CYBERSECURITY INTELLIGENCE

Dewan Shahid
PWN-001 | Cybersecurity Researcher

Google Bug Hunter Bugcrowd Verified

Vulnerability Research • OSINT Automation • Threat Intelligence

Cybersecurity practitioner specializing in vulnerability discovery and OSINT automation. Transform digital footprints into actionable intelligence. 5+ years disassembling attack surfaces. Recognized for preventing 1.14 TB of sensitive data exposure.

50+
Research Projects
100+
Investigations
10+
Years Experience

About Dewan Shahid

Cybersecurity practitioner focused on vulnerability research, OSINT automation, and intelligence-driven security analysis. Based in Karachi, Pakistan.

Security Research & OSINT Automation

I approach cybersecurity as infrastructure forensics—mapping digital systems to understand how they leak, connect, and reveal themselves. Not theoretical security, but practical vulnerability discovery grounded in structured OSINT methodologies and systematic analysis.

Recognized by Google Bug Hunters (Dragon Badge, Oct 2024) and Bugcrowd (Submission Shogun, Bounty Bee, Jan 2025) for responsible disclosure of critical vulnerabilities including XSS, Open Redirect, CSRF, and infrastructure misconfigurations.

Helped prevent exposure of 1.14 TB of sensitive data across multiple Pakistani organizations. Coordinated responsible disclosures with 5+ organizations and educational institutions, improving their security posture and data protection frameworks.

Current Work: Building TBV Server—a self-hosted intelligence platform combining real-time system monitoring, multi-source OSINT capabilities, CRM, CCTV integration, and structured threat analysis into a unified operational control center.

Approach: Practical, methodology-driven, focused on real-world impact. Every finding is traced, verified, and actionable.

Research Focus

Exposure analysis, infrastructure mapping, threat intelligence

Digital Surface

OSINT methodology, asset discovery, vulnerability assessment

Intelligence

Warning-oriented analysis, threat assessment, exposure reporting

Methodology

Structured research, technical tradecraft, actionable reporting

Recognition & Achievements

Formal recognition from major vulnerability disclosure programs and proven impact in data protection.

VERIFIED

Dragon Badge

Google Bug Hunters Program • October 2024

Recognized for responsible disclosure of critical XSS and Open Redirect vulnerabilities in YouTube. Formal recognition from Google's security team.

VERIFIED

Submission Shogun

Bugcrowd Program • January 2025

High-volume submission recognition. Reported and validated critical security flaws in public platforms, directly contributing to vendor security improvements.

VERIFIED

Bounty Bee

Bugcrowd Program • January 2025

Active bounty program contributor. Consistently identified and reported security vulnerabilities across multiple platforms with responsible disclosure practices.

Major Impact Achievements

1.14 TB Data Exposure Prevented

Discovered critical misconfigurations across 5 Pakistani software firms and coordinated responsible disclosure, preventing large-scale sensitive financial and employee data exposure.

Large-Scale Data Leak Mitigation

Coordinated with educational institution administrators to mitigate a large student data leak, safeguarding thousands of users and improving their protection framework.

Platform Vulnerabilities Disclosed

Identified and reported an Open Redirect vulnerability in Bugcrowd's own platform, directly contributing to improved application security and vendor awareness.

450+ Users Served

TBV Bot OSINT automation tool used by 450+ security practitioners for breach detection and threat intelligence workflows.

Professional Overview

5+

Years of cybersecurity practice

50+

Research projects & investigations

100%

Responsible disclosure rate

The TBV Collective

Independent cyber intelligence collective focused on OSINT, exposure analysis, and warning-oriented research.

About TBV

TBV (The Blue Vault) operates as the strategic framework for organized cyber intelligence work. It's built on three layers: TBV Server (the operational backbone), TBV Bot (field automation, now retired), and the broader intelligence methodology that ties everything into structured, repeatable workflows.

The goal is simple: take messy digital footprints, scattered signals, and exposed data, then transform them into something that can actually be reasoned about. Everything integrates—data collection, verification, analysis, and actionable intelligence delivery.

TBV Server

Self-hosted LAN intelligence platform combining system monitoring, CRM, OSINT, CCTV, and network tooling into unified operational control.

  • System monitoring dashboard
  • Real-time OSINT integration
  • CCTV & network scanning
  • FastAPI + SQLAlchemy stack

TBV Bot (Retired)

OSINT automation tool used by 450+ users. Modular Python architecture with breach detection, threat correlation, and social media reconnaissance.

  • Breach detection automation
  • Threat correlation logic
  • Social media reconnaissance
  • Identity metadata extraction

Vulnerability Research

Hands-on discovery of web application vulnerabilities, infrastructure misconfigurations, and digital exposure through systematic analysis and responsible disclosure.

