pks@sec:~$ whoami

Pintu Kumar
Sutradhar

$>

I simulate real attacker tactics, techniques and procedures against customer environments — uncovering weaknesses across web, mobile, API, network and Active Directory attack surfaces, then turning them into practical, actionable fixes.

scroll to explore
0+ years in security
0 certifications
0+ assessments delivered
0+ tools in toolkit
capabilities

What I do

Seven core domains, one objective: find the weaknesses, prove they matter, and get them fixed.

Penetration Testing

Simulating real attacker TTPs against networks, applications and infrastructure to validate what is actually exploitable.

networksweb

Vulnerability Assessment

Comprehensive scans and analysis of servers and systems, surfacing critical weaknesses with remediation strategies.

serversinfra

Web App Security

Thorough evaluation of web applications end-to-end, delivered as clear reports with the detail needed to remediate.

OWASPreports

Mobile App Security

Android and iOS testing using both dynamic and static analysis techniques to find real, reachable flaws.

androidiosstatic + dynamic

API Testing

Targeted penetration tests on APIs — authentication, authorization and data handling — with security enhancements recommended.

RESTauth

OSINT

Open-source intelligence gathering to map the exposed footprint of an organization before an engagement begins.

reconfootprint

Digital Forensics

Evidence-oriented analysis of systems and artifacts to understand what happened and what it means for defense.

artifactsanalysis

Plus the full toolkit

Every capability above is powered by a categorized toolkit — from recon to post-exploitation.

view skills →
methodology

How an engagement runs

A disciplined lifecycle. Every finding is verified, prioritized, and tied to a fix.

01

Recon & Discovery

Map the environment and attack surface — assets, exposed services and entry points — before touching a thing.

02

Assessment

Identify and analyze system, application and network vulnerabilities, then assess and prioritize the risk each one carries.

03

Exploitation & Verification

Simulate attacker tactics, techniques and procedures to prove which weaknesses are genuinely reachable.

04

Reporting & Remediation

Deliver detailed findings with actionable remediation strategies — and stay current so the next round is sharper.

certified by ISC2 Fortinet EC-Council Google The SecOps Group ISO 27001:2022 all credentials →
engagements

Assessment track record

Security assessments delivered across banking, fintech, telecom-adjacent services, retail, healthcare and development organizations.

initiate contact

Want your attack surface tested?

Whether it is a web application, mobile app, API or the whole network — I can help you find the holes before someone else does.

$ ping -c 1 pintushapno2396@gmail.com