Cybersecurity Analyst | Threat Intelligence | Vulnerability Assessment | CVE Research | Security Research
I build practical security tools, investigate published vulnerabilities through controlled experimentation, and translate technical findings into actionable defensive intelligence.
My work focuses on threat intelligence, vulnerability assessment, CVE research, and security automation. Rather than accepting published security claims at face value, I enjoy validating them through reproducible experimentation, careful measurement, and transparent reporting.
With a multidisciplinary background in Computer Applications, Biochemistry, and Chemistry, I approach cybersecurity as an evidence-driven discipline: formulate a hypothesis, build a controlled environment, measure the outcome, and document findings that others can reproduce.
Research Summary
Objective: Re-evaluate CVE-2016-6210 on a modern default OpenSSH deployment.
Method: Manual probing, Hydra, and Metasploit were used to collect authentication timing measurements. Welch's t-test and Cohen's d were applied to distinguish genuine timing signals from measurement noise.
Finding: No statistically significant timing difference was observed on the tested Ubuntu Server default PAM configuration, indicating that the documented timing side-channel was not reproducible under these conditions.
This project re-investigates CVE-2016-6210, an OpenSSH username enumeration timing side-channel, to determine whether it remains observable on a modern Ubuntu Server configured with default PAM authentication.
Rather than relying on visual inspection of response times, the project evaluates timing measurements statistically. The outcome is a reproducible validation study demonstrating that carefully supported negative results can be as valuable as positive findings when assessing the current security posture of published vulnerabilities.
Stack
Python • OpenSSH • Hydra • Metasploit • Ubuntu Server • Kali Linux
Python-based vulnerability assessment platform integrating reconnaissance, CVE intelligence, weighted risk scoring, and automated reporting into a single workflow.
Features include:
- DNS Enumeration
- SSL/TLS Inspection
- HTTP Security Header Analysis
- Technology Fingerprinting
- OSINT Integration
- CVE Correlation
- HTML/PDF Reporting
Stack
Python • AsyncIO • NVD API • Shodan • HTML • PDF
Technical reports analysing recent vulnerabilities through:
- CVSS Assessment
- MITRE ATT&CK Mapping
- Exploitation Context
- Indicators of Compromise
- Detection Opportunities
- Defensive Recommendations
Collection of Python and SQL security scripts covering log analysis, detection engineering exercises, access control automation, and introductory threat hunting.
Artificial Intelligence in Aging Research: Advanced Models for Detecting and Targeting Cellular Senescence
Co-author of a peer-reviewed publication investigating deep learning approaches for cellular senescence detection.
Published in
Madhya Bharti Journal
UGC CARE Group I
Vol. 86, No. 7 (2025)
Contributed to the official MITRE ATT&CK Python library by:
- Identifying an AttributeError in the navlayers exporter
- Implementing the fix
- Expanding automated regression test coverage
- Submitting a pull request currently under maintainer review
- Infrastructure Security
- Detection Engineering
- Threat Hunting
- Applied Cryptography
- Cloud Security
I'm always interested in cybersecurity research, vulnerability analysis, open-source collaboration, and conversations about infrastructure security and threat intelligence.