  • XSS, CSRF, Open Redirect discovery
  • Infrastructure misconfiguration audits
  • Data exposure prevention
  • Responsible disclosure coordination

Research Intelligence

Methodology-driven investigations into exposure analysis, infrastructure mapping, and threat landscape intelligence.

DISCOVERY

Vulnerability Discovery

Systematic detection of security weaknesses in web applications and infrastructure. Focus on XSS, Open Redirect, CSRF, and infrastructure misconfigurations.

Web Apps Infrastructure Burp Suite
BREACH

Breach Detection & Analysis

Intelligence gathering on data breaches, data exposure discovery, and compromise confirmation. Automated breach monitoring and correlation.

Detection Monitoring Analysis
FOOTPRINT

Digital Footprint Analysis

Comprehensive mapping of digital identity exposure. Social media reconnaissance, identity metadata extraction, and cross-platform analysis.

OSINT Mapping Social Media
RECON

Infrastructure Reconnaissance

Passive mapping and asset discovery. DNS enumeration, WHOIS analysis, Shodan scanning, and technology fingerprinting without active probing.

DNS Shodan Passive
PREVENTION

Data Leak Prevention & Mitigation

Identification of sensitive data exposure vectors. Risk assessment, remediation coordination, and prevention strategies for data loss.

Risk Assessment Mitigation Prevention
AUTOMATION

Threat Intelligence Automation

Python-powered automation of intelligence workflows. Integration of multiple OSINT APIs, scheduled research, and real-time threat correlation.

Python APIs Automation

Featured Projects & Tools

Production systems, research tools, and intelligence platforms built for cybersecurity analysis and OSINT operations.

TBV Server

Self-hosted LAN intelligence platform combining monitoring, OSINT, CRM, CCTV, and network tooling.

Capabilities
  • Real-time system monitoring (CPU, RAM, disk, network)
  • CCTV camera integration with live stream (WebRTC/HLS)
  • Multi-source OSINT (Breach detection, Malware tracking)
  • Cloud Storage Bucket Scanner (AWS S3 & Google Cloud)
  • WiFi network scanning & asset discovery
  • HTTP Request Replicator (cURL, Fetch, HAR formats)

Tech Stack:

FastAPI Python 3.11 SQLAlchemy Nginx APScheduler FFmpeg
Status: Active Development (Jan 2026 – Present)

TBV Bot

Retired

OSINT automation tool used by 450+ users for breach detection and threat intelligence.

Features
  • Breach detection & credential monitoring
  • Malware association tracking
  • Social media reconnaissance engine
  • IP-based threat artifact correlation
  • Identity metadata extraction (lawful sources)
  • Modular architecture with rate-limiting

Tech Stack:

Python Discord.py OSINT APIs Async Automation
Status: Discontinued (Retired Jul 2025)

Archived for historical reference • 450+ users served

Bug Bounty Programs

Responsible vulnerability disclosure with formal recognition from major tech platforms.

Recognition
  • Google Bug Hunters - Dragon Badge (Oct 2024)
  • Bugcrowd - Submission Shogun (Jan 2025)
  • Bugcrowd - Bounty Bee (Jan 2025)
  • XSS, Open Redirect, CSRF vulnerabilities
  • Infrastructure & configuration exposure analysis

Specializations:

XSS Open Redirect Infrastructure CSRF
Impact: 1.14 TB data exposure prevented • Multiple platforms secured

Infrastructure Tools

Custom reconnaissance and asset discovery tools for infrastructure auditing.

Capabilities
  • Passive infrastructure mapping & reconnaissance
  • DNS enumeration & WHOIS analysis
  • Shodan scanning & technology fingerprinting
  • Service enumeration & asset discovery
  • Misconfiguration detection & analysis

Tech Stack:

Python Shodan API OSINT APIs Passive Recon
Use Case: Exposure analysis, vulnerability assessment, attack surface mapping

TBV Server

Self-hosted LAN intelligence platform combining monitoring, OSINT, CRM, and network tooling.

Full-stack platform with real-time system dashboards, CCTV streaming, WiFi scanning, cloud storage enumeration, HTTP request replication, and multi-source OSINT capabilities. Deployed with Nginx reverse proxy and automated background tasks.

Tech Stack:

FastAPI SQLAlchemy Python 3.11 Nginx
GitHub

TBV Bot (Retired)

OSINT automation tool used by 450+ users for breach detection and intelligence workflows.

Modular Python architecture with breach intelligence modules, social media reconnaissance, threat correlation logic, and identity metadata extraction. Rate-limiting and structured output for reliable automation.

Tech Stack:

Python Discord.py OSINT APIs Async
GitHub

Google Bug Hunter & Bugcrowd

Responsible vulnerability disclosure with formal recognition and bug bounty credentials.

