Summary
Overview
Work History
Education
Skills
Certification
Notable Research
Timeline
Generic

Ashish Kunwar

Security Researcher
Noida,UP

Summary

Self-learner driven by hard work and passion with a solid understanding of information security and extensive experience in diverse cyber-security sub-domains. Skill set includes web and network application penetration testing, expertise in SAST and DAST. Practical experience in vulnerability analysis and attack surface management. Recognized by over 500 companies for effectively reporting critical security vulnerabilities.

Overview

5
5
years of professional experience
7
7
years of post-secondary education
4
4
Certifications
2
2
Languages

Work History

Security Researcher II

Microsoft
12.2023 - Current
  • Worked on fingerprinting web technologies, CMS platforms, and other web components using a non-intrusive approach (versioning, passive fingerprinting, behavioral analysis) instead of active probing.
  • Developed detection rules for Microsoft Defender External Attack Surface Management (MDEASM) to accurately identify technologies and vulnerabilities while minimizing footprint.
  • Collaborated with engineering teams to create custom probing for specific ports when required or based on customer requests.
  • Analyzed existing vulnerabilities and wrote detections for them, mapping them to MITRE ATT&CK techniques.
  • Researched and tracked threat actors, studying their TTPs and monitoring zero-day vulnerabilities they exploited.
  • Created detections for Command & Control (C2) panels and infrastructure to enable active tracking of malicious operations.
  • Built complex KQL (Kusto Query Language) queries for threat hunting, detection engineering, and analyzing large-scale security telemetry.
  • Created detailed vulnerability profiles(ASI), covering CVE analysis, exploitability, and risk assessment.
  • Worked closely with teams to analyze and publish reports on emerging threats, vulnerabilities, and attack techniques.
  • Contributed to security articles and intelligence reports to help the broader security community.

Researcher

Microsoft
04.2022 - 09.2023
  • Conducted in-depth vulnerability research by analyzing web technologies, CMS platforms, and other web components to identify potential security weaknesses.
  • Performed detailed analysis of identified vulnerabilities and exploits, assessing their impact, exploitability, and mapping them to MITRE ATT&CK techniques.
  • Developed and implemented detections for attack surface management, focusing on non-intrusive fingerprinting.
  • Contributed to threat intelligence efforts, combining data collection, processing, analysis, and dissemination to provide actionable insights that support security decision-making.
  • Worked closely with cross-functional teams, including engineering and research groups, to enhance security posture, keep up with evolving threats, and ensure a rapid response to emerging cybersecurity challenges.

As a Vendor

Vulnerability Researcher

RISKIQ
03.2021 - 03.2022
  • Conduct vulnerability research Spanning across Network and Web
  • Doing IOC analysis of latest Threats emerging on the web
  • Developing Tools and Tactics to automate or solve the issues related to Research
  • Doing Exploit Development / Proof of Concept related to the Products
  • Come up with a solution of the trade to map the attack surface on the web

Penetration Tester

Red Sentry
08.2020 - 01.2021
  • Performs Penetration Testing for clients
  • Involves Initial Recon to Privilege Escalation
  • Report Writing and Delivery

Education

Bachelor of Technology -

G.D. Goenka University
01.2019 - 01.2023

Polytechnic(Diploma) - C.S.

YBN University
01.2017 - 01.2020

Skills

Strong Communication Skills

undefined

Certification

2020, System Operator and Certification (SOC), Wild West

Notable Research

  • Gifsicle Null Dereference Vulnerability, https://github.com/kohler/gifsicle/issues/130
  • Nano Text Editor Memory Leak, https://savannah.gnu.org/bugs/?53269
  • Erlang Buffer Overflow, https://github.com/erlang/otp/issues/4291

Timeline

Security Researcher II

Microsoft
12.2023 - Current

Researcher

Microsoft
04.2022 - 09.2023

Vulnerability Researcher

RISKIQ
03.2021 - 03.2022

Penetration Tester

Red Sentry
08.2020 - 01.2021

Bachelor of Technology -

G.D. Goenka University
01.2019 - 01.2023

Polytechnic(Diploma) - C.S.

YBN University
01.2017 - 01.2020
Ashish KunwarSecurity Researcher