BugSnaps — my penetration testing and offensive security practice. Application and infrastructure testing against the OWASP methodology, for growing businesses that need findings their developers can actually act on rather than a PDF of raw scanner output.
MyRecon — an OSINT platform that came out of the day job. Username sweeps across 100+ platforms, email breach exposure, and domain, DNS and IP investigation. On the web, on Google Play, and backed by a breach archive that updates daily. Passwords are hashed in your browser, so they never leave your device.
I take on application and infrastructure security work, plus footprint removal for people who need their personal data off the open web.
Same address for a result you think is wrong — those are the most useful messages I get. If a platform reports something MyRecon missed, or reports one that isn't real, tell me and I'll measure it.
Mapping an organisation's attack surface and mapping a person's public footprint are the same exercise with a different subject. You enumerate what is reachable, verify what is real, and discard what only looks like a finding. The third step is the one almost every OSINT tool skips.
Run a username through most tools in this category and you get a wall of green ticks. Click a few and you find pages saying the account isn't there. That isn't a small annoyance — it makes the whole output unusable, because if you can't tell which results are real you have to check all of them by hand, and at that point the tool has saved you nothing.
So MyRecon measures instead of assuming. To test whether a platform can be checked reliably we request a handle we know is real and a string of nonsense nobody could have registered, then compare the responses byte for byte. Several well-known platforms return literally identical pages for both. Those get labelled honestly or excluded — a smaller platform count that is true is worth more than a bigger one that is partly fiction.
| Role | Penetration tester · Founder | CONFIRMED |
| Certification | Certified Ethical Hacker — passed first attempt | CONFIRMED |
| Education | Master's degree, NMIMS Mumbai | CONFIRMED |
| Handle | 4ryanwalia — same on nearly every platform | CONFIRMED |
| What it is | Stack | |
|---|---|---|
| MyRecon | Username sweeps across 100+ platforms, email breach exposure, domain/DNS/IP investigation. Web app, Android app, and a daily-updated breach archive. | Kotlin Python JS |
| Cryptoji / Coffin | Hybrid-encrypted messages encoded as emoji sequences. Premium burial services for your digital secrets. | Django React |
| KINDA-EDR | Endpoint detection and response, small enough to read end to end. | Python |
| Phishing Detection | Classifies a URL as phishing or legitimate from real-world features rather than a blocklist. | Python Jupyter |
| Photo Retrieval | Hand it one selfie and it finds you in a folder of event photos using facial embeddings. | Python Streamlit |
| WhisperDesk | Role-based complaint management with genuinely anonymous submissions and live status tracking. | Spring Boot JWT MySQL |
Pattern of life is the intelligence term for working out a subject's routine, so it seemed the honest label for this. It is deliberately not a heatmap of the year — GitHub already draws one further down this page, and a second copy of it would tell you nothing the first one didn't.
Both panels are rendered from GitHub's own GraphQL API by
a script in this repo, not by a
third-party stats service. The usual one was returning 503 when I
checked — which is exactly the problem with hanging your profile off someone
else's free deployment. The section headers, chips and links are drawn by
another one for the same reason: apart
from the Spotify card, which is my own endpoint, this page makes no request to
anybody else's server to render itself.
If MyRecon saved you an afternoon of manual checking — or the breach archive told you something you needed to know — you can put something in the tin.
scan complete · 4 attributes confirmed · 0 inferred