Skip to content
View rakshit-737's full-sized avatar

Block or report rakshit-737

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
rakshit-737/README.md
Terminal: whoami → Rakshit Rameshbabu, Software & Security Engineer, B.Tech CSE (Cyber Security) at VIT Chennai. A radar sweeps across his public security repos.

detection-as-code, measured on real telemetry · provenance graphs to root cause and blast radius · static analysis that never runs the sample · attribution that can say I don't know · every number regenerates from one command

Portfolio: rakshit-737.is-a.dev LinkedIn: rakshit-rameshbabu Email: rakshitoffl@gmail.com Resume (PDF) CyLab Academy

❯ cat about.md

I'm a B.Tech CSE (Cyber Security) student at VIT Chennai (CGPA 9.07, class of 2028). I build defensive security tooling and full-stack products, and I take them end to end: written requirements, architecture, CI, then a release.

Every repo is held to one rule: every number regenerates from one command. That means public datasets, committed results, baselines run on identical inputs, and a Limitations section that says what does not work. The security tools are defensive and lab-safe: static where possible, sandboxed where not.

# ~/.config/rakshit.yml
now:
  - wiring 13 detection / DFIR / CTI engines into one evidence graph   # throughline
  - Warden v2: supply-chain firewall for PyPI, manifests and images    # warden
  - taking Fillwright toward a Chrome Web Store release                # fillwright
research: ML job scheduling, reported as a negative result             # proactive-feasibility-scheduler
interests: [detection engineering, DFIR, supply-chain security, AI-agent security, post-quantum crypto]
open_to: internships & full-time roles in software / security engineering

❯ ls ~/featured

Note

Every number on these cards is copied from the linked repo's README or committed results/. Where a result is synthetic or simulated, the card says so.

THROUGHLINE: evidence-first security knowledge graph WARDEN: software supply-chain security platform NIKASHA: fact-checks vulnerability reports against source AFTERLOCK: Kubernetes containment verifier ANVIL: detection-as-code for Sigma SLUICE: information-flow control for LLM agents Proactive Feasibility Scheduler: ML scheduling evaluation with a negative result DOCFORGE: local-first document studio FILLWRIGHT: privacy-first resume autofill extension FEELSLIKE: digital-twin HVAC optimizer

❯ throughline --map

Thirteen single-purpose security engines, each benchmarked on its own, plugged into one graph. THROUGHLINE fuses them, so what happened, how did it start, who did it, and how sure are we? becomes one query.

THROUGHLINE map: ANVIL, GAUNTLET, VANTAGE (detection), REVENANT, ROOTLINE (DFIR), DRAGNET, OCCAM (intel), VITRINE, SPECIMEN (malware), FEINT (network), LINCHPIN, STRATUM, TRACEGATE (infra and supply chain) all feeding one evidence graph

open the full arsenal: every security repo, one measured headline each
domain repo headline (from the repo's own results)
detection engineering ANVIL 461/461 evaluable SigmaHQ regression cases detected; 2,994,137 benign events replayed against 2,803 rules
purple team GAUNTLET replays 96 real OTRF attack recordings through 2,519 SigmaHQ rules; ranked gaps and a CI regression gate
control coverage VANTAGE CIS IG2 on classic Windows logs: 53.9% claimed ATT&CK coverage vs 11.2% defended
DFIR timelines REVENANT confidence-graded incident stories; every claim cites the SHA-256 of its event; append-only custody ledger
attack reconstruction ROOTLINE ATLAS S1–S4: event F1 0.559 vs 0.077 for IOC grep; graph reduction 3.8–4.4× with 100% of attack edges kept
attribution DRAGNET right group ranked first in 68% of 25 ATT&CK campaigns; never commits at MEDIUM+ to a wrong actor
CTI reasoning OCCAM under planted false flags, names the framed group 1.1% of the time vs 88.0% for TTP similarity
malware triage VITRINE EMBER 2018 temporal split: ROC AUC 0.9917, 74.5% TPR at 0.1% FPR; never executes a sample
malware pipeline SPECIMEN static gate skips 42% of detonations, misses 1.2% of malware; 95.9% family accuracy on 48,976 CAPEv2 reports
NIDS robustness FEINT XGBoost at 99.7% clean accuracy detects 42% of flows under realisable evasion; adversarial training restores 80–96%
attack paths LINCHPIN exact minimum remediation cut over scanner, BloodHound and EPSS/KEV data; sends no packets
cloud-native STRATUM F1 1.000 on 148 upstream PSS conformance pods; 32 of 87 real workloads not PSS-restricted
CI/CD provenance TRACEGATE finding → introducing commit: 97.5% (356/365) vs 17.3% for the best baseline
K8s containment AFTERLOCK Go collector + Python planner; live kind lab agrees with the model on 17/17 steps across 3 runs
supply chain WARDEN 14 static analyzers, SBOM + SARIF + CI gate; 2,908 backend tests in CI
vuln-report triage NIKASHA v0.1.0 on PyPI; 0/126 genuine curl reports falsely flagged (Wilson 95% upper bound 2.96%)
agent security SLUICE · taintwall taintwall: exfiltration 43% → 0% with all four layers, benign utility held at 100%
state reconstruction SPECTRA pre-alpha: a Python reference slice runs end to end; no milestone is green yet, and the README says so

