Krish Gera

Security Consultant

Clarity for your external risk. Less exposure, less cost.

Offensive-security and OSINT background. I turn messy internet-facing exposure into a short, prioritized plan your team can execute.

Attack surface Brand + identity monitoring Threat intel triage Incident readiness
Reality
Exposure changes daily: new subdomains, misconfigs, leaked creds, impersonation domains.
Risk
If you do not have visibility, attackers do. Delays turn small issues into outages and fraud.
Outcome
You get a prioritized plan, crisp evidence, and a clear path to reduce blast radius.
Ambient Intel
Scanning
Signals

Fixed-scope packages

Designed for one-off work, short engagements, and fast impact. Clear scope, clean output.

Attack Surface Baseline

From £399

Establish what is exposed, what matters, and what to fix first.

  • Asset inventory: domains, subdomains, services, endpoints
  • Exposure review: common misconfigs and high-risk surfaces
  • Prioritized fix plan: severity, likelihood, effort
  • Executive summary + engineer-ready notes
Typical delivery: three to five days, depending on scope.

Brand + Identity Monitoring Setup

From £499

Detect brand abuse and leaked identities early, before it becomes customer impact.

  • Typosquat and impersonation monitoring
  • Credential exposure detection and triage
  • Signal routing: what triggers alerts and why
  • Playbook: what to do when a hit lands
Output: monitoring rules, alert logic, and a response checklist.

Incident Readiness Pack

From £549

Reduce time-to-decision when something breaks. Logging, alerts, and runbooks that work.

  • Response playbooks: triage, containment, comms
  • Logging and alert recommendations (minimal, effective)
  • Evidence capture checklist
  • Tabletop scenario run: one realistic case
Outcome: faster containment and less guesswork under pressure.
Prices are starting points for typical scope. Exact quote depends on asset count and constraints.

Credibility

Recognition
Singapore GovTech GBBP14 Hall of Fame (YesWeHack)
Technical ranking
Former top one hundred global on Hack The Box
Operating model
I work like an internal security lead for teams that do not have one. Practical, low-noise, and focused on what can be fixed.
What you get
Clear evidence, a prioritized plan, and automation where it saves time without creating noise.

Process

Fast, structured, low-drag.

One
Scope lock
We define targets, constraints, and what “done” looks like.
Two
Evidence
I gather signals, validate, and separate noise from risk.
Three
Decision output
You receive a prioritized plan with clear reasoning.
Four
Handover
Engineer-ready notes, plus an exec summary if needed.

Secure contact

If you prefer encrypted communication and are comfortable with using PGP, my public key and fingerprint are below.

Normal email and the contact form below are fine for most requests.

