
Devansh Bordia
Cloud and application security engineer and vulnerability researcher
Network
13.4K connectionsSummary
Work
Education
Projects
Writing
An in-depth guide to subfinder: beginner to advanced
February 1, 2023A comprehensive guide to subdomain enumeration using subfinder, covering installation, usage, advanced options and integrations.
Insider Threats as Biggest Risk
October 1, 2022Article covering insider threat types, detection approaches and mitigation strategies.
CodeShield: Cloud Asset Inventory & Privilege Escalation Toolkit
August 1, 2022Medium post reviewing CodeShield, describing IAM privilege escalation detection and cloud asset inventory capabilities.
Common security vulnerabilities in Core AWS services: Exploitation and mitigation
July 1, 2022A long-form guide that surveys common misconfigurations and vulnerabilities across core AWS services and recommended mitigations for cloud security assessments.
CSRF in ICEHRM 31.0.0.0S in Delete User Endpoint
April 1, 2022Medium writeup documenting a CSRF vulnerability in ICEHRM allowing arbitrary user deletion and an exploit proof-of-concept.
Exploiting IAM Vulnerabilities in AWS
July 1, 2021Detailed blog post walking through IAM enumeration, common IAM misconfigurations, exploitation examples and remediation advice for AWS accounts.
Beginner's guide to iOS pentesting: tools, setup, and techniques
A practical guide to setting up an iOS pentesting environment and workflows for static and dynamic analysis.