╔══════════════════════════════════════════════════════════════════╗
║ OPERATOR : Ayush Thakur — Cybersecurity Professional ║
║ TARGET : Threats, Vulnerabilities & Attackers ║
║ LOCATION : Chandigarh, India ║
║ FOCUS : SOC | VAPT | Digital Forensics | AI Security ║
║ FRAMEWORKS : MITRE ATT&CK | ISO 27001 | NIST CSF | OWASP ║
║ THM STATUS : Top 1% Global | Rank #8382 | LEGEND | 132 Rooms ║
║ EDUCATION : MCA @ Chandigarh University (2024-2026) ║
║ MISSION : Securing the digital world, one packet at a time ║
╚══════════════════════════════════════════════════════════════════╝
MCA Major Project | Chandigarh University | April 2026
FastAPI React 18 PostgreSQL Redis Celery Docker Compose Nmap OWASP ZAP NIST NVD API JWT RBAC ReportLab
An enterprise-grade, open-source Security Operations Center platform integrating automated vulnerability scanning, real-time CVE intelligence, compliance mapping, and incident management — all orchestrated via a single docker compose up command.
┌─────────────────────────────────────────────────────────────────────┐
│ ARCHITECTURE : 5-Service Docker Compose Stack │
│ BACKEND : FastAPI + SQLAlchemy + PostgreSQL + Redis + Celery │
│ FRONTEND : React 18 + Vite + Recharts (14 Dashboard Pages) │
│ SCANNERS : Nmap 7.94 (Network) + OWASP ZAP (Web App) │
│ INTELLIGENCE : NIST NVD API v2.0 + CVSS 3.x Scoring │
│ COMPLIANCE : NIST SP 800-53 Rev 5 + ISO/IEC 27001:2022 │
│ SECURITY : JWT + bcrypt + 3-Tier RBAC (Admin/Analyst/Viewer) │
│ ASYNC : Celery Workers + APScheduler background tasks │
└─────────────────────────────────────────────────────────────────────┘
Key Metrics & Achievements:
- ⚡ Parallel Scanning: ThreadPoolExecutor (5 workers) — ~4x speedup (48 min → 12 min for 20 assets)
- 🎯 Scan Accuracy: Nmap 92% precision | OWASP ZAP 90% recall | CVE Correlation 100% precision
- 📋 Compliance: 83% NIST SP 800-53 + 82.4% ISO 27001 + 100% OWASP Top 10 coverage
- 🔐 100% JWT authentication coverage across all 14 API endpoints
- 📄 Auto PDF SOC Reports with CVSS scores, compliance mappings & prioritized remediation
- 📊 5 Real-time Recharts visualizations — priority donut, status bar, scan history area, risky assets, trend line
- ⚡ Sub-200ms API response times | 50+ concurrent users validated via JMeter load testing
- 🛡️ Zero unauthorized access in full security test suite (JWT tampering, RBAC bypass, SQLi, CORS)
University Project (Formally Graded) | Aug – Oct 2025
Python Scapy Scikit-learn Random Forest Flask Gemini AI Chart.js UNSW-NB15
A real-time ML-powered NIDS detecting network intrusions with 100% accuracy, featuring Gemini AI integration for natural-language threat summaries.
┌─────────────────────────────────────────────────────────────────────┐
│ DATASET : UNSW-NB15 (175,000+ samples, 49 features) │
│ MODELS : Random Forest | SVM | Decision Tree | KNN | Naive Bayes│
│ BEST : Random Forest — 100% Accuracy (F1 = 1.00) │
│ LATENCY : < 1 second real-time inference │
│ CPU USAGE : 15-20% during live deployment │
│ AI LAYER : Gemini AI API — Natural Language Threat Summaries │
│ DASHBOARD : Flask + Chart.js live traffic visualization │
│ CAPTURE : Real-time packet sniffing via Scapy │
└─────────────────────────────────────────────────────────────────────┘
Key Achievements:
- 🧠 5 ML models benchmarked — Random Forest achieved perfect F1 = 1.00
- 💬 Gemini AI generates human-readable, analyst-friendly threat summaries
- 📡 Real-time Scapy packet capture with sub-second classification
- 📊 Live dashboard for traffic pattern monitoring
Sep – Nov 2024
AWS CLI ADB SQLite DIVA Android OWASP
- 🔍 Identified 13+ vulnerabilities in DIVA Android app — CWE-mapped, CVSS-scored
- ☁️ Discovered critical AWS misconfigurations: public S3, over-privileged IAM, unencrypted EBS
- 📄 Delivered quantitative PoC reports with OWASP-aligned remediation steps
Aug 2025 – Nov 2025
- 🚨 Deployed Snort-based NIDS with 40+ custom rules detecting port scans, brute-force, ICMP sweeps & C2 traffic
- 📉 Reduced false-positive rate by 40% via quantitative traffic analysis and iterative rule tuning
- 📊 Performed PCAP analysis & log correlation (Wireshark, tcpdump); produced 15+ structured incident reports with PoCs & attack timelines
May 2025 – Jul 2025
- 🕷️ Conducted Web Application VAPT across 5+ clients using Burp Suite, Nmap & Nikto
- 🐛 Identified 20+ OWASP Top-10 vulnerabilities with CVSS-scored severity ratings
- 📝 Delivered audit-ready reports with exploitation scenarios, remediation steps & CWE mappings
Sep 2024 – Nov 2024
- 📱 Conducted mobile & cloud security investigations using ADB and AWS CLI
- 📋 Delivered ISO 27001-aligned evidence reports with chain-of-custody documentation
- 🔬 Solved 30+ TryHackMe & HackTheBox labs across red & blue team paths
| Platform | Achievement |
|---|---|
| 🔴 TryHackMe | Top 1% Globally — Rank #8382 — LEGEND — 24 Badges — 132 Rooms |
| ☁️ SANS AWS CTF | Top 20 Region / Top 300 Global |
| 🎯 SANS Cyber Range BootUp CTF | 5806 Points |
| 🏅 Certificate | Issuer | Year |
|---|---|---|
| 🔒 Introduction to Data Protection & Privacy | Coursera | 2026 |
| 🤖 Building AI-Powered Applications | Chandigarh University / Coursera | 2025 |
| 🌐 Networks & Security | Google / Coursera | 2025 |
| ⚔️ Ethical Hacking Essentials (EHE) | EC-Council | — |
| 🛡️ Network Security Associate | OPSWAT | — |
| 🇮🇳 Cybersecurity Training | MeitY, Govt. of India | — |
| ☁️ Google Cloud GenAI Program | — | |
| 🎓 Campus Ambassador | IIT Delhi, eDC BECon 2026 | 2026 |
| Degree | Institution | Duration | Score |
|---|---|---|---|
| 🎓 MCA | Chandigarh University, Mohali | 2024 – 2026 | CGPA: 6.63 |
| 🎓 BCA | Nilamber-Pitamber University | 2019 – 2023 | 70.50% |
📧 ayushwork981@gmail.com | 📍 Chandigarh, India |