Fingerprint: 08AD 4C2F 5DB6 07EC 163A E2BD 785C DDC3 8590 F40A

View PGP public key (ASCII-armored)
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGlvSn0BEACo+e/bfbqM7wLW+l9IcrfoBb0dxBmcBUeGQRJsfVxrbfKhjsqe
7Rl7bTcsvpozaJfMUESRKDsN5p6xIeEVyEXrwt5244Ot72n8rCG+FrNyMwHmMSYD
qLA26p4TQCj30kajlgzwt1C+dD5H/G5Cp+Sd+9yXPXOuM5bKhZD8yp3wmiaFcQd6
W0C8BlH79UhabMpZFPzTvrnN4oYlEw9rDr8P1w8vso20vYLkh9JMQKj0ulQHz0Ar
jYz5nAZRJ+ii+hjcOYuhiiDwYgUPiyKsIfMNoRyUU6jz/Jk5XVCaQPc8MGNBgGUK
0WUy4nilZuCbk+okIww3TpFh4mkN6CLZG3aUVfL7WM137QpQma7O7w5yWLu0h5U9
axHn03b/Xu7j3xoBTMBhyoj6eOFcCtmt29CqJljJeBxt2B4OMH4PTKYoUd8pZPU3
q3TgGZixf9sHI8lh8QEn1RaU7x0aCdX6bRa3zfZUZDR6j2ytBf8bsqUtd7Ovqn+P
CaYG7a0JGIv2v1VNTfv2Avmy/zM9E769F2wCl+QqsgXTnVRYNEDZukukV6b/qITY
vhwaPX32IhLzDlc104Ts0RBmr9yzpjeoXsjaXf2ghjOeMitW4yDQt9peEHNafmZy
0xw2uZKOjD4ydNrLWxUKGOMwptOCAN5MXtNS1vxddq5xBLLihudydJMy2wARAQAB
tCBLcmlzaCBHZXJhIDxrcmlzaGdlcmFAcHJvdG9uLm1lPokCTgQTAQoAOBYhBAit
TC9dtgfsFjrivXhc3cOFkPQKBQJpb0p9AhsDBQsJCAcCBhUKCQgLAgQWAgMBAh4B
AheAAAoJEHhc3cOFkPQKehcP/29PKruyP4tf/qCodhTk61eoG3vi1q+4DxSdNVuS
7W1CSH5BXNMV17aYmqWwDHC9DtWrDv6CZYNRtGwjEc8QhSgyD6cNzth3I+EylTz0
/HT+0pTq6rDKtvI1hnjN++C9mzqrrLV8lZue9mORzi1gSKBwpLFrue1B+8POhRiz
1g8nWpG3HVNJcPNovMkV+0xzzGXqbWA9etWysN6SDf7iHjIkIuE3S8cv7gWlq/5r
bfJgHdwBJpWzwh921iLKuOlOj8nUyLl4Wg9jXy/QKP+5t90y4DrqvaLuI1k1dP83
tymGB0nfcDjeAjzeuT51g22+5ZhvDejSDHjz679BxMYOmxIfLgo5xddrdCQYS4cB
RKf0ivMnCUTMfuwBLeqqlRVMPABzpF7sVBIw7+v+Tl+Zp88l1Z3mhjSRCsUJYpvB
EpG7VRPxuZbJ/Ipn64BmM1Se0ufWNn9yXNBh0D1aiHqH8T9DpAB7qg/hjDXUa/C7
7b6pN3sfawFOQdCzO7xaX5iJ+dhkQ1MGL/MQ5Ym+pvM5K5QNIOqgSvHwHEEnIidJ
VYSCdrjm7G3Fkag7H6NALIiBxYkO5Y0SAwuvLF6/7+pPpZaHYi8m/lLBeMa+uWbt
kdXA7vTe3kPp9yRNoENX6Zr48AS2Q0qMpSeXrcHP30ARA4A8ORarSjp6v1BRQkqU
qASKuQINBGlvSn0BEAC4znKvchUij3jb+qUey8nm0Lid7Q+pZSGOESiSrVftOCCB
3/ss9pCpOrZjn29DeTJfeUU4PAQSFIJjhR0/AFOfr8B/C7TK07DHZkm82zdYtwY1
r3CkzCzrVr+old+4ZBmmE6jMrw+E1jCIP11fplJKm4vl4C2hAAnn31x7qSctZKK9
17Grfh5IbfCR2YOC3WN4VCM7oVHonBXNnR9mVWfKV4PrWuICC3BSiS5ZBubbVc3y
Y6ujunf1ZazYvqoYR0xuRGuIRt99hG9u0aA/3UWmtcNgQv7z9Okk/QP96bFFMyKC
5lhMwyHOD3bCt4eXMPV/J25AVF73um9RLx/qmdr7Py4Wv5A28eyzV5U09DOlxP28
LVlp3DgqXYipS4lYE68q06XY+xuiPSRB1I7mc8dyfI68oyVlUJNa/KyHIIU3M16T
GL9Y5Ok0ty1xZ3LWU5m74pSGpmSwB/2w2+qIgmndq00F9NZ76GzD4ordMGdVms5L
+ZZBYHRy1CARpdhvFzdE0At/Qza2kL2jiV8FpdopzqBwuTk8mORDCKkZWaXvvUqJ
f8KKaTHPLmyDSlUCCbu0xX69mO4sfZM/7u0xub0sz9ZPAicCUG1u1taFR/in8N3k
4jP68E3Ud3oKR3kwZ5vWI4RHIFSnwV55aOe9ExkV7ikh9MSamve2FAQ9aCD9DQAR
AQABiQI2BBgBCgAgFiEECK1ML122B+wWOuK9eFzdw4WQ9AoFAmlvSn0CGwwACgkQ
eFzdw4WQ9AqVWw//eCcUXkaOCqCBlFeLWECOylDUOopKaprG/9834ouo3Vm396eW
t8G3zlHZtE5J71UgBSrkcbmDydA0mMzEAv7LoCNZZwIIpE9nNWzK1U5fh0eKlNhm
/z/lle2oSRVRHxZEVw7BLXZcJ12aNBohVd4Z8KjZSRO1hcpKcAsSf/juaMtEDWkM
vqYlrGc+MnIT0p9am+HsTGIeiZOZGqHow8DobrZlgHYvj/zbsWPCTTP3mJEhBRN8
PnB4bOxF1dgNTO/fdLJxEX3RVtVlZw4Z0c85inauPkO8EZptLYf+gNiP//Jr5uPZ
LaNy3myyEXNBDQtp973N1xPtb8QbXDagzfEjSbPo/ZhlktXtorD1hwjOiWBiZouX
Ko2ynGSFKa9rFzNC/bZKythhkQDV70dw5rLwJdPtEPFhQKxT3c/5DNSX59pLYuJc
myS+2wCtVHp4OpQ1p5i9xUr6araUAn2ZgYElhhaVMeNgUUX68VBeOiLFfR92vE2Z
J3cgtqU4/7cO221kG2BtH5gk61NYJCl6rhHrQCkpX74url0fxwb4SrylAPqdtmt3
dHkyBdIE4eVmCQ0JaaKStZ3ujG2IcACpRwyVHb+D4wRsopyCr8YI03NztQ0/J9Hk
leARk2qEbfW65BNO0LpX8zRKF4McVW/XH1hxp8Pq4OVrPtquBYKIjI8SYUo=
=LJc+
-----END PGP PUBLIC KEY BLOCK-----

Contact

Fixed packages, one-off reports, and short consulting. I reply via email. Direct: krishgera@proton.me