Manually validated Semgrep SAST findings via source code review; investigated RDP exploit flags to eliminate false positives and identify genuine security exposures within internal products
Architected and deployed a full-fledged honeypot infrastructure from scratch, including SSH, web login decoys, databases (e.g. MSSQL, PostgreSQL), and SMTP honeypots; automated deployment using Ansible scripts and implemented network hardening (iptables, port mimicry, one-way communication)Developed real-time attack monitoring system using FastAPI, Uvicorn, MongoDB, and JavaScript dashboards; implemented geolocation-based visualization with WebSocket connectivity, scheduled tasks via cron jobs, and system monitoring using watchdog processes
Implemented secure coding practices and Apache2 configurations to prevent common web vulnerabilities; hardened infrastructure against recon and exploitation attempts
Led internal VAPT, discovering 2 P1 bugs (IDOR/BAC) and 4 P3 bugs (incl. file upload flaw)