Skip to content

SESSION LIVE

OVERWATCHLABS.AI
FOUNDER // OFFENSIVE SECURITY

> whoami — abhimanyu_gupta

I break inbefore they do.

Red teamer turned founder. Four years of assumed-breach ops against banks, insurers and state platforms — now building Forensia so companies can see their attack surface the way I do.

  • 4+YEARS RED TEAM
  • 130+APPS & APIS BROKEN
  • 1CVE PUBLISHED

SCROLL

01 // SELECTED OPS

Four engagements.
No names, all detail.

Clients stay anonymous. The tradecraft doesn't.

01NON-BANKING FINANCIAL INSTITUTION2024

Internal red team, assumed breach

ACCESS

Full Active Directory compromise

Custom-payload EDR bypass + privilege chain

  • EDR BYPASS
  • ACTIVE DIRECTORY
  • INFRASTRUCTURE
PROBLEM
Assumed-breach scenario inside a large NBFC with CrowdStrike deployed fleet-wide and almost no visibility into lateral-movement gaps.
APPROACH
Built custom payloads to walk past CrowdStrike, abused a weak domain-controller path, then chained misconfigurations to escalate.
OUTCOME
Full Active Directory compromise across the internal network, with every business-impact scenario demonstrated end to end.
IMPACT
Exposed critical gaps in endpoint protection and AD hardening, and moved real budget into identity and EDR guardrails.
02STATE GOVERNMENT SERVICES PLATFORM2023

Web & mobile exposure review at scale

SCALE

80+ web apps & mobile APKs

Multiple internal teams and vendor codebases

  • WEB APPS
  • MOBILE APKS
  • SOURCE DISCLOSURE
  • PII
PROBLEM
Eighty-plus web applications and mobile APKs, built by a dozen teams and vendors, all on inconsistent security baselines.
APPROACH
Large-scale application and API testing paired with configuration review — surfacing source-code disclosure, PII exposure and RCE paths.
OUTCOME
Externally exposed critical issues closed, and secure defaults normalised across the whole portfolio.
IMPACT
Leadership got a clear map of exposure drift over time plus a repeatable baseline every new release is measured against.
03FINANCIAL INSURANCE ENTERPRISE2023

Red team & phishing campaign

REACH

85% of endpoints under C2

One targeted campaign, assumed-breach simulation

  • PHISHING
  • AV EVASION
  • API SECURITY
  • WEB APPSEC
PROBLEM
The insurer needed to know whether its people and its online application stack held up against realistic attacker behaviour.
APPROACH
Tailored phishing campaigns with AV evasion, alongside ten-plus focused API and web application assessments.
OUTCOME
Critical weaknesses exposed across customer-facing journeys and the back-end controls behind them.
IMPACT
Drove changes to mail filtering, user awareness and app-layer defences — with a measurable drop in click-through.
04HEALTHCARE & ENTERPRISE CLIENTS2022

Application portfolio audit

PORTFOLIO

30+ web apps & 20+ APIs

Mixed maturity and monitoring states

  • WEB APPSEC
  • API SECURITY
  • INFRASTRUCTURE
  • CODE REVIEW
PROBLEM
Products that had grown organically: thirty-plus web apps and twenty-plus APIs at wildly different maturity, monitored inconsistently.
APPROACH
Infrastructure review with Nessus and Nipper, combined with SonarQube-assisted manual source-code analysis across the portfolio.
OUTCOME
High-risk defects closed with proof-of-concept-backed fixes, and monitoring tightened around the critical paths.
IMPACT
Left behind a repeatable security playbook for future releases and a lower rate of re-introduced defects.

02 // ANATOMY OF ONE OP

How a domain
CanRDPMemberOfAllowedToDelegateHasSessionDCSyncWORKSTATIONuser01SVC ACCOUNTunconstrained deleg.MEMBER SRVsql-02TIER-0 ADMINadm_backupDOMAIN CTRLdc-01Shortest path to domain admin — 3 hops, 0 exploits
falls in five moves.

The 2024 NBFC operation, step by step. Assumed breach, EDR everywhere, nobody expecting me.

KILL CHAIN PROGRESS

Five steps. Under a week. Not one production service disrupted.

  1. STEP 01RECON

    Map the internal, quietly

    One low-privilege workstation to start. Enumerated the domain with living-off-the-land tooling only — nothing dropped to disk, no telemetry worth an alert.

  2. STEP 02EVASION

    Write a payload the EDR likes

    Off-the-shelf loaders died instantly. Built a custom one — fresh syscalls, no known signatures, sleep obfuscation — and got a beacon that survived a full working day.

