Dhrumil Mistry

Security clearance dossier

No. CVE-2024-22513

Portrait of Dhrumil Mistry

Mistry Dhrumil

Role
Senior Security Engineer, BrowserStack
Also
Project lead, OWASP OFFAT
Based in
Mumbai, India
Works on
API security, supply chain, zero trust, AI security
GitHub
82 public repos, 1.6k stars, 195 followers

I secure software supply chains, build zero trust access and write the tools security teams use every day. I lead OWASP OFFAT, and I've found account takeover bugs in government and startup APIs.

Page 01

About me

I break things for a living so they don't break in production. At BrowserStack I work on zero trust access, supply chain security and the internal tools our security team runs every day. I also lead OWASP OFFAT, an open source tool that turns an OpenAPI spec into security tests and runs them against your API.

Most of what I know came from building offensive tools in the open, hunting account takeover bugs in the APIs of government bodies, companies and startups, and then automating each finding so the same class of bug can't come back.

I studied Electronics and Telecommunication, which is why I still reach for C, assembly and an Arduino when a problem gets interesting.

Page 02

Experience

  1. Aug 2024 to now

    Senior Security Engineer, BrowserStack

    • Ran a supply chain security programme end to end: SBOMs for every repository and container image, a malicious package detector over the SBOM inventory, and guardrails that stop risky dependencies in repos, images, developer machines and our internal SCA tool.
    • Leading zero trust work: SaaS apps gated to company laptops, BYOD work profiles on Android and iOS, an open source VPN replacement with RBAC, and fleet-wide DLP taken from benchmark to policy.
    • Building an AI security harness that automates the team's daily ops, including an end-to-end flow that gathers context, debugs and fixes issues users report in our internal tools.
    • Made the in-house secret scanner faster, hardened the SCA jobs, and wrote an infrastructure-as-code scanner, Jenkinsfile linters and a Jamf automation wrapper.
    • Enforce MDM policies and CIS benchmarks across the MacBook fleet.
  2. Ongoing

    Project lead, OWASP OFFAT

    • Lead OFFAT (OFFensive API Tester), which reads an OpenAPI spec, generates tests for common API vulnerabilities and runs them.
    • Pentested the APIs of many applications and folded the checks back into the tool.
  3. Jun 2023 to Aug 2024

    Cyber Security Engineer, UniAcco, UniCreds and UniScholars

    • Built in-house security tools in Python and Go for cloud, application, API and IT automation.
    • Hardened the Django apps with middleware against EC2 metadata SSRF, XSS, HTML and null byte injection and path traversal, and added an ML-based Lambda that scans uploaded files.
    • Upgraded Django 3.2 to 5.0 and Python 3.7 to 3.12 across projects, and cleared every known CVE from our container images.
    • Managed AWS WAF through Terraform, firewalls, IDS/IPS, cloud IAM, SIEM and endpoint tooling. Ran regular pentests and helped with disaster recovery and business continuity plans.
    • Wrote custom Semgrep rules integrated with SonarQube, reviewed code for security hotspots, and trained developers on secure coding.
  4. Sep 2022 to May 2023

    Cyber Security Engineer Intern, UniAcco

    • Pentested all three products and drove fixes for PII leaks, account takeover, DoS, XSS and cache poisoning.
    • Built an ELB log analyzer that flags malicious actors in AWS ALB logs, and shipped API security monitoring to production.
    • Led the ISO 27001:2013 certification: scoping, policies and the internal audit.
Page 03

Open source

Live from GitHub, sorted by stars.

  • OWASP/OFFAT

    Automatically tests your API for common vulnerabilities, using tests generated from an OpenAPI spec.

  • pyhtools

    A Python hacking library: network scanner, ARP and DNS spoofers, packet sniffer, credential harvesters and more.

  • Termux-SSH

    Set up an SSH server on Android with Termux.

Page 04

Toolkit

Offensive
Web and API pentesting, reverse engineering, security research and tool development, Burp Suite, OWASP ZAP
Application security
Secure code review, SAST automation with Semgrep and SonarQube, SCA, AI security
Cloud and infrastructure
AWS WAF with Terraform, AWS SDK automation, IaC scanning, SBOMs and supply chain guardrails, SIEM, IDS/IPS
Containers
Docker, Kubernetes, container image hardening, image SBOMs and vulnerability scanning
AI tools
Claude and Claude Code, including a multi-agent security review harness I built on it
Endpoint and access
Zero trust network access, MDM and CIS benchmarks, DLP, Jamf, BYOD work profiles
Languages
Python, Go, C, C++, Java, assembly, shell
Python frameworks
Django, Django REST Framework, Flask, FastAPI
Go frameworks
Fiber, fasthttp, Gorilla Mux and WebSocket, Cobra, gopacket
Foundations
Linux, networking, virtualization, Git, Arduino and IoT
Page 05

Vulnerabilities found

CVE-2024-22513

In djangorestframework-simplejwt, a user whose account had been disabled could keep using a still-valid token to reach protected resources, because the library didn't check whether the user was still active. Read the write-up.

  • Account takeover vulnerabilities in the APIs of government bodies, well-known organisations and startups, recognised in several halls of fame.
  • Vulnerabilities reported to the affected organisations and to CERT-In.
  • Mitigated a DDoS attack during peak season.
Page 06

Education and certifications

Education

  • Bachelor of Engineering, Electronics and Telecommunication Shree L. R. Tiwari College of Engineering, University of Mumbai Aug 2019 to May 2023, CGPA 9.68 out of 10
  • Higher Secondary Certificate (HSC) Jai Hind College Mar 2017 to Mar 2019, 79.38%
  • Secondary School Certificate (SSC) St. Xavier's High School Completed Mar 2017, 87.20%
Page 07

Get in touch

I'm always happy to talk about API security, supply chain attacks, security tooling or a project you'd like to collaborate on. The best way to reach me is a message on LinkedIn.

When I'm not staring at a terminal, I'm producing music and playing whichever instrument is closest. I write long-form notes on my blog.