Available for opportunities

Gali
Lokesh

Security researcher specializing in web application penetration testing and bug bounty hunting. I uncover authentication flaws, race conditions, XSS, IDOR, SSRF, and business logic vulnerabilities across responsible disclosure programs.

Gali Lokesh
10+
Organizations Secured
3+
Bug Bounty Platforms
HOF
Multiple Recognitions

About

Who I Am

I am a security researcher focused on web application penetration testing and bug bounty hunting. I actively test live applications to uncover vulnerabilities including authentication bypasses, race conditions, XSS, IDOR, SSRF, SQL Injection, and business logic flaws.

My methodology combines deep manual analysis with automated reconnaissance. I have secured 10+ organizations through responsible disclosure and earned Hall of Fame recognition across multiple programs on Intigriti, Bugcrowd, and private responsible disclosure programs.

I also build open-source tooling — including ReconDragon-X-Ultimate — to streamline bug bounty recon workflows for the community.

Vulnerability Classes
XSSIDORSSRF SQL InjectionAuth Bypass Race ConditionsBusiness Logic HTML Injection
Security Tools
Burp SuiteNmapNuclei SQLMapSubfinderHTTPX GAUFFUFGhauri Kali LinuxWaybackurls
Languages
Shell ScriptingPython JavaScriptJava

Experience

Work History

Independent Security Researcher
Bug Bounty — Self-Directed
2025 — Present
Conduct manual web application penetration testing across live bug bounty programs on Intigriti, Bugcrowd, and private responsible disclosure programs. Successfully secured 10+ organizations by identifying and responsibly disclosing critical vulnerabilities. Earned multiple Hall of Fame recognitions. Built ReconDragon-X-Ultimate, an automated recon framework used across bug bounty workflows.

Recognition

Hall of Fame

🏆
Intigriti
Responsible Disclosure
🏆
Bugcrowd
Responsible Disclosure
🏆
Private Programs
Multiple Recognitions
🔒
10+ Organizations
Secured via Disclosure

Projects

Security Tools

🐉

ReconDragon-X-Ultimate

Automated bug bounty reconnaissance framework built with shell scripting. Integrates Subfinder, PureDNS, MassDNS, HTTPX, GAU, Waybackurls, Hakrawler, Arjun, FFUF, and Nuclei into a unified workflow. Generates reports and sends Telegram notifications on scan completion.

View on GitHub →

Write-ups

Research & Blog

✍️

Medium Blog

Technical write-ups covering real-world vulnerability discoveries, exploitation techniques, and bug bounty methodology from live programs and responsible disclosures.

Read on Medium →

Credentials

Certifications & Education

📜
Burp Suite: Hands-On Testing on Real Sites with Bug Bounty
Udemy — 2026
View Certificate
📜
Advance Live Bug Bounty & Ethical Hacking
Udemy — 2026
View Certificate
🎓
B.Tech — Electronics & Communication Engineering
Narasaraopeta Engineering College (NEC) — Expected 2027

Contact

Get In Touch

✉️
Email
galilokesh7@gmail.com
💼
LinkedIn
lokesh-bugwrith
🐙
GitHub
Lokesh-BugWraith
🔍
Intigriti
bugwraith
🐛
Bugcrowd
bugwraith
✍️
Medium
@bugwraith