❯ ls ~/also-built

  • PlantPal+: plant care, fitness and nutrition on one habit loop. TypeScript monorepo (Expo, React + Vite, Express, PostgreSQL) with an IEEE-830 requirements package: 228 FRs, 119 user stories, 89 use cases.
  • RailMind: a digital twin of a 21-station railway network feeding LangGraph agents that score incident-response plans. Runs offline, no API keys.
  • portfolio: a candlelit, scroll-driven Next.js site. CI gates Lighthouse, axe, CSP and link checks; accessibility, best-practices and SEO score 100.
  • VIT CGPA Calculator · learn-sql · PaceReader · ZT Web Security Simulator: small tools for studying and campus life.

❯ which --all

Python, TypeScript, JavaScript, Go, C, C++, Java, Bash, Linux
FastAPI, Django, Node.js, Express, PostgreSQL, Redis, MongoDB, SQLite, Supabase
React, Next.js, Tailwind, Vite, PyTorch, scikit-learn, Docker, Kubernetes, GitHub Actions, AWS, Vercel, Git

Security toolchain: Sigma, YARA, MITRE ATT&CK, Sysmon, Volatility 3, plaso, eBPF, Trivy, Syft, OSV, OPA/Rego, Tetragon, BloodHound, nmap, OpenVAS, NVD/EPSS/KEV, XGBoost, SHAP, LangGraph, MCP and more

❯ tail trophies.log

trophies.log: 2025-06-21 FIRST PRIZE, Cyber Secure 360 Expo 2025, SCOPE, VIT Chennai · 2026-06 TOP 100, FarAway Zuup Hackathon, of ~11,000 participants · 2026-08 FINALS, FeelsLike (Team Goldilocks), digital-twin building optimizer · 2026-09-17 RELEASE, Warden v2.0.0, supply-chain security platform · 2026-09-20 RELEASE, Fillwright v0.6.1, privacy-first autofill extension · 2026-09-26 RELEASE, Nikasha v0.1.0 on PyPI, GHCR and GitHub Releases · ongoing: CGPA 9.07, B.Tech CSE (Cyber Security), VIT Chennai, class of 2028

❯ gh telemetry

GitHub telemetry: contributions, commits, pull requests, stars and streaks, with a 52-week heatmap Language breakdown by bytes across public repositories

3D contribution calendar A snake eating the contribution graph
how this profile builds itself
flowchart LR
  API[("GitHub GraphQL API")] --> CARDS["build_cards.py<br/>telemetry · languages · project cards"]
  ART["build_art.py<br/>hero · taglines · buttons · map · trophies"] --> GIT
  API --> SNK["Platane/snk<br/>contribution snake"]
  API --> D3["github-profile-3d-contrib<br/>3D calendar"]
  CARDS & SNK & D3 --> GIT["profile.yml<br/>daily at 01:47 IST · on script changes"]
  GIT -->|git commit| SVG["assets/ + generated/*.svg"]
  SVG --> README(["this README"])
  classDef n fill:#0a0e14,stroke:#00e38c,color:#e6edf3
  classDef hub fill:#00e38c,stroke:#00e38c,color:#0a0e14
  class API,CARDS,ART,SNK,D3,GIT,SVG n
  class README hub
Loading

The hero, tagline banner, link buttons, toolchain, map, trophies log and footer are hand-built animated SVGs (scripts/build_art.py): SMIL only, no JavaScript, with a subset of JetBrains Mono embedded so they render the same on every OS, and every animation rests on its finished frame. The public instances of github-readme-stats, trophies and activity-graph now return 503/402, so the telemetry and language cards are generated here instead. Apart from the skill icons, every image on this page is served from this repo.

exit: process completed

Popular repositories Loading

  1. proactive-feasibility-scheduler proactive-feasibility-scheduler Public

    A learned wait-time score cannot rank a queue by anything except requested size — a negative result with zero counterexamples over 45,432 dispatch instants on the reference platform (45,268 and zer…

    Python 1

  2. warden-supply-chain-security warden-supply-chain-security Public

    Warden, a software supply-chain security platform. Analyses PyPI packages, project manifests and container images without running them: behaviour, provenance, vulnerabilities, SBOMs, release drift,…

    Python 1

  3. portfolio portfolio Public

    my little corner on the internet

    TypeScript 1

  4. docforge docforge Public

    Local-first document studio — write Markdown, export typeset PDFs and native Word (.docx) files with TOC, footnotes, citations, equations and cross-references. No account, works offline.

    TypeScript 1 1

  5. gauntlet gauntlet Public

    Threat-informed purple-team coverage scoring: ATT&CK CTI prioritization, replay of real recorded attacks (OTRF) through SigmaHQ rules, Navigator export, CI regression gate

    Python 1

  6. My-DSA-Journey My-DSA-Journey Public