I build security tooling on both sides of the engagement: offensive frameworks that model how intrusions actually happen, and detection systems that measure whether anyone would have noticed.
B.Tech in cybersecurity; research intern. Recent work centres on Android kernel telemetry and metadata-resistant communication.
Chiral — Attributes security-relevant kernel events, from network egress to credential-adjacent file access, to installed Android packages rather than to PIDs or UIDs. Rust, eBPF
Parda — End-to-end encrypted messaging built to resist metadata analysis, not only content interception. Rust
mirrorlab — Simulates ATT&CK techniques against a Sigma ruleset to establish which attacks the rules actually catch. Python
DARPAN — Multi-protocol deception framework for threat-actor profiling and campaign tracking. Python
spoofed — Async network spoofing suite for authorized auditing: IPv4/IPv6 interception, LLMNR/NBT-NS poisoning, tamper-evident audit logging. Python
wifi_down — Automated WiFi security auditing across the full pipeline — scan, attack, crack, report. Python
Python and Rust, primarily; Go, TypeScript, Dart and eBPF where the problem calls for it.
Offensive tooling here is written for authorized testing.
Open to work — swastik362004@gmail.com


