whoami
I am a Security Analyst @ CrowdStrike. I like tinkering with technology, messing up my computer, and taking pride in fixing it back. These days I love reversing malware samples and building automation projects within my current security firm.
whoami -v
I started as a technical content writer as a CompSci major student. My interactions brought me in circles of developers and cool projects which slowly sparked my creativity in tech. Once a web developer, I delved into Sys Admin, networking and made my way to DevOps where I discovered system security. Since then, I have built my own projects, contributed in other's cool ones, and that's how I got introduced to the FOSS world. Over the years I have improved on my technical skills, spoke at OSS events, wrote blogs and continued in mentoring newbies.
Love Working On:
- Fuzz testing libraries, reading a emulating assembly with unicorn, reversing malware samples and analysis using FlareVM.
- Monitoring and Automating Cloud Services workflows. Have worked with various services on AWS and GCP. Experience with IAM, policies and group management.
- Kubernetes and Docker Security. Secret Management and Rotation using Vault and Cluster hardening using kskan and monitoring using Falco. Proficient in docker environment workflow.
- Linux kernel enthusiast, writing automation tools in bash and python to make life easier.
/proc/self/status
-
Security Analyst, CrowdStrike
(SEPTEMBER 2024 - PRESENT)
Part of Falcon Complete Team. -
Open Mainframe Project, Software Discovery Tool - Steering Committee Member
(SEPTEMBER 2021 - PRESENT)
/usr/local/bin/
-
ARM processor emulation on Unicorn
Using Unicorn CPU emulator to emulate pico firmware and study assembly. -
Laufeyson, Domain Recon Framework
Laufeyson is a dedicated fast growing Domain Recon framework capable of gathering intel on a domain or an IP. -
Bypassing CSP, File Forensics
A small project focussed on how polyglot files can be taken advantage of in bypassing CSP rules for Reflected XSS attacks. -
GNU toolchain on InterProcess Communication(IPC)
Built a semi-system of two processes and studied every possible route of process handling using signals and shared memory segments. -
Deploying application using Voice assistant driven pipeline
A Voice-to-Code implementation where you can deploy/create and feature branch of an applications by completely using Alexa/Google Home. -
Hardware implementation - A Computer from scratch
A project that mainly focuses on building a computer right from scratch, starting from the level of gates to registers, to reaching CPU and the assembler. -
DevSecOps-Automation-Monitoring
Contains all types of automation scripts that can be used by Devops practisioners for automating daily workflows. -
Keka Reminder Bot
A bot that is capable of sending scheduled messages (default telegram allows per message scheduling) which works for months with minimal memory consumption. -
New Tab Extension
Built a simple new tab extension that supports chrome and firefox browsers. Available on Firefox Add-ons.
/usr/src/contrib/
-
OWASP Maryam, OSINT Framework
Maryam is a dedicated fast growing OSINT framework capable of scraping and gathering large amount of Data. A project under OWASP. -
Software Discovery Tool by OpenMainframe Project
Software Discovery Tool helps match developers with the best open source software that meets their needs.
/mnt/external/
-
AWS Community Builder
(MARCH 2022 - MARCH 2023) and again (MARCH 2024 - MARCH 2025)
Selected as part of AWS 2022 and 2024 Cohort while I learn more about Cloud based on AWS paid credits. -
GHC Scholar and OpenSource Mentor 2021
(SEPTEMBER 2021 - DECEMBER 2021)
Selected as a GHC scholar by AnitaBorg for 2021 for showing exemplary skills and quality as Women In Tech. -
IBM Z Ambassador 2021
(SEPTEMBER 2021 - DECEMBER 2021)
Getting connected with professionals from IBM Z and explored the Mainframe ecosystem. -
DSC HIT — Outreach Team Director, Core Team Member
(AUGUST 2018 - SEPTEMBER 2021)
Event management, community outreach and security instructor in the developer community. -
Pycon India, Co-Organizer
(AUGUST 2021)
Spreading the love of Python communities. -
CTF Challenge Creator and Community Staff, Omicronctf — Community Moderator
(SEPTEMBER 2020 - NOVEMBER 2020)
A newly formed community, focussed on creating ctf challenges for people new to infosec training. -
Grayhat CON 2020 Helpdesk, Online
(OCTOBER 2020)
Second biggest international conference for cybersecurity professionals. -
Devfest Kolkata '19 — Social Media Coordinator
(4th-5th AUGUST 2019)
Media outreach, event handling and help desk at the developers' conference.
/var/log/events/
-
Divulging your social profile — Open Source Intelligence
(NOVEMBER 2020) ONLINE -
Dumb Browser ft. Smart Policy
(JUNE 2021) ONLINE -
Looking for Open Source Software on Z?
(SEPTEMBER 2021) ONLINE -
Who Begat Python?
(SEPTEMBER 2021) ONLINE -
Software Discovery Tool!
(SEPTEMBER 2021) ONLINE -
Let Your Voice Assistant Deploy Your Code!
(MAY 2022) OFFLINE
/var/log/blogs/
-
I got my hands on a Raspberry Pi Pico firmware.
So I reversed it on Ghidra and emulated it on Unicorn. -
GNU toolchain on InterProcess Communication(IPC)
Run, break, study, re-run, dump. The 3G from GNU tool chain is here to make your life easier. -
Abusing CSP, File Forensics
Your website might be the shiniest of all, however, do you have the correct 'policy' afterall? -
Troubleshooting USB Flash Drive Detection in the Linux Kernel
Why you should boot a self compiled kernel atleast once in your life. -
I told my Alexa to merge develop to main
Are you lazy like me? If you love automation, read on. -
Distro Sickness, is it real?
I installed 6 linux distributions and Windows 7, 10 versions in last 24hrs and this is what I found out. -
Exploring Nmap, Interesting and Useful Flags
Port Scanning opened new doors in my Networked Brain. Here's few. -
Malware Analysis using Radare2
Breaking down infections for fun. Exploring r2 while breaking down the first ever discovered malware for Apple M1 chips.