I find what'shidden in plainsight.
I'm Deepanshu Deep, a security researcher working where intelligence meets offense. I trace digital footprints, profile threats, and break web apps before the bad guys do.
I work both sides of the wire. As an OSINT and threat intel analyst, I turn scattered public data into a clear picture of people, infrastructure and adversaries. As a bug bounty hunter, I hunt real vulnerabilities in real web apps and APIs, then write up exactly how I found them. Gather everything.
> Trust nothing. Verify twice.
What I do, end to end.
OSINT
Open-Source Intelligence
Turning scattered public data into a clear, verified picture of a person, organisation or infrastructure.
- Username pivoting
- Email & phone OSINT
- Domain & DNS mapping
- SOCMINT
- Geolocation & IMINT
- Google / GitHub dorking
CTI
Cyber Threat Intelligence
Tracking adversaries, their tooling and infrastructure, and turning it into intel defenders can act on.
- Threat actor profiling
- IOC enrichment
- MITRE ATT&CK mapping
- Dark web monitoring
- Phishing tracking
- Intel reporting
OFFSEC
Bug Bounty & VAPT
Breaking web applications and APIs the way real attackers would, then reporting it responsibly.
- Web & API pentesting
- IDOR / BAC
- Auth & logic flaws
- XSS, SQLi, SSRF
- Attack surface recon
- Clear PoC reports
Tradecraft & tooling.
Know more about my work here.
Findings and field guides on Medium and OSINT Team.
Poke around.
An interactive shell. Type a command or tap one below.
Let's talk.
Open to OSINT investigations, threat intel work, pentest engagements and security collaborations.