Surya Dev Singh
Security Consultant - Red Team @ Payatu
About
I specialize in simulating real-world cyberattacks to help organizations identify and fix their blind spots. With a focus on adversary emulation, Active Directory attacks, post-exploitation, and EDR bypass, Penetration Testing, I conduct full-scope red team operations that replicate advanced persistent threats (APT).I've reported vulnerabilities to major platforms like Google, LinkedIn, Mozilla Firefox, Jenkins, In Drive, Deautche Bank and more - and have 4 CVEs published under my name: CVE-2026-8971CVE-2026-2790CVE-2025-1936CVE-2024-34147My work spans payload development, C2 infrastructure (Cobalt Strike, Sliver), and techniques like Kerberoasting, DCSync, and AMSI bypass. I enjoy creating stealthy attack paths, documenting findings with MITRE ATT&CK mapping, and helping blue teams improve through collaborative purple teaming.Always open to discussions around red teaming, offensive research, and pushing the boundaries of ethical hacking. Please feel free to get in touch with me via email at : suryadevsingh2321@gmail.com
India
Bengaluru
Computer & Network Security
Initial Access, Active Directory, C2 Frameworks Expertise, Evasion & Bypass Techniques, Client Communication & OPSEC, HL7 Standards, DICOM, Medical Device Authentication and Authorization, Red Team Operations, Medical Device Regulatory Compliance, Command and Control, U.S. Health Insurance Portability and Accountability Act (HIPAA), Medical Devices, Infrastructure, Product Security, active directory hacking, Security Research, Malware Development, C#, C (Programming Language)
Experience

Security Consultant - Red Team
Bangalore Urban
Conduct full-scope Red Team engagements simulating APT-level adversaries to assess and improve detection & response capabilities of clients. Develop and execute custom attack paths involving initial access, privilege escalation, lateral movement, and domain persistence. Utilize tools like Cobalt Strike, Havoc, Mythic, Donut, Mimikatz, and custom payloads for stealthy operations. Perform assumed breach assessments, adversary emulation, and purple teaming exercises with blue teams. Bypass security controls such as EDR, AV, AMSI, WDAC, and conduct post-exploitation on Windows and Linux environments. Conduct phishing campaigns, payload delivery via client-side attacks, and command & control operations. Report vulnerabilities and weaknesses with detailed kill-chain mapping, MITRE ATT&CK alignment, and actionable remediation steps.

Penetration Tester
Bangalore Urban, Karnataka, India
Understand the purpose of the medical machine and assets to be pentested, learning the relevance to the Business, and helping to identify the worst case scenarios to focus on their exploitation Execution of the Penetration test activities, registering all the conducted actions, and following trendy TTPs that real attackers are abusing on the wild that can be used as weapon for medical devices and software's. Documentation of the results of the Penetration test activities, including technical documentation Support, on demand, to the penetration testing lead on organizing, following up and reporting Pentest related activities Creation and maintenance of offensive-related toolset, including applications and underlying infrastructure Automation of offensive-related scans, including detection, exploitation and reporting Support to the IT administrators on explaining the exploitation of findings, as well as proposing recommendations and best practices for remediation Support, on demand, to Red Team activities

Penetration Tester
Bangalore Urban, Karnataka, India
Assist in understanding medical devices and their relevance to business needs. Help identify and exploit worst-case scenarios during penetration tests. Document actions and results, follow current attack trends, and create and maintain offensive tools. Automate scans for detection, exploitation, and reporting. Support IT administrators with remediation recommendations and assist in Red Team activities as needed.

Security Researcher
As a security researcher at Hadess , I am responsible for identifying, and working on latest TTPs Involve in Red Teaming to Reproduce & reconstruct them . In addition to my core responsibilities, I also focus on researching and analyzing new threat adversaries. I develop and implement new security research techniques related to red teaming and offensive security and create proof-of-concept (POC) exploits and reports for all types of adversaries. I am confident that my skills and experience make me a valuable asset to Hades and the cybersecurity community.
Surya Dev Singh's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



