Cybersecurity Student · Aspiring Ethical Hacker · Security Tool Builder
B.Tech Computer Science (Cybersecurity) student at Ramrao Adik Institute of Technology, D.Y. Patil Deemed to be University, building practical security tools and competing in CTFs while leading a 30-person technical team as IEEE Student Branch Technical Head.
- 🔭 Currently building: client-side security tools (steganography, password auditing) and preparing for roles in VAPT and threat detection
- 🛡️ Recently: completed a Cybersecurity Internship at Elevate Labs, covering VAPT and SIEM-based incident response
- 🎯 Organized:Technovate CTF — a national-level CTF I ran independently, securing ₹9+ Lakhs in sponsorship through direct outreach
- 🌱 Currently learning: Number Theory and Generative AI / agentic systems
- 👯 Looking to collaborate on: AI-assisted defensive security tooling
- 🤔 Looking for guidance on: advanced malware analysis
- 💬 Ask me about: penetration testing, SIEM (Splunk/Wazuh), CTF strategy, applied cryptography, or AI tooling
- 📫 Reach me:LinkedIn · yash18xd@gmail.com
| 🥇 | AI Security CTF Challenge — Winner, Redfox Security (Jan 2026) |
| 🚩 | SecLeaf Q2 CTF 2026 — Rank 48 / Top 7% Global (May 2026) |
| 🎯 | TryHackMe — Top 2% Global, 190+ rooms solved |
| 🏴 | HackTheBox — Cyber Apocalypse CTF 2025 — Top 19% (1519 / 8130 teams) |
| 🚩 | Boro CTF 2026 — Rank 59 Global |
| 🎓 | Samsung Innovation Campus — AI & Machine Learning Certification |
SteganoGuard — Client-side LSB steganography tool with AES-256-GCM encryption and HMAC-SHA256 integrity verification. Hides messages inside PNG/BMP images with zero server-side data transmission.
Password Guardian — Privacy-first password strength analyzer with real-time entropy scoring and HaveIBeenPwned breach detection via k-anonymity — the actual password never leaves the browser.
SIEM Dashboard — Self-hosted SIEM dashboard with syslog ingestion, a declarative correlation engine for detecting brute-force/port-scan/injection attacks, JWT-secured REST API, and a live React dashboard. FastAPI + SQLAlchemy backend, tested with pytest, CI'd on every push.
Penetration Testing & Analysis: Nmap · Wireshark · Burp Suite · Metasploit · Nikto Password & Hash Analysis: John the Ripper · Hydra · Hashcat SIEM / Detection: Splunk · Wazuh Frameworks & Standards: OWASP Top 10 · MITRE ATT&CK · CVE Analysis · Zero Trust Security Domains: Vulnerability Assessment · Incident Response · Threat Intelligence · Network Security · OSINT