PRIYANSH KHANDAL
CYBERSECURITY RESEARCHER & SOC AUTOMATION BUILDER
Specializing in Defensive Security and Network Anlaysis, digital forensics, autonomous SIEM threat response, and Web3 / AI agent defense mechanisms.
ABOUT OPERATOR
PRIYANSH KHANDAL
I am a cybersecurity researcher and software engineer operating at the intersection of offensive security, defensive automation, and decentralized systems. My work focuses on building low-level threat detection engines, reversing malware payloads, and securing modern AI agent protocols.
Whether executing kernel-level anti-rootkit research, analyzing network PCAPs during forensic investigations, or creating AI-driven SOC incident automation tools like Blackwall, I aim for zero-friction precision and clean architecture.
Handle used across GitHub and CTFs: rootwithkhandal.
FEATURED PROJECTS
SKILLS & CAPABILITIES
📡 BLUE TEAM & SOC AUTOMATION
- [x] Network AnalysisEXPERT
- [x] Autonomous SIEM ResponseEXPERT
- [x] Sigma & YARA Detection RulesEXPERT
- [x] Suricata / Zeek Network IDSADVANCED
- [x] Incident Response AutomationEXPERT
🔍 DIGITAL FORENSICS & IR
- [x] Volatility RAM Memory AnalysisEXPERT
- [x] Wireshark & PCAP Deep InspectionEXPERT
- [x] Disk Artifact Extraction (FTK/Autopsy)ADVANCED
- [x] Mobile Artifact ForensicsADVANCED
- [x] Malware Triage & Sandbox AnalysisADVANCED
⚡ LANGUAGES & RUNTIMES
- [x] Python & Async Security ToolingADVANCED
- [x] Bash ADVANCED
- [x] PowershellINTERMEDIATE
- [x] Go (Golang)INTERMEDIATE
- [x] Solidity & Web3 AuditingINTERMEDIATE
- [x] RustBASICS
WORK EXPERIENCE & CREDENTIALS
CYBERCRIME INTERN
- Assisted senior investigators in extracting digital evidence from confiscated mobile devices, hard drives, and flash storage.
- Performed Volatility memory analysis and PCAP network reconstruction to identify malware command-and-control (C2) servers.
- Maintained strict chain of custody documentation for forensic evidence presented in judicial proceedings.
SECURITY RESEARCHER & SOC AUTOMATION BUILDER
- Designed and released TrustLayer, an open-source Web3 auditing and AI guardrail engine built in Rust.
- Architected Blackwall, an autonomous SOC agent integrating Suricata IDS and eBPF kernel hooks to quarantine compromised hosts in real time.
- Researched Model Context Protocol (MCP) prompt injection vectors and published defense mechanisms (`mcp-firewall`).
CYBER SECURITY INTERN
- Learn about Networking and Security Fundamentals .
- Developed a A production-ready authentication system with advanced security features, role-based access control, and comprehensive user management.
CERTIFICATIONS & ACADEMIC BACKGROUND
- CEH (Certified Ethical Hacker) (Ongoing) — Core penetration testing methodology, network security auditing, and vulnerability assessment.
- CSA (Certified SOC Analyst) — Practical hands-on network penetration testing, web app security, and system exploitation.
- Master in Computer Applications — Academic specialization Computer Applications and Networking.