ICSTwin
A virtual twin of an industrial control network: switches, firewalls, and PLC logic. Next: simulated Modbus, DNP3, and IEC 61850 attacks, plus mapping to India’s CEA 2026 power-sector cybersecurity requirements.
root@byteping:~$ whoami
I investigate how systems fail, document what I find, and build things that make the next failure harder.
$ cat /etc/profile
FOCUS
web security
API security
cloud misconfigurations
ICS/OT + UAV research
$ status --current
researching▌
I’m a cybersecurity student at the National Forensic Sciences University, Delhi, focused on web and API security, reverse engineering, network forensics, cloud misconfigurations, and security research for industrial control systems and drones.
I’m looking for hands-on work in VAPT, application security, and API security. I write detailed, step-by-step notes because a finding is more useful when someone else can reproduce the reasoning behind it.
A virtual twin of an industrial control network: switches, firewalls, and PLC logic. Next: simulated Modbus, DNP3, and IEC 61850 attacks, plus mapping to India’s CEA 2026 power-sector cybersecurity requirements.
Designing a dual-layer MAVLink authentication system combining CNN-based RF fingerprinting with CRYSTALS-Dilithium signatures. The evaluation target is a 20–100 ms real-time budget — no results claimed yet.
Raspberry Pi 3B prototype using OpenCV lane detection, path planning, and ultrasonic obstacle avoidance through a motor-speed feedback loop.
Arduino UNO build with IR sensors, an L298 motor driver, and a custom control script reading infrared reflectivity.
Team leader / team Rudra_Root · also played CRACCON '26 + RAD 2.0
31 challenges: prototype pollution, weak JWT secrets, SSTI, IDOR, mass assignment, path traversal, command injection, native exploitation, steganography, forensics, and OSINT.
read the notes ↗19 challenges covering SSRF to AWS metadata, IAM privilege escalation, S3 enumeration, Lambda secrets, SQLi, IDOR, JWT, signed RPC mass assignment, reverse engineering, and Git-history recovery.
[ writeup link not provided ]Credential leakage, AES token forgery, Shamir secret sharing, zsteg, zero-width characters, Ghidra, ptrace bypass, DNS exfiltration, and timing-jitter covert channels.
read the notes ↗OWASP Top 10 · IDOR · JWT attacks · SQL injection · SSTI · SSRF · command injection · path traversal · mass assignment · prototype pollution · misconfiguration
Burp Suite · Nmap · Wireshark · Metasploit · OWASP ZAP · OpenVAS · Hashcat · curl · Ghidra · GDB · Pwntools
HTTP/HTTPS · TCP/IP · DNS · Linux/Kali · Bash · REST · GraphQL · Git/GitHub · AWS IAM/S3/Lambda
Python · C/C++ · Java · .NET · R · SQL · Node.js · OpenCV · NumPy · Pandas · TensorFlow · SciPy · Matplotlib
Researched AI in surveillance technology: UAVs, CCTV video analytics, facial recognition, and GIS mapping. Authored a technical report.
Conversational data analysis intern. Used an LLM to automate unstructured-data analysis, generate inferences, and explore trends and entity relationships.
Design team volunteer at BSides Dehradun 0x02 and Cyber Security Awareness Month at NFSU Delhi.
For internship conversations, security collaboration, or a good technical rabbit hole.
kdivyanshu832@gmail.com ↗