Skip to content
View aayushthakur001's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report aayushthakur001

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
aayushthakur001/README.md

Ayush Kumar Thakur

🛡️ Cybersecurity Professional | SOC Analyst | VAPT Engineer | AI Security Researcher

Typing SVG


LinkedIn GitHub TryHackMe Email Portfolio Medium


👨‍💻 About Me

╔══════════════════════════════════════════════════════════════════╗
║  OPERATOR   : Ayush Thakur — Cybersecurity Professional          ║
║  TARGET     : Threats, Vulnerabilities & Attackers               ║
║  LOCATION   : Chandigarh, India                                  ║
║  FOCUS      : SOC | VAPT | Digital Forensics | AI Security       ║
║  FRAMEWORKS : MITRE ATT&CK | ISO 27001 | NIST CSF | OWASP        ║
║  THM STATUS : Top 1% Global | Rank #8382 | LEGEND | 132 Rooms    ║
║  EDUCATION  : MCA @ Chandigarh University (2024-2026)            ║
║  MISSION    : Securing the digital world, one packet at a time   ║
╚══════════════════════════════════════════════════════════════════╝

🏆 TryHackMe Achievement

TryHackMe

🎯 Global Rank 🏅 Tier 🛡️ Badges 🏠 Rooms 🔴 Red Team 🔵 Blue Team
#8382 LEGEND 24 132

🚀 Featured Projects

🟣 PurpleOps — SOC & Vulnerability Intelligence Platform

MCA Major Project | Chandigarh University | April 2026

FastAPI React 18 PostgreSQL Redis Celery Docker Compose Nmap OWASP ZAP NIST NVD API JWT RBAC ReportLab

An enterprise-grade, open-source Security Operations Center platform integrating automated vulnerability scanning, real-time CVE intelligence, compliance mapping, and incident management — all orchestrated via a single docker compose up command.

┌─────────────────────────────────────────────────────────────────────┐
│  ARCHITECTURE : 5-Service Docker Compose Stack                      │
│  BACKEND      : FastAPI + SQLAlchemy + PostgreSQL + Redis + Celery  │
│  FRONTEND     : React 18 + Vite + Recharts (14 Dashboard Pages)     │
│  SCANNERS     : Nmap 7.94 (Network) + OWASP ZAP (Web App)           │
│  INTELLIGENCE : NIST NVD API v2.0 + CVSS 3.x Scoring                │
│  COMPLIANCE   : NIST SP 800-53 Rev 5 + ISO/IEC 27001:2022           │
│  SECURITY     : JWT + bcrypt + 3-Tier RBAC (Admin/Analyst/Viewer)   │
│  ASYNC        : Celery Workers + APScheduler background tasks       │
└─────────────────────────────────────────────────────────────────────┘

Key Metrics & Achievements:

  • Parallel Scanning: ThreadPoolExecutor (5 workers) — ~4x speedup (48 min → 12 min for 20 assets)
  • 🎯 Scan Accuracy: Nmap 92% precision | OWASP ZAP 90% recall | CVE Correlation 100% precision
  • 📋 Compliance: 83% NIST SP 800-53 + 82.4% ISO 27001 + 100% OWASP Top 10 coverage
  • 🔐 100% JWT authentication coverage across all 14 API endpoints
  • 📄 Auto PDF SOC Reports with CVSS scores, compliance mappings & prioritized remediation
  • 📊 5 Real-time Recharts visualizations — priority donut, status bar, scan history area, risky assets, trend line
  • Sub-200ms API response times | 50+ concurrent users validated via JMeter load testing
  • 🛡️ Zero unauthorized access in full security test suite (JWT tampering, RBAC bypass, SQLi, CORS)

Tech Stack: FastAPI React PostgreSQL Redis Docker Celery Python Nmap OWASP ZAP

GitHub


🤖 AI-Assisted Network Intrusion Detection System

University Project (Formally Graded) | Aug – Oct 2025

Python Scapy Scikit-learn Random Forest Flask Gemini AI Chart.js UNSW-NB15

A real-time ML-powered NIDS detecting network intrusions with 100% accuracy, featuring Gemini AI integration for natural-language threat summaries.

