10+Projects
Offensive tooling, simulations, and security research



Offensive Security Researcher specializing in adversary simulation, malware engineering, forensics, and threat intelligence operations. Building controlled attack-chain research for real-world defense readiness.
Professional engagement, security collaboration, and operational communication conducted through verified channels only.
OPERATIONAL METRICS
10+Projects
Offensive tooling, simulations, and security research
3Publications
Deep-dive analysis on real-world attack patterns
6+Years Experience
Adversary mindset across multiple domains
4Core Focus Areas
Red Teaming • Malware • Recon • Engineering
Offensive security research and adversary-focused capability development conducted within controlled and ethically scoped testing environments.
Attack surface discovery, infrastructure mapping, intelligence collection, and adversarial footprint analysis across public and semi-public sources.
Security assessment of modern web applications involving authentication flows, business logic analysis, API security, and vulnerability research.
Internal and external network assessment focused on exposure analysis, service enumeration, protocol weaknesses, and trust-boundary evaluation.
Adversary simulation exercises covering initial access, lateral movement, persistence methodologies, and objective-oriented attack-chain execution.
Development of custom tooling, automation pipelines, and operational frameworks designed to emulate adversarial scale under controlled conditions.
Research into payload development, loaders, crypter experimentation, evasion methodologies, and offensive capability prototyping.
Artifact analysis, incident triage, forensic timeline reconstruction, compromise assessment, and evidence-aware investigative workflows.
No VPN, password manager, or encrypted app saves you if you're careless. Habits matter more than gadgets.
Treat every system, account, and device as potentially compromised. Don't assume anything is private or safe by default.
Use verified, end-to-end encrypted messaging when discussing sensitive matters. Verify contacts before trusting them.
A verified contact proves identity, not device integrity. Trusted people can still operate from compromised systems.
If a device or account appears compromised, disconnect it and stop using it. Continued usage increases exposure.
Separate devices, accounts, communication channels, and identities across different operational domains.
Behavioral patterns, timing, relationships, and movement expose more than message content.
Trust is temporary and must be continuously validated. People, systems, and environments change.
Urgency, familiarity, fear, and authority are operational attack surfaces. Skepticism is part of security.
If the endpoint is compromised, encryption becomes irrelevant. Physical and local system integrity comes first.
Overcomplicated routines fail under pressure. Consistent fundamentals outperform elaborate systems.
Static routines increase trackability. Vary timing, devices, movement, and communication methods.
Records provide accountability and recovery, but unsecured logs become intelligence assets for adversaries.
Every platform, service, application, or dependency expands the exposure surface.
Recovery paths, offline backups, and operational redundancy are part of security, not separate from it.
Real-world tooling and frameworks. Public where appropriate, restricted where disclosure would reduce research value.
High-capacity DNS intelligence engine designed for extensive infrastructure mapping and behavioral correlation.
Mohini, codenamed Agent R.A.M.B.H.A, is a next-generation Cyber Deception & Red Team Operations Framework built in Golang for manipulation, invisibility, and controlled chaos
Traditional DNS resolvers are stuck in the past - slow, opaque, and architected for a trust model that no longer exists. HopZeroDNS is a next-gen recursive DNS resolver purpose-built for today's threat landscape, with performance, traceability, and cryptographic assurance as its core principles.
IDify is a decentralized application (dApp) and protocol that redefines how resumes, credentials, and reputations are managed, verified, and trusted - all on-chain.
Mayabati is a personal AI chef designed for enhancing the culinary experience. Crafted by Biswadeb Mukherjee.
A security-first, lightweight application designed to assist penetration testing by providing a controlled, hardened environment for practicing and validating offensive security skills.
If you find value in the research and projects presented here, you may choose to support this work through Buy Me a Coffee. Your support helps sustain ongoing research, project development, and the infrastructure required to maintain these initiatives. Before making any contribution, please review the Payment & Support Rules.
Selected papers and technical write-ups documenting investigations, methodologies, and outcomes.
High-throughput DNS intelligence framework enabling large-scale infrastructure analysis and behavioral correlation.
The investigation documents observable, non-intrusive indicators associated with multiple publicly accessible websites impersonating or mimicking Indian identity-related services.
A study on offline AI-driven recipe and diet assistant workflows, including usability and practical adaptation patterns.
Certifications, research recognitions, and formally validated competencies.
Offensive security methodology, reconnaissance, exploitation and post-exploitation discipline aligned with adversarial simulation standards.