!DOCTYPE html> About Us — Grey Shield | Offensive Security & Cyber Skills Development
// ABOUT GREY SHIELD

Find the Gaps
Before an Attacker Does.

Grey Shield runs manual-first VAPT and red team engagements across web, network, cloud, and mobile — validating real attack chains instead of handing you a list of CVEs from a scanner. The same engagements shaped Vulnfield, a training platform where learners don't stop at capturing the flag — they patch the vulnerable source themselves and prove the fix actually holds.

Security Testing Was Never
Going to Be Enough

Grey Shield began as a straightforward penetration testing practice — web application, network, cloud, and mobile assessments, plus red team engagements for companies that couldn't risk getting this wrong.

A pattern kept showing up across client work: most researchers we met had cleared certifications and captured flags in sandboxed labs, but few had ever gone back and fixed the vulnerability they'd just exploited. Finding a bug and patching it without breaking the application are different skills — and most training only ever taught the first one.

That project became Vulnfield, and it's still early. Built around the OWASP Top 10, every lab runs the same loop: find the weakness, exploit it and capture the flag, patch the vulnerable code without breaking the feature, then re-run the original attack to prove the fix holds. We're now putting the same energy into a handful of internal tools born directly from client engagements — the kind of gaps you only notice once you've done the work yourself, week after week.

Three Pillars.
One Mission.

Enterprise Security Services

Web application, network, cloud, and mobile penetration testing, red team operations, source code review, and compliance gap analysis — scoped around what could actually go wrong in your environment, not a generic checklist.

Vulnfield — Exploit. Patch. Prove.

OWASP Top 10 labs where learners exploit a real vulnerability, capture the flag, then open the source, patch the root cause, and re-run the original attack to prove it's actually blocked — built and run by the same team that works these attack chains on client engagements.

Security Tools & Products

Internal tooling built to solve problems we've hit ourselves mid-engagement — currently in active development, with details to follow once it's ready to share.

Method Over
Checklist

Every finding in a Grey Shield report is manually verified — chained the way an attacker actually would, not flagged by a scanner and left for you to confirm. Here's who does the work.

Vipin Prajapat

Cyber Security Researcher

Manual VAPT and red team engagements across web, network, and cloud.

Puneet Kumar

VAPT Analyst

Runs vulnerability assessments and retesting across client engagements.

Pardeep Prajapati

Platform Engineer

Keeps servers, deployments, and internal systems running reliably.

Shashank

Security Tools Engineer

Builds and maintains the internal tooling the team relies on daily.

Registered. Recognised. Accountable.

MSME Registered

Ministry of MSME, Government of India

Udyam Reg. No: UDYAM-HR-07-0029134

Want to Test Your Defences
— or Sharpen Your Skills?

Whether you're an enterprise looking for a real security assessment, or a learner looking to exploit, patch, and prove your way through real vulnerability chains, we'd like to hear from you.