The Cobalt Pentester Spotlight highlights the fascinating journey of our Core members. Through an interview-style format, we share their experiences, background, and insights into the world of an accomplished pentester.
What's your handle? Do you use more than one? What's the origin story?
I simply use my real name, Gaurav Bhosale, across all my professional work. I've never really felt the need for a hacker alias. I wanted people to associate my work, research, and contributions directly with my name, so I've kept it consistent throughout my career.
What got you into cybersecurity? How did you get into pentesting specifically?
My cybersecurity journey started in 2017 after watching Mr. Robot. Like many people, I was fascinated by the technical side of hacking and wanted to understand how it all worked. At first, I experimented without really knowing what I was learning about phishing, basic attacks, and exploring different hacking techniques.
One of my first real experiences was experimenting with my college's security, including identifying weaknesses in the CCTV system. That curiosity quickly turned into a passion for learning security the right way.
In 2018, I attended my first cybersecurity conference hosted by Null. Meeting experienced security professionals completely changed my perspective. That's when I decided to focus on penetration testing as a career, and I've been passionate about it ever since.
What exploit or clever attack are you most proud of and why?
Business logic vulnerabilities are my favourite type of finding because they can't be discovered by simply running automated tools. They require understanding how the application is designed to work and then thinking about how that logic can be abused.
I'm also particularly interested in sensitive information disclosure issues. Sometimes a small piece of exposed information API keys, internal endpoints, configuration files, or hidden functionality can become the starting point for a much larger attack.
These findings reward curiosity, patience, and a deep understanding of the application rather than relying purely on technical exploits.
What is your go-to brag when talking about your pentesting skills?
If I had to pick one strength, it would be my ability to identify complex business logic flaws. I enjoy understanding how an application works from a user's perspective and then thinking about ways those workflows could be abused. Those are often the findings that create the most value for customers.
Could you share a time something went wrong in the course of a pentest? What happened and what did you do?
Fortunately, I haven't experienced any major issues during a customer engagement. I treat every pentest as a professional engagement built on trust between the customer and the testing team.
Before testing, I make sure I fully understand the scope and rules of engagement. During testing, I'm careful to follow agreed methodologies and avoid unnecessary risk. That disciplined approach has helped my engagements run smoothly.
What are your favorite tools or TTPs when conducting pentests? Why do you find them effective?
Burp Suite and Nmap are the two tools I use on almost every engagement.
Burp Suite is incredibly powerful for analysing web applications, APIs, authentication flows, and business logic. Nmap remains my go-to tool for network discovery, service enumeration, and identifying potential attack surfaces.
While tools are important, I believe methodology and understanding the application are far more valuable than any single tool.
What are your favorite asset types (web applications, APIs, network, etc.) to pentest and why?
I enjoy testing web applications, APIs, internal and external networks, and cloud or CI/CD environments.
Web applications and APIs are especially interesting because they often involve unique business logic, while network assessments require a different mindset focused on infrastructure, privilege escalation, and lateral movement. Switching between different types of engagements keeps the work exciting.
What certifications do you have? Why did you go for those ones specifically?
I currently hold:
- CRTP (Certified Red Team Professional)
- CRTA (Certified Red Team Analyst)
- AI/ML Pentesting certification
I chose these certifications because they focus on practical, hands-on skills rather than multiple-choice exams. I wanted certifications that reflected real-world offensive security knowledge and could immediately improve my work during engagements.
What advice do you wish someone had given you when you first started pentesting?
Don't rush.
Take the time to build a strong foundation. I always describe security as a triangle consisting of Networking, Operating Systems, and Web Technologies. Understanding those fundamentals makes everything else much easier.
Spend time learning networking concepts, Linux and Windows internals, web technologies, and protocols. Platforms like OverTheWire Bandit, PortSwigger Web Security Academy, and Hack The Box are fantastic places to build those fundamentals.
The better your basics, the better your pentesting becomes.
How do you approach explaining findings to customers during a pentest? Is there a way you discuss your findings with customers? How do you ensure they have a quality experience?
I explain findings as if I'm teaching a class.
I assume not everyone in the room has a security background, so I avoid unnecessary jargon and focus on helping customers understand what happened, why it matters, how it could be exploited, and how they can fix it.
My goal is to bridge the gap between security teams, developers, and business stakeholders so everyone leaves the conversation with a clear understanding of the risk.
What is your favorite part of working with a pentesting team? What about working on your own?
Working with other pentesters is one of my favourite parts of the job because everyone approaches problems differently. Every engagement becomes an opportunity to learn new techniques, shortcuts, and ways of thinking.
Working independently is equally rewarding because it pushes me to trust my own methodology, stay disciplined, and continuously improve my skills.
Why do you like pentesting with Cobalt?
What I appreciate most about Cobalt is that it focuses on delivering high-quality penetration testing rather than simply rewarding the number of vulnerabilities found.
The platform gives testers the time, support, and structured methodology needed to deliver meaningful security assessments that genuinely help customers improve their security posture.
Would you recommend Cobalt to someone looking for a pentest? Why or why not?
Absolutely.
Cobalt combines experienced security professionals with a strong methodology, excellent project management, and responsive support throughout an engagement. Customers receive not just vulnerability reports but actionable security guidance backed by a professional team.
What do customers or the media often misunderstand about pentesters?
Many people think pentesters simply run automated tools and generate reports.
In reality, the majority of valuable findings come from understanding how applications work, thinking like an attacker, and spending time exploring complex workflows. Good pentesting is creative problem-solving just as much as it is technical knowledge.
How do you see pentesting changing in 2026 and over the next few years?
AI will certainly change how pentesters work by automating repetitive tasks such as reconnaissance, vulnerability identification, and report generation.
However, I don't believe AI will replace experienced pentesters. The most valuable vulnerabilities, especially business logic flaws and complex attack chains still require human creativity, critical thinking, and experience.
I think AI will make good pentesters even more productive rather than replacing them.
What’s one non-technical skill (e.g., writing, communication, project management) that you believe is becoming critically important for a successful pentester and how do you cultivate it?
Communication.
Finding a vulnerability is only half the job. Explaining the risk clearly, helping developers understand the issue, and recommending practical fixes are just as important.
I continuously improve this skill by writing detailed reports, presenting findings to customers, speaking at conferences, mentoring others, and always trying to explain technical concepts in simple language.
What's your p(Doom)?
Outside of work, I enjoy gaming and spending time with family and friends. It's a great way to disconnect from security for a while, recharge, and come back with a fresh perspective for the next challenge.