┌─────────────────────────────────────────────────────────────────────┐
│  DATASET   : UNSW-NB15 (175,000+ samples, 49 features)              │
│  MODELS    : Random Forest | SVM | Decision Tree | KNN | Naive Bayes│
│  BEST      : Random Forest — 100% Accuracy (F1 = 1.00)              │
│  LATENCY   : < 1 second real-time inference                         │
│  CPU USAGE : 15-20% during live deployment                          │
│  AI LAYER  : Gemini AI API — Natural Language Threat Summaries      │
│  DASHBOARD : Flask + Chart.js live traffic visualization            │
│  CAPTURE   : Real-time packet sniffing via Scapy                    │
└─────────────────────────────────────────────────────────────────────┘

Key Achievements:

  • 🧠 5 ML models benchmarked — Random Forest achieved perfect F1 = 1.00
  • 💬 Gemini AI generates human-readable, analyst-friendly threat summaries
  • 📡 Real-time Scapy packet capture with sub-second classification
  • 📊 Live dashboard for traffic pattern monitoring

Tech Stack: Python scikit-learn Flask Gemini AI Pandas

GitHub


☁️ Cloud & Mobile Vulnerability Research

Sep – Nov 2024

AWS CLI ADB SQLite DIVA Android OWASP

  • 🔍 Identified 13+ vulnerabilities in DIVA Android app — CWE-mapped, CVSS-scored
  • ☁️ Discovered critical AWS misconfigurations: public S3, over-privileged IAM, unencrypted EBS
  • 📄 Delivered quantitative PoC reports with OWASP-aligned remediation steps

GitHub


💼 Professional Experience

🔵 Security Admin Associate (L1) Intern — Infotact Solutions India

Aug 2025 – Nov 2025

  • 🚨 Deployed Snort-based NIDS with 40+ custom rules detecting port scans, brute-force, ICMP sweeps & C2 traffic
  • 📉 Reduced false-positive rate by 40% via quantitative traffic analysis and iterative rule tuning
  • 📊 Performed PCAP analysis & log correlation (Wireshark, tcpdump); produced 15+ structured incident reports with PoCs & attack timelines

🔴 Cyber Security Intern — VAPT — A2IT InternEdge, Mohali

May 2025 – Jul 2025

  • 🕷️ Conducted Web Application VAPT across 5+ clients using Burp Suite, Nmap & Nikto
  • 🐛 Identified 20+ OWASP Top-10 vulnerabilities with CVSS-scored severity ratings
  • 📝 Delivered audit-ready reports with exploitation scenarios, remediation steps & CWE mappings

🟣 Cyber Security & Digital Forensics Intern — Cyber Secured India

Sep 2024 – Nov 2024

  • 📱 Conducted mobile & cloud security investigations using ADB and AWS CLI
  • 📋 Delivered ISO 27001-aligned evidence reports with chain-of-custody documentation
  • 🔬 Solved 30+ TryHackMe & HackTheBox labs across red & blue team paths

🛠️ Technical Skills

🔵 SOC & Blue Team

Splunk Wireshark ELK Stack Snort OSSIM tcpdump

🔴 VAPT & Red Team

Burp Suite Metasploit Nmap OWASP ZAP Nikto Nuclei Kali Linux

☁️ Cloud & Digital Forensics

AWS Linux Docker Bash

🤖 AI & ML Security

Python scikit-learn TensorFlow Google Gemini Pandas

🧰 Dev & Backend

FastAPI Flask React PostgreSQL Redis Git Postman

📐 Frameworks & Standards

MITRE ATT&CK ISO 27001 NIST CSF OWASP CVE/CVSS


🏆 CTF & Competitive Security

Platform Achievement
🔴 TryHackMe Top 1% Globally — Rank #8382LEGEND — 24 Badges — 132 Rooms
☁️ SANS AWS CTF Top 20 Region / Top 300 Global
🎯 SANS Cyber Range BootUp CTF 5806 Points

📜 Certifications

🏅 Certificate Issuer Year
🔒 Introduction to Data Protection & Privacy Coursera 2026
🤖 Building AI-Powered Applications Chandigarh University / Coursera 2025
🌐 Networks & Security Google / Coursera 2025
⚔️ Ethical Hacking Essentials (EHE) EC-Council
🛡️ Network Security Associate OPSWAT
🇮🇳 Cybersecurity Training MeitY, Govt. of India
☁️ Google Cloud GenAI Program Google
🎓 Campus Ambassador IIT Delhi, eDC BECon 2026 2026

📊 GitHub Stats

GitHub Streak

🔝 Top Contributed Repos


snake gif

📚 Education

Degree Institution Duration Score
🎓 MCA Chandigarh University, Mohali 2024 – 2026 CGPA: 6.63
🎓 BCA Nilamber-Pitamber University 2019 – 2023 70.50%

📬 Connect With Me

LinkedIn Twitter Medium Dev.to HackerRank YouTube

📧 ayushwork981@gmail.com | 📍 Chandigarh, India |


💬 "The quieter you become, the more you are able to hear." — Kali Linux

Profile Views

Star my repos if you find them useful!

Pinned Loading

  1. PurpleOps PurpleOps Public

    Purple-Ops is a full-stack, production-ready Security Operations Center platform that integrates automated vulnerability scanning, real-time CVE threat intelligence, and regulatory compliance autom…

    JavaScript 2 1

  2. juice-shop juice-shop Public

    Forked from juice-shop/juice-shop

    OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

    TypeScript