[OPERATOR_ID // rootwithkhandal]

PRIYANSH KHANDAL

CYBERSECURITY RESEARCHER & SOC AUTOMATION BUILDER

Specializing in Red/Blue Team operations, digital forensics, autonomous SIEM threat response, and Web3 / AI agent defense mechanisms.

root@khandal:~ (tty1)
$ whoami
> Priyansh Khandal | Security Researcher & Developer
$ uname -a
> Linux khandal-soc 6.8.0-sec #1 SMP PREEMPT_DYNAMIC x86_64
$ cat focus.txt
> [x] Red Team & Kernel Driver Hooking
> [x] eBPF & Autonomous SIEM Detection
> [x] Web3 Smart Contract Auditing & MCP Guardrails
$ status --detailed
> [ONLINE] Ready for contracts & security auditing.

ABOUT OPERATOR

PRIYANSH KHANDAL

I am a cybersecurity researcher and software engineer operating at the intersection of offensive security, defensive automation, and decentralized systems. My work focuses on building low-level threat detection engines, reversing malware payloads, and securing modern AI agent protocols.

Whether executing kernel-level anti-rootkit research, analyzing network PCAPs during forensic investigations, or creating AI-driven SOC incident automation tools like Blackwall, I aim for zero-friction precision and clean architecture.

Handle used across GitHub and CTFs: rootwithkhandal.

✦ Network Security ✦ Logs Analysis ✦ Memory Forensics ✦ Smart Contract Audits
7+
Core Security Repos
PYTHON
Primary Weaponry
SOC / IR
Automation Specialty
CERTIFIED
CSA

FEATURED PROJECTS

SKILLS & CAPABILITIES

📡 BLUE TEAM & SOC AUTOMATION

  • [x] Network AnalysisEXPERT
  • [x] Autonomous SIEM ResponseEXPERT
  • [x] Sigma & YARA Detection RulesEXPERT
  • [x] Suricata / Zeek Network IDSADVANCED
  • [x] Incident Response AutomationEXPERT

🔍 DIGITAL FORENSICS & IR

  • [x] Volatility RAM Memory AnalysisEXPERT
  • [x] Wireshark & PCAP Deep InspectionEXPERT
  • [x] Disk Artifact Extraction (FTK/Autopsy)ADVANCED
  • [x] Mobile Artifact ForensicsADVANCED
  • [x] Malware Triage & Sandbox AnalysisADVANCED

LANGUAGES & RUNTIMES

  • [x] Python & Async Security ToolingADVANCED
  • [x] Bash ADVANCED
  • [x] PowershellINTERMEDIATE
  • [x] Go (Golang)INTERMEDIATE
  • [x] Solidity & Web3 AuditingINTERMEDIATE
  • [x] RustBASICS

WORK EXPERIENCE & CREDENTIALS

April 2026 - Present

CYBERCRIME INTERN

Rajasthan Police Cybercrime Branch
  • Assisted senior investigators in extracting digital evidence from confiscated mobile devices, hard drives, and flash storage.
  • Performed Volatility memory analysis and PCAP network reconstruction to identify malware command-and-control (C2) servers.
  • Maintained strict chain of custody documentation for forensic evidence presented in judicial proceedings.
2024 — PRESENT

SECURITY RESEARCHER & SOC AUTOMATION BUILDER

Independent / Open Source Security Community
  • Designed and released TrustLayer, an open-source Web3 auditing and AI guardrail engine built in Rust.
  • Architected Blackwall, an autonomous SOC agent integrating Suricata IDS and eBPF kernel hooks to quarantine compromised hosts in real time.
  • Researched Model Context Protocol (MCP) prompt injection vectors and published defense mechanisms (`mcp-firewall`).
November 2025

CYBER SECURITY INTERN

Vault Tec Security
  • Learn about Networking and Security Fundamentals .
  • Developed a A production-ready authentication system with advanced security features, role-based access control, and comprehensive user management.
CREDENTIALS & CERTIFICATIONS

CERTIFICATIONS & ACADEMIC BACKGROUND

Verified Cyber Security Certifications & Degree
  • CEH (Certified Ethical Hacker) (Ongoing) — Core penetration testing methodology, network security auditing, and vulnerability assessment.
  • CSA (Certified SOC Analyst) — Practical hands-on network penetration testing, web app security, and system exploitation.
  • Master in Computer Applications — Academic specialization Computer Applications and Networking.

