Shodan Censys crt.sh VirusTotal GreyNoise
WEB SECURITY Burp Suite OWASP ZAP SQLMap ffuf Gobuster Nuclei Nikto
EXPLOITATION Metasploit Hydra Hashcat John the Ripper Exploit-DB SecLists
FORENSICS & RE Ghidra Wireshark tcpdump Binwalk Volatility Autopsy CyberChef YARA
BLUE TEAM Wazuh Splunk Elastic Suricata Snort Zeek CIS Benchmarks
LABS TryHackMe Hack The Box PortSwigger picoCTF RingZer0 OverTheWire

█░  05 — TELEMETRY

GitHub telemetry: repositories, stars earned, followers, commits, pull requests, issues, and language distribution
Contribution grid for the rolling 12-month window with total contributions
Contribution graph consumed by a snake

█░  06 — CURRENT OPS

$ tail -f ~/ops/NOW.log

[ACTIVE]  ReconTitan     :: confirmed-exploitation engine + richer PDF reporting
[ACTIVE]  HexForge       :: widening PE/ELF structure coverage and entropy triage
[ACTIVE]  OSCP path      :: AD attack paths, pivoting, Linux & Windows privesc
[QUEUED]  Dork-Ripper    :: automated validation pass over every operator set
[ONGOING] Web security   :: authz logic, API abuse, cache and CORS edge cases
[ONGOING] Writeups       :: PortSwigger, picoCTF and RingZer0 — reasoning included

Open to collaborate on

  • Recon and OSINT automation pipelines
  • Beginner-friendly, well-documented security tooling
  • Web security research, labs, and writeups
  • CTF teams and practice groups

How I work best

  • Documentation-first — if it isn't reproducible, it isn't done
  • Scoped and authorized, always in writing
  • Evidence over assertion, remediation over blame
  • Small tools that compose, not one monolith

█░  07 — CHANNELS

Connect on LinkedIn Read the writeups TryHackMe profile Follow on GitHub


End of transmission — all work shown is for authorized testing, learning and responsible research

Pinned Loading

  1. Dork-Ripper Dork-Ripper Public

    A massive categorized Google dork collection for Authorized Recon, OSINT, and Bug Bounty Hunting as well including some of the repositories like Onions, CCTVs, Cryptos and Some Like Which I Can't N…

    5

  2. HexForgeStudio HexForgeStudio Public

    Local-first hex editor, binary forensics, threat triage, PE analysis, and forensic PDF reporting.

    TypeScript 4

  3. Interview-Hub Interview-Hub Public

    A curated collection of 5000+ Cyber Security interview questions with detailed answers covering Networking, Linux, Windows, Active Directory, Web Security, Cloud, SOC, DFIR, Red Teaming, Blue Teami…

    1

  4. ReconTitan ReconTitan Public

    Security-hardened external reconnaissance, OSINT, and bounded penetration-test simulation platform with confirmed exploitation and PDF reporting.

    Python 1