nitesh@gupta
About

Nitesh Gupta

Cyber security consultant and red teamer in Mumbai, India. I break into enterprise networks for a living. Active Directory attack paths, internal and external penetration testing, and the web, mobile and API layers on top of them, then write up how it was done so it can be fixed properly.

OSCPOSCP+ CRTPMumbai, India Available for consulting

Experience

  1. Jan 2026 to Present

    Security Engineer · Saint-Gobain INDEC (Grindwell Norton Limited)

    Mumbai, India

    Vulnerability validation, exploitability analysis and risk assessment of emerging threats across enterprise infrastructure, cloud and business-critical applications. Runs attack surface management end to end, and operationalises newly disclosed CVEs into advisories the infrastructure, cloud and application teams can act on.

  2. Apr 2024 to Jan 2026

    Cyber Security Consultant · Security Brigade Infosec Pvt Ltd

    Mumbai, India

    Owned security assessment operations for the Mahindra & Mahindra Group across national and international subsidiaries: internal and external network testing, red-team retesting to verify mitigations, and advanced evasion work to measure EDR coverage and improve SOC detection.

  3. Dec 2022 to Apr 2024

    Security Researcher · Security Brigade Infosec Pvt Ltd

    Mumbai, India

    VAPT across Mahindra & Mahindra subsidiaries, dark web and breach monitoring for exposed credentials, and working alongside development teams through the patching cycle to closure.

  4. May 2022 to Oct 2022

    Cyber Security Trainer · Encryptic Security Pvt Ltd

    Mumbai, India

    Taught batches of 20+ students, from networking and common web attacks through to SSRF and XXE, with hands-on exploitation exercises throughout.

What I do

Offensive
  • Red teaming
  • Internal & external network penetration testing
  • Active Directory attack paths
  • Privilege escalation
  • EDR evasion
  • Social engineering
Application
  • Web application testing
  • API security testing
  • Mobile application testing (Android/iOS)
  • Source-assisted review
  • OWASP Top 10 / ASVS
Tooling
  • BloodHound
  • Impacket
  • Certipy
  • NetExec / CrackMapExec
  • Burp Suite
  • Metasploit
  • Nessus
  • Nmap
  • Ligolo-ng
  • Responder
Engineering
  • Python
  • Bash
  • PowerShell
  • Attack surface management
  • Vulnerability intelligence

Certifications

8
Offensive Security Certified Professional (OSCP)

Offensive Security · 2025

Offensive Security Certified Professional Plus (OSCP+)

Offensive Security · 2025

Certified Red Team Professional (CRTP)

Altered Security · 2025

Certified Network Pentester (CNPen)

SecOps Group · 2024

Certified Ethical Hacker (CEH)

EC-Council · 2022

eLearnSecurity Junior Penetration Tester (eJPT)

eLearnSecurity / INE · 2022

Certified AppSec Practitioner (CAP)

SecOps Group · 2023

Certified Network Security Practitioner (CNSP)

SecOps Group · 2023

Security acknowledgements

11 organisations

Organisations that have credited me for responsibly disclosed vulnerabilities.

SentinelOneSpartooJio Platform LimitedABB Information Systems LtdNavientExtraHop NetworksSimplyCookLenskartGoFrugalGovernment of IndiaMUFG Americas

Education

Master of Computer Applications (MCA, Cyber Security)

Lovely Professional University · Pursuing

Bachelor of Computer Applications (BCA)

Institute of Business Studies & Research, Navi Mumbai · 2021

Writeups

47 Proving Grounds boxes documented end to end: 17 Windows, 25 Linux and 5 Active Directory.

Frequently asked

Who is Nitesh Gupta?

Nitesh Gupta is a cyber security consultant and red teamer based in Mumbai, India. He works on Active Directory attack paths, network and application penetration testing, and enterprise security assessments, and holds the OSCP, OSCP+ and CRTP certifications.

What does Nitesh Gupta specialise in?

Red teaming and Active Directory security in particular: Kerberos attacks, ACL and ADCS abuse, lateral movement and domain escalation, alongside web, mobile and API penetration testing.

What certifications does Nitesh Gupta hold?

OSCP, OSCP+, CRTP, CNPen, CEH, eJPT, CAP and CNSP.

Is Nitesh Gupta available for security consulting?

Yes. He takes on penetration testing, red team and Active Directory security assessment work. The fastest way to reach him is by email at [email protected] or through LinkedIn.

Where can I read Nitesh Gupta's security writeups?

All 47 Offensive Security Proving Grounds walkthroughs are published at niteshgupta.com/writeups/, covering Windows, Linux and Active Directory boxes.

Get in touch

Open to penetration testing, red team and Active Directory security assessment work.