Available for new engagements

I believe in
breaking things
to make them stronger.

Security Researcher and Penetration Tester in Kerala, India. Currently working bug bounty full time.

Alen Sebastian
3 Hall of Fame
2+ Years
Experience
20+ Projects
Delivered

Security tooling I built because the
thing I needed didn't exist yet.

Null Loader firmware flashing interface
01 Live

Null Loader

The ultimate web-based firmware deployment suite for ESP32 security toolkits. A high-performance, browser-based flasher that deploys security firmwares to ESP32 boards directly via the Web Serial API, with no command-line tools, local Python environments, or driver struggles.

  • Web Serial API
  • esp-web-tools
  • JavaScript
Open the live tool
GHOST Scanner command line
02

GHOST Scanner

Automated web vulnerability scanner with OWASP Top 10 detection, with fourteen test modules driven from one command line menu.

  • Python
  • Bash
View source
Marauder Web UI control centre
03

Marauder Web UI

Web-based control interface for ESP32 Marauder with WiFi and Bluetooth reconnaissance capabilities from a single panel.

  • C++
  • ESP32
View source

Vulnerabilities found, reported
responsibly, and credited publicly.

Decathlon

Hall of Fame — Responsible disclosure of security vulnerabilities

NASA

Hall of Fame — Responsible disclosure of security vulnerabilities

Electroneum

Hall of Fame — Responsible disclosure of security vulnerabilities

Where the work has been done.

Bug Bounty Hunter

Current

Independent · 2026 — Present

  • Hunt and responsibly disclose vulnerabilities across public programs
  • Credited in the Decathlon, NASA and Electronium halls of fame

Security Consultant

Gladius & Schild · 2024 — Jul 2026

  • Conduct penetration testing for enterprise clients
  • Perform security assessments and code reviews
  • Develop custom security tools and automation

Bachelor of Computer Application

Marian College Kuttikkanam Autonomous · Kerala, India

Certifications

eJPT
eJPTv2 Junior Penetration Tester v2
ACP
ACP APIsec Certified Practitioner
CAP
CAPv2 Certified AppSec Practitioner v2
CNSP
CNSP Certified Network Security Practitioner

I identify vulnerabilities, craft robust
security solutions, and help organizations
stay ahead of cyber threats.

Assessment

  • Red teaming
  • Penetration testing
  • VAPT
  • Web exploitation
  • API security
  • Network security

Instruments

  • Burp Suite
  • Metasploit
  • Nmap
  • Wireshark
  • Ghidra
  • SQLMap

Languages

  • Python
  • Bash
  • JavaScript
  • SQL
  • C / C++

Every section on this page is also
reachable by command.

guest@alen : ~ read only
guest@alen:~$

Let's work together

Available for
new engagements.

hello@alensebastian.in