  3. STEP 03IDENTITY

    Follow the trust, not the CVEs

    BloodHound turned a flat network into a graph. Weak delegation on a forgotten service account was the shortest path to a domain controller — three hops, zero exploits.

  4. STEP 04DOMAIN ADMIN

    Own everything, break nothing

    Domain admin without disrupting a single production service. The point was never the ticket — it was proving which business processes I could have stopped.

    ACCESS ACHIEVED — full AD compromise via custom EDR bypass + delegation chain

  5. STEP 05THE PART THAT MATTERS

    Report blast radius, not findings

    Nobody in a boardroom cares about a Kerberos flag. They care that loan disbursement could have been halted for a day. That framing is what moved real budget.

03 // WHAT I ACTUALLY DO

Four things,
done properly.

Red team & adversary simulation

Full-scope and assumed-breach ops that copy real tradecraft — not a scanner report with a logo on it.

  • EDR/AV evasion & payload dev
  • AD and identity abuse to DA
  • Campaign-grade phishing
  • Blast-radius reporting

Threat intel & surface mapping

Everything of yours that's on the internet, ranked by what an attacker would reach for first.

  • Continuous asset discovery
  • Misconfig + weak-auth correlation
  • Attack-path modelling
  • Summaries execs actually read

TEE research & platform hardening

Enclaves, confidential workloads, and whether the hardware promise survives contact with reality.

  • Enclave & side-channel review
  • Threat models for TEE services
  • Firmware / runtime test plans
  • Research → deployable controls

Application & API security

Auth, session and business logic — the class of bug a scanner structurally cannot find.

  • Auth & business-logic deep dives
  • Source review + manual triage
  • IDOR & mass data exposure
  • Infrastructure baselining

04 // WHAT I'M BUILDING

Two ventures.
One sells hours,
one sells software.

ACTIVE

OverwatchLabs.ai

My offensive security practice. Red-team operations, application and API assessments, and TEE-aware platform hardening for teams that can't afford to guess.

BOOK AN ENGAGEMENT

LAUNCHING

Forensia

Threat intelligence that doesn't drown you. Forensia takes your noisy external exposure and returns a short, ranked list of what's actually going to hurt — in language a board understands.

  • continuous external discovery
  • attack paths, not finding lists
  • executive-ready risk signal

05 // INTERACTIVE

Type at me.

A real shell, not a screenshot. Everything about me is in here somewhere — including a flag I've hidden. Start with help.

EASTER EGGS↑ ↑ ↓ ↓ ← → ← → B A — konami still workstry sudo su, nmap, flag
abhimanyu@overwatchlabs — zsh

overwatchlabs shell v2.1 — abhimanyu gupta

type 'help' for commands. type 'flag' if you think you're clever.

06 // RESEARCH

I write. A lot.

38 posts on TEEs, quantum, malware internals and web3 security. Hover the wall to stop it.

19 MAY 26Formal Verification — How to Prove Code Won't Betray You?15 MAY 26But what the hell is EVM? (Ethereum Virtual Machine)18 APR 26Just what the hell is ZCASH?13 APR 26But How Exactly does UniSwap work?05 APR 26Phrack Cool issues part1: Quantum ROP03 APR 26Is npm cooked? Anyone confirmed? (npm axios attack)20 MAR 26Web3 series part 2: Tokenization of Real-World Assets (RWAs)17 MAR 26You know web scraping, but do you know Darkweb scraping?11 FEB 26Breaking Sandboxes In MCP agents20 JAN 26Theories, Theories and wait for it... THEORIES30 DEC 25How the hell does TEEs work exactly?02 DEC 25Quantum series part 2: What the hell is Quantum Cryptography !?22 NOV 25WireTap: Why This Physical Attack Doesn't Break TEEs – And How They're Getting Even Better
15 MAY 26Firewalls; What They Actually Do, and Why Attackers Get Through Anyway :/18 APR 26Malware analysis part2: Why File Signatures are the DNA of malware analysis :)13 APR 26What the hell is Quantum Safe Bitcoin (QSB)?06 APR 26OPSEC Guide (Respective To Drift protocol incident)03 APR 26Hacking Zero-Knowledge protocol cuz why not02 APR 26Learning Zero Knowledge Proofs makes me feel smart so you learn it too18 MAR 26Quantum series part 3: Quantum Networking and How it will look like in the future27 FEB 26Malware Analysis part 1: JVM Reverse Engineering28 JAN 26What the hell is MCP (Model Context Protocol) anyway?13 JAN 26How the hell does TEEs work with respect to different architectures?(INTEL version)07 DEC 25Cool exploits part 1: React2Shell26 NOV 25Quantum Computing in simple terms (just kidding)