tarun koyalwar

About

AI researcher in offensive security at ProjectDiscovery, building the evals, benchmarks, and observability behind Neo, its security agent. The path here was self-taught, by way of bug bounty, then Go tooling, then years running production platform work, and now the problem that has held focus since: proving, with evidence, what these models actually do when pointed at a target.

2026–present

AI-security research

Neo is ProjectDiscovery's security agent. The work here is its observability layer: the harness, the tracing, and the annotation-and-evals-at-scale pipeline that reveal what Neo actually does across a run, not the pass-or-fail summary. An agent that finds a vulnerability is easy to celebrate and hard to trust. Instrumentation is what turns the black box into something a security team can reason about.

The numbers back the approach: 85% on Argus black-box DAST under a hardened, game-resistant methodology. BSides Las Vegas 2026, this August, is the first talk that will be recorded: a behavioral audit across 189 offensive-security LLM runs.

2022–2025

ProjectDiscovery: OSS to platform

Joined ProjectDiscovery for a Go role in 2022, cold-messaged on Twitter with a GitHub full of tools where a résumé should have been.

Was a core maintainer on Nuclei through its v3 era, now past ~29k stars: authored its Go SDK, proposed multi-protocol template execution, and co-developed the JavaScript scripting and flow engine that gave templates logic a YAML matcher could never express. Built Alterx. Then production platform work, the systems that carried ProjectDiscovery from open-source tooling to a product. Now on Neo.

2021–2022

Bug bounty

First bounty landed September 2021. 50+ vulnerabilities reported across that first year, concentrated on one private program. Peak find: a GraphQL IDOR on an e-commerce platform, $6,000, patched overnight. Another paid ~$5,000. ~$15k across the year.

One target gave up three misconfigured S3 buckets, one of them holding a database backup full of PII. The builder instinct took over: Sandman and Talosplus, both written in Go to learn the language. University straight into bounties.

2018–2022

IIIT Pune

B.Tech in Computer Science, Aug 2018 to Jun 2022. Security came self-taught in the third year: CEH coursework, TryHackMe, HackTheBox, and every one of the ~200 labs in PortSwigger's Web Security Academy. Enough reps to prove the lesson that stuck: vulnerabilities follow patterns once the volume adds up.

Skipped campus placement outright, a deliberate bet on bug bounty over a safe first job. GitHub account since Dec 2018: the tooling habit predates the security one.