I build thingsthat break things.

I'm Shantanu— a security assurance lead working across AppSec, DevSecOps, cloud hardening, and AI-driven security automation. This is the map of things I've built, broken, researched, or obsessed over long enough to ship.

Things shipped
08
Years in AppSec
06+
Certifications
OSWE · OSCP
— Selected work

Work worth keeping in one place.

  1. 01
    Writing2020—

    SecurityJunky

    Notes from building and breaking secure systems.

    My long-running home for technical writing: AppSec, DevSecOps, AI-driven security automation, and hands-on guides across web, mobile, APIs, cloud hardening, and vulnerability research.

    BlogAppSecDevSecOpsAI
    Read the blog
  2. 02
    Research2025

    Chromium VRP

    A searchable archive for Chromium VRP reports.

    A public archive for Chromium Vulnerability Reward Program submissions: historical reports, dashboard stats, researcher lookups by agent, and JSON endpoints for people who want to query the data directly.

    Next.jsPublic APIStatic
    Browse reports
  3. 03
    Tool2025

    PolyLens

    A sharper workspace for Polymarket traders.

    Browser extension plus web app for Polymarket, with advanced filtering, better visual context, and portfolio tracking for people who live inside prediction markets.

    Next.jsBrowser Ext.Fintech
    Visit PolyLens
  4. 04
    Experiment2025

    Résumé

    A resume site built through an AI-native workflow.

    A personal resume site built entirely through v0.dev, with no hand-written code. Part experiment, part proof that AI-native workflows are already good enough to ship useful things.

    v0.devVercelNo-code
    Open résumé
  5. 05
    Creative2024

    itsfucking.fun

    A portfolio that refuses to behave.

    A deliberately chaotic portfolio: interactive demos, hover-driven details, and a loud little reminder that the internet does not always need to look like a quarterly business review.

    PortfolioInteractive
    Visit
  6. 06
    Research2025

    BeaverTail Malware Analysis

    A fake AI recruiter, a malicious repo, and a five-stage payload.

    A deep-dive into an attack where threat actors impersonate recruiters and lure developers into cloning a malicious GitHub repo. The writeup follows the chain from JavaScript infostealers to Python RAT deployment, AnyDesk hijacking, credential theft, and persistence.

    Malware AnalysisThreat IntelDeriv Tech
    Read on Medium
  7. 07
    Research2026

    QuiloBook Malware Analysis

    When a trusted vendor channel becomes the delivery path.

    A Deriv security writeup co-authored with Deriv's Head of Security on QuiloBook, a signed Rust loader and RAT campaign delivered through compromised vendor communications. The analysis follows the fake PDF reader, PNG-hidden payload, C2 infrastructure, persistence paths, and defender-ready IOCs.

    Malware AnalysisSupply ChainThreat Intel
    Read on Substack
  8. 08
    Writing2026

    OSWE Certification Journey

    What it took to pass OSWE on the first attempt.

    A candid account of preparing for and passing the OffSec Web Expert exam: manual source review, web exploitation, no AI assistance, study methodology, HackTheBox machines, CTF prep, exam failures, and the resources built along the way.

    OSWEOffSecWeb Exploitation
    Read on Medium