devansh

Devansh Batham

Security researcher / a life-long learner curious

I somehow got pulled into cyber security around 2016. I don't remember exactly how. Probably a CTF challenge that made me feel stupid in exactly the right way.

That feeling of having absolutely no idea what's going on, poking at something for hours, and eventually figuring it out has probably been responsible for most of what I've done since.

I started with web security and bug hunting, and then just kept going further down the rabbit hole.

I've also always been terrible at sticking to one subject. Growing up, I loved reading about people like Da Vinci, Feynman, and Ibn al-Haytham,  people who seemed completely uninterested in staying inside one neat little box.

I've always had the same problem, I want to learn everything.

Cyber Security just happened to be the rabbit hole that went the deepest.

A lot of my early fascination with hacking came from reading Phrack, The Conscience of a Hacker, old 2600 issues, random forums, writeups, and whatever else I could find on the internet.

I really liked the old hacker ethos, curiosity over credentials, understanding things instead of blindly trusting them, taking systems apart simply because you want to know how they work.

Over time, I also realized that security isn't really just about computers. It's about systems, trust, incentives, weird edge cases, and assumptions somebody forgot they were making.

Over the years, I've reported hundreds of vulnerabilities across more than a hundred companies and built a bunch of open-source tools, including ParamSpider, FavFreak, OpenRedireX, Rayder, and a few others.

Somehow they've collectively picked up 10,000+ stars on GitHub, which is still pretty cool to me.

I've spent time doing bug bounty, vulnerability research, pentesting, blockchain security, triage, open-source tooling, and leading security teams.

I previously led the Technical Services / Triage team at HackerOne, where I spent a lot of time looking at vulnerability reports and sitting somewhere in the middle between researchers and the companies they were hacking.

These days, I work at HackerOne as a Staff Security Researcher.

I still spend most of my free time building things, breaking things, reading random papers, disappearing into unnecessary rabbit holes, and learning subjects that have absolutely nothing to do with whatever I was learning the week before.

My technical stuff lives under writings.

Everything else ends up in ramblings.

You can reach me at devanshbatham009@gmail.com.


GitHub · X · LinkedIn · Email