Verified security researcher with Google Bug Hunter Dragon Badge (Oct 2024) and Bugcrowd recognition (Submission Shogun, Bounty Bee). Focus on web application vulnerabilities including XSS, Open Redirect, CSRF, and infrastructure misconfigurations. Responsible disclosure coordination across multiple platforms.

Specializations:

XSS Open Redirect Infrastructure Disclosure
Google Program

Infrastructure Reconnaissance Tools

Passive reconnaissance and asset discovery for infrastructure auditing and exposure analysis.

Custom Python-based tools for infrastructure mapping, service enumeration, misconfigurations detection, and digital asset discovery. Integrated with open-source intelligence frameworks and OSINT APIs for comprehensive attack surface analysis.

Tech Stack:

Python Shodan Nmap Passive Recon
GitHub

Infrastructure Stack

Complete overview of research systems, intelligence pipelines, and operational infrastructure.

Research Systems

Dedicated infrastructure for OSINT research, data collection, and intelligence analysis workflows.

  • Collection systems
  • Data processing
  • Analysis tools
  • Report generation

Intelligence Pipeline

Automated intelligence aggregation and processing pipeline for real-time threat monitoring.

  • Feed aggregation
  • Data normalization
  • Correlation engine
  • Alert distribution

Automation

Automated workflows for recurring research tasks, scanning, and intelligence gathering.

  • Scheduled scans
  • Automated checks
  • Batch processing
  • Workflow orchestration

Monitoring

Real-time monitoring, alerting systems, and operational dashboards for infrastructure oversight.

  • Real-time alerts
  • Health monitoring
  • Performance tracking
  • Incident response

Storage & Processing

Scalable storage infrastructure and high-performance data processing for large datasets.

  • Database systems
  • Data warehousing
  • Query optimization
  • Backup systems

Integration & APIs

API infrastructure and integrations with third-party services and intelligence sources.

  • REST APIs
  • GraphQL interface
  • Third-party feeds
  • Webhook support

Technical Expertise

Comprehensive skill set across cybersecurity, OSINT, infrastructure, and intelligent systems development.

Languages

Python Expert
Bash/Shell Expert
JavaScript Advanced
HTML/CSS Advanced

Security Tools

Burp Suite Advanced
Nmap Advanced
Shodan/Censys Expert
Metasploit Intermediate

Frameworks

FastAPI Advanced
SQLAlchemy Advanced
Discord.py Advanced
Async Patterns Advanced

Infrastructure

Linux Administration
Nginx & Reverse Proxy
Docker & Containerization
Git & Version Control
SQLite & Database Design
SDR & Signal Analysis

OSINT Methods

Breach Detection & Monitoring
Social Media Reconnaissance
DNS & Passive Recon
Identity Metadata Extraction
Threat Correlation & Analysis
Data Leak Investigation

Specializations

Vulnerability Discovery & Assessment
Web App Security (OWASP Top 10)
Infrastructure Exposure Analysis
Cyber Threat Intelligence
Responsible Disclosure Coordination
Intelligence Automation Systems

Proficiency Breakdown

5+

Years of Practice

20+

Security Tools

10+

Programming Languages

Expert

OSINT Methodologies

Programming Languages

Python 95%
Bash/Shell 93%
HTML/CSS 85%
JavaScript 75%

Security Tools

Burp Suite Advanced
Nmap Advanced
Metasploit Intermediate
Wireshark/Shodan Advanced

Backend & Frameworks

FastAPI 85%
SQLAlchemy 80%
Uvicorn 82%
Git 90%

Platform & Infrastructure

Linux Administration 92%
Nginx 88%
Docker 80%
SDR Fundamentals 75%

Vulnerability Research

Web App Testing Expert
Infrastructure Auditing Expert
OSINT Automation Expert
Breach Intelligence Advanced

Recognition & Achievements

Google Bug Hunter

Dragon Badge • Oct 2024

Bugcrowd Recognition

Submission Shogun • Bounty Bee

Data Protection Advocate

1.14 TB exposure prevented

Bash/Shell Expert
JavaScript/Node.js Advanced
Go Intermediate

Research Methods

OSINT Methodology Expert
Intelligence Analysis Expert
Threat Assessment Expert
Report Writing Advanced

Get in Touch

Open to collaboration, research partnerships, and security consulting inquiries.

Dewan Shahid

Cybersecurity Practitioner | OSINT & Threat Intelligence Builder

📍 Karachi, Pakistan

📱 +92 335 8153802

Available for collaboration

Connect Online

Send a Message

I typically respond within 24-48 hours for urgent matters.

Email

contact.shieldmatrix@proton.me

Connect

GitHub
LinkedIn
Twitter / X

Response time

Usually within 24-48 hours