DEV Community

Destawell
Destawell

Posted on Edited on

Introducing Destawell — Mobile-First Security Research & Open-Source Tooling

Mobile-First Security Research | AI Red Teaming | Open-Source Tooling


Who We Are

I'm Niranj R. Mahaswar — Founder & Lead Security Researcher at Destawell, alongside Shifana (Co-Founder & Brand Strategy), who leads brand strategy and community.

Destawell is a cybersecurity research brand focused on three core areas:

  1. Android Penetration Testing Infrastructure — Building tools for Termux, Kali NetHunter, and ARM64 mobile environments
  2. AI Red Teaming — Testing LLM safety alignment and responsible disclosure
  3. Open-Source Mobile Tooling — Automation-first solutions for security researchers

Why I Started Destawell

The gap between desktop security tooling and mobile environments is massive. Most Termux users struggle with broken dependencies, incomplete Kali deployments, and no clear path for no-root pentesting.

Destawell exists to close that gap.


What We've Built So Far

Tool What It Does
Termux-fixer Automated error resolution for common Termux issues
Kali-Termux-Pro No-root Kali toolchain deployment on Android
Wraith-Scanner Lightweight network discovery for mobile
Kali_Critic Real-time output analysis for Kali Linux

All tools target Android ARM64 and are open-source.


Featured Research

AI Safety — Gemini 2.5 Pro Alignment Bypass
Identified a safety alignment bypass in Gemini 2.5 Pro tied to CVE-2023-32233 (a Linux kernel race condition in nf_tables).

  • Gemini 2.5 Pro → Generated functional exploit primitives
  • Claude 3, GPT-4o, Llama 3, GitHub Copilot → All refused
  • Disclosure: Google IssueTracker #889286 / Google AI VRP — marked out of scope, documentation public

CVE-2026-86046 / GHSA-259w-wmqg-fp76 — termux-sync
Discovered and disclosed a path traversal / zip-slip vulnerability in termux-sync (CVSS 7.1 High, CWE-22).

  • Patched upstream in v1.2.4 by maintainer djunekz
  • Technical writeup published.

NASA Vulnerability Disclosure Program (Bugcrowd)
Active researcher on NASA's VDP, conducting vulnerability research on Earthdata Search and related NASA properties. This work was formally recognized with a Letter of Appreciation from NASA, signed by Kelvin Taylor, Senior Agency Information Security Officer, NASA OCIO (September 2026).


Verified Credentials

  • Ethical Hacking — Cisco Networking Academy
  • Junior Cybersecurity Analyst — Cisco Networking Academy
  • Certified LLM Security Professional (CLLMSP)

Where To Find Us

  • GitHub: github.com/Destawell
  • LinkedIn: linkedin.com/in/niranj-r-mahaswar-0949883b3
  • Instagram: @destawell_off
  • Email: niranjmaheswar0@gmail.com

What's Next

More tool releases, deeper LLM red teaming research, and expanding our mobile pentesting ecosystem.

If you're working on Android security, Termux automation, or AI safety — let's connect.

— Niranj, Destawell

Top comments (1)

Collapse
 
destawell profile image
Destawell • Edited

Official Destawell brand account.Due to some issues the current email is down. You can email at niranjmaheswar0@gmail.com