RESEARCH INSIGHTS

✦ BLUE TEAM & EBPF RESEARCH

Autonomous SIEM Incident Response via eBPF Kernel Tracing & Suricata NIDS

Traditional SIEM alerting introduces unacceptable latency during active ransomware or lateral movement attacks. By deploying low-overhead eBPF (Extended Berkeley Packet Filter) kernel probes coupled with real-time Suricata NIDS event streaming, host-level network sockets and malicious process lineage can be intercepted directly in kernel-space. This architecture reduces threat isolation time from minutes to under 50 milliseconds without destabilizing host kernel space.

eBPF Suricata SIEM Automation MITRE ATT&CK
✦ DIGITAL FORENSICS & IR

RAM Memory Forensics & Volatility Malware Payload Reconstruction

During forensic investigations with the Rajasthan Police Cybercrime Branch, raw RAM dumps provided critical unencrypted artifacts unavailable on disk. Utilizing the Volatility 3 framework to inspect unlinked VAD (Virtual Address Descriptor) trees, API hook tables, and injected DLL payloads allowed complete extraction of Command-and-Control (C2) IP addresses and decrypted payload binaries from volatile memory dumps.

Volatility 3 RAM Forensics DLL Injection C2 Extraction
✦ AI AGENT & WEB3 SECURITY

Model Context Protocol (MCP) Guardrails & Prompt Injection Defense

As LLM agents adopt Model Context Protocol (MCP) tool integrations, untrusted input payloads can induce indirect prompt injection attacks leading to unauthorized remote procedure calls (RPCs). Our research introduces mcp-firewall, an inline AST parser and zero-trust schema validation proxy that intercepts tool requests between LLMs and host APIs to sanitize execution context before system execution.

MCP Security Prompt Injection LLM Guardrails OWASP AI Top 10

KNOWLEDGE BASE & FAQ

> Who is Priyansh Khandal (@rootwithkhandal)?

Priyansh Khandal is a Cybersecurity Researcher and SOC Automation Builder operating at the intersection of offensive red teaming, blue team incident response, digital forensics, and Web3 / AI agent security guardrails.

> What open-source security tools has Priyansh built?

Key repositories include Blackwall (an autonomous SOC bot leveraging eBPF and Suricata NIDS), TrustLayer (Web3 smart contract auditing and AI guardrails engine in Rust), and mcp-firewall (Model Context Protocol security firewall for LLM agents).

> What credentials and real-world experience does Priyansh hold?

Priyansh holds the CEH (Certified Ethical Hacker) and CSA (Certified SOC Analyst) certifications, a Master in Computer Applications degree, and hands-on digital forensics experience with the Rajasthan Police Cybercrime Branch.

> How can I verify PGP key or initiate security audits?

Reach out directly via email at priyansh@khandal.xyz or use the terminal contact form below. Verify encrypted communications with PGP Fingerprint: 9F82 4B1E 7D3C 0A92 8E65 1F42 C5B8 E7D0 3A21 4F90.

TERMINAL CONTACT

Whether you want to discuss security audits, open-source SOC tools, research collaborations, or hire me for contract roles, reach out via terminal or encrypted channels:

GH

GITHUB

@rootwithkhandal

IN

LINKEDIN

Priyansh Khandal

@

EMAIL

priyansh@khandal.xyz

[PGP KEY FINGERPRINT]
9F82 4B1E 7D3C 0A92 8E65 1F42 C5B8 E7D0 3A21 4F90

$ send_message --to=priyansh