I'm a B.Tech CSE (Cyber Security) student at VIT Chennai (CGPA 9.07, class of 2028). I build defensive security tooling and full-stack products, and I take them end to end: written requirements, architecture, CI, then a release.
Every repo is held to one rule: every number regenerates from one command. That means public datasets, committed results, baselines run on identical inputs, and a Limitations section that says what does not work. The security tools are defensive and lab-safe: static where possible, sandboxed where not.
# ~/.config/rakshit.yml
now:
- wiring 13 detection / DFIR / CTI engines into one evidence graph # throughline
- Warden v2: supply-chain firewall for PyPI, manifests and images # warden
- taking Fillwright toward a Chrome Web Store release # fillwright
research: ML job scheduling, reported as a negative result # proactive-feasibility-scheduler
interests: [detection engineering, DFIR, supply-chain security, AI-agent security, post-quantum crypto]
open_to: internships & full-time roles in software / security engineeringNote
Every number on these cards is copied from the linked repo's README or committed results/. Where a result is synthetic or simulated, the card says so.
Thirteen single-purpose security engines, each benchmarked on its own, plugged into one graph. THROUGHLINE fuses them, so what happened, how did it start, who did it, and how sure are we? becomes one query.
open the full arsenal: every security repo, one measured headline each
| domain | repo | headline (from the repo's own results) |
|---|---|---|
| detection engineering | ANVIL | 461/461 evaluable SigmaHQ regression cases detected; 2,994,137 benign events replayed against 2,803 rules |
| purple team | GAUNTLET | replays 96 real OTRF attack recordings through 2,519 SigmaHQ rules; ranked gaps and a CI regression gate |
| control coverage | VANTAGE | CIS IG2 on classic Windows logs: 53.9% claimed ATT&CK coverage vs 11.2% defended |
| DFIR timelines | REVENANT | confidence-graded incident stories; every claim cites the SHA-256 of its event; append-only custody ledger |
| attack reconstruction | ROOTLINE | ATLAS S1–S4: event F1 0.559 vs 0.077 for IOC grep; graph reduction 3.8–4.4× with 100% of attack edges kept |
| attribution | DRAGNET | right group ranked first in 68% of 25 ATT&CK campaigns; never commits at MEDIUM+ to a wrong actor |
| CTI reasoning | OCCAM | under planted false flags, names the framed group 1.1% of the time vs 88.0% for TTP similarity |
| malware triage | VITRINE | EMBER 2018 temporal split: ROC AUC 0.9917, 74.5% TPR at 0.1% FPR; never executes a sample |
| malware pipeline | SPECIMEN | static gate skips 42% of detonations, misses 1.2% of malware; 95.9% family accuracy on 48,976 CAPEv2 reports |
| NIDS robustness | FEINT | XGBoost at 99.7% clean accuracy detects 42% of flows under realisable evasion; adversarial training restores 80–96% |
| attack paths | LINCHPIN | exact minimum remediation cut over scanner, BloodHound and EPSS/KEV data; sends no packets |
| cloud-native | STRATUM | F1 1.000 on 148 upstream PSS conformance pods; 32 of 87 real workloads not PSS-restricted |
| CI/CD provenance | TRACEGATE | finding → introducing commit: 97.5% (356/365) vs 17.3% for the best baseline |
| K8s containment | AFTERLOCK | Go collector + Python planner; live kind lab agrees with the model on 17/17 steps across 3 runs |
| supply chain | WARDEN | 14 static analyzers, SBOM + SARIF + CI gate; 2,908 backend tests in CI |
| vuln-report triage | NIKASHA | v0.1.0 on PyPI; 0/126 genuine curl reports falsely flagged (Wilson 95% upper bound 2.96%) |
| agent security | SLUICE · taintwall | taintwall: exfiltration 43% → 0% with all four layers, benign utility held at 100% |
| state reconstruction | SPECTRA | pre-alpha: a Python reference slice runs end to end; no milestone is green yet, and the README says so |
- PlantPal+: plant care, fitness and nutrition on one habit loop. TypeScript monorepo (Expo, React + Vite, Express, PostgreSQL) with an IEEE-830 requirements package: 228 FRs, 119 user stories, 89 use cases.
- RailMind: a digital twin of a 21-station railway network feeding LangGraph agents that score incident-response plans. Runs offline, no API keys.
- portfolio: a candlelit, scroll-driven Next.js site. CI gates Lighthouse, axe, CSP and link checks; accessibility, best-practices and SEO score 100.
- VIT CGPA Calculator · learn-sql · PaceReader · ZT Web Security Simulator: small tools for studying and campus life.
how this profile builds itself
flowchart LR
API[("GitHub GraphQL API")] --> CARDS["build_cards.py<br/>telemetry · languages · project cards"]
ART["build_art.py<br/>hero · taglines · buttons · map · trophies"] --> GIT
API --> SNK["Platane/snk<br/>contribution snake"]
API --> D3["github-profile-3d-contrib<br/>3D calendar"]
CARDS & SNK & D3 --> GIT["profile.yml<br/>daily at 01:47 IST · on script changes"]
GIT -->|git commit| SVG["assets/ + generated/*.svg"]
SVG --> README(["this README"])
classDef n fill:#0a0e14,stroke:#00e38c,color:#e6edf3
classDef hub fill:#00e38c,stroke:#00e38c,color:#0a0e14
class API,CARDS,ART,SNK,D3,GIT,SVG n
class README hub
The hero, tagline banner, link buttons, toolchain, map, trophies log and footer are hand-built animated SVGs (scripts/build_art.py): SMIL only, no JavaScript, with a subset of JetBrains Mono embedded so they render the same on every OS, and every animation rests on its finished frame. The public instances of github-readme-stats, trophies and activity-graph now return 503/402, so the telemetry and language cards are generated here instead. Apart from the skill icons, every image on this page is served from this repo.



