ACTIVE_EXPLOITATION_MODE // 2026

Weaponizing code to engineer bulletproof defenses.

Offensive Security Engineer with 5+ years of experience specializing in Red Teaming, Adversary Emulation, custom exploit development, and bypassing modern Endpoint Detection & Response (EDR) solutions.

msfconsole_bypass.py [TARGET: SECURE_HOST]
SCROLL_TO_DECRYPT
[OP_TIME]
0
Years Simulated Campaigns
[CTF_RANK]
AIR 8
NCIIPC Cracking Rank
[BYPASSES]
0
Sigma Exploits Authored

Professional Summary

Understanding defense requires thinking like the infiltrator. I build resilient postures by simulating the adversary.

Over 5 years, my core mission has been simulating advanced persistent threats (APTs) to identify blind spots in enterprise defenses. I specialize in red teaming operations, reverse engineering malware to map TTPs, and auditing system telemetry (Sysmon, Windows Event Logs) to write bypass-resistant monitoring rules.

Tactical Proficiencies

  • Red Teaming & Adversary Simulation
  • EDR Evasion & Privilege Escalation
  • Custom Exploit Development & Scripting
  • Reverse Engineering & Malware Triage

Campaign History

Apr 2026 – Present

PwC Services LLP

Gurugram, Haryana
[OP_PWC_CENTRAL] ACTIVE

Senior Associate (Red Team & Emulation)

  • Simulated 20+ advanced Azure attack vectors to uncover structural cloud vulnerabilities.
  • Engineered KQL detection rules based on emulated attacker behaviors in Microsoft Sentinel.
  • Reduced incident detection bypass rates by ~30% through defensive gap assessments.
  • Assessed client infrastructure robustness via targeted adversary simulation mappings (MITRE ATT&CK).
Aug 2024 – Apr 2026

Attackfence Techlabs

Gurugram, Haryana
[OP_STEALTH_RAIN] ARCHIVED

Security Researcher (Offensive Dev)

  • Developed 50+ custom Sigma detections targeting obfuscated execution and identity compromises.
  • Audited alerts to reduce false-positive rates by ~25% using code tuning.
  • Reverse-engineered malware binaries to extract TTPs and validate evasion rules.
  • Automated payload compilation and simulation pipelines in Python and PowerShell.
Nov 2023 – Jul 2024

Megashop Retail

Remote, India
[OP_MATRIX_DUMP] ARCHIVED

Senior Security Analyst (Threat Emulation)

  • Built 30+ detections identifying credential harvesting, lateral movement, and persistent backdoors.
  • Tuned SIEM rules, reducing noise by ~20% without losing detection fidelity.
  • Analyzed authentication anomalies and SaaS access bypasses across cloud infrastructures.
Aug 2023 – Oct 2023

GMDC Ltd.

Ahmedabad, Gujarat
[OP_INFRA_CRACK] ARCHIVED

Cybersecurity Intern (Exploit Development)

  • Authored 15+ custom Windows Sigma rules focusing on privilege escalation hooks.
  • Developed network signature rules (Suricata) to flag malicious traffic beacons.
  • Validated rule coverage using simulated attacker frameworks.
Jun 2021 – Jul 2023

Megashop Retail

Remote, India
[OP_LOG_PARSE] ARCHIVED

Security Analyst (Operations)

  • Audited 100+ alert channels monthly and mapped complex attack chains into detection signatures.
  • Wrote Python log parsers, reducing command-line file forensics time.
  • Assisted in reverse-engineering suspicious payloads to extract high-fidelity IOCs.

Technical Arsenal

Offensive Security & Red Teaming

Simulating threat scenarios, writing custom exploits, and mapping tactics to MITRE ATT&CK.

Adversary Emulation
Red Teaming / Penetration Testing
Exploit Validation
MITRE ATT&CK Recon

EDR Evasion & Signature Writing

Developing rules to catch stealth operations while understanding how to bypass hooks.

EDR Unhooking & Evasion
Sigma Exploit Signatures
Sysmon & Event Log Auditing
Suricata Rule Development

Defensive Control Systems

Targeting and analyzing ingestion pipelines of major security hubs.

Microsoft Sentinel SIEM
KQL Threat Hunting
Wazuh EDR & Defender XDR

Exploitation Scripts & Automation

Scripting custom automated payloads, scraper systems, and API interceptors.

Python Exploit Scripting
PowerShell PrivEsc Automation
YAML / Sigma Configurations

Malware Reverse Engineering

Decompiling and debugging malicious payloads to extract core behaviors and vulnerabilities.

IDA Pro & Ghidra Static Analysis
x64dbg Dynamic Debugging
Cuckoo Sandbox Triage

GitHub Operations & Arsenal

OPERATION_RAVEN

Autonomous Bug Bounty AI Agent

A self-evolving AI agent built in Python, integrated with the Gemini CLI, to automate application mapping, vulnerability testing, and payload validation dynamically.

  • Discovered 5+ verified logic bugs on live targets.
  • Bypassed safety parameters via contextual prompt engineering.
  • Dynamically compiles and runs 10+ validation modules.
Python AI Red Teaming LLMs API Auditing
raven_agent_console.sh
# ./raven_daemon.py --target api.corp --scan
[*] Launching target mapping... 8 routes identified
[*] Analyzing route /v2/debug/invoice_payload
[!] ALERT: Found IDOR parameter vulnerability
# ./raven_daemon.py --exploit IDOR --bypass
[*] Crafting payload bypass sequence via LLM hooks...
[!] Bypass Successful: Exfiltrated root database records
[✔] Exploit report compiled. Severity Score: 9.1 (Critical)
GITHUB_PROJ

AutoDetect Hub

A fully automated detection engineering pipeline synchronized and executed daily via GitHub Actions.

  • Automated Python pipelines fetch threat feed intelligence logs daily.
  • Compiles rules dynamically to Sentinel-compatible KQL and Sigma configurations.
  • Scheduled workflows deploy signatures to active production environments automatically.
Python GitHub Actions SIEM Deploys Sigma
RED_LAB

Adversary Simulation Lab

A hyper-realistic mock directory forest designed to emulate APT techniques and validation workflows.

  • Simulates process hollowing, LSASS extraction, and remote service attacks.
  • Audits defensive coverage margins against custom built indicators.
  • Calculates metric coverage logs mapped directly to MITRE ATT&CK.
Sysmon Windows AD PowerShell ATT&CK

Exploitations & Bypasses

Trend Micro EDR Kill (Hall of Fame)

Critical Evasion Vulnerability

Honored in the official Hall of Fame for discovering an EDR bypass mechanism. Identified a critical execution flaw that enabled standard, non-privileged local users to terminate and completely disable the Trend Micro EDR solution on endpoints.

NCIIPC CTF AIR 8

All India Rank 8 | 5,000+ Exploiter Cohort

Ranked 8th nationally in a premier government exploitation challenge. Excelled in categories spanning system binary exploitation, cryptography breaking, reverse engineering, and infrastructure infiltration.

Education

M.Tech in Cyber Security

2022 – 2024

National Forensic Sciences University

Gandhinagar, Gujarat

B.Tech in Information Technology

2018 – 2022

Inderprastha Engineering College

Ghaziabad, Uttar Pradesh

SECURE_CHANNEL_ESTABLISHED

Establish Encrypted Link

Reach out over standard routing keys to coordinate penetration tests, simulations, or contract audits.