⬇ Download as PDF
← Back to Portfolio
Print dialog → Save as PDF · Disable headers & footers for a clean output.
Sidharth M
Cybersecurity Researcher & Web Application Penetration Tester
Professional Summary
Cybersecurity professional pursuing BTech in CS&E (Cybersecurity) at VIT Chennai. Experienced in web application
penetration testing (VAPT), network security, firewall hardening, and cloud-native threat research. Government-level
security intern at Cyber Dome, Kerala Police . Published in 3 peer-reviewed journals &
books . Vice Chair at ACM VIT Chennai. Proficient in OWASP Top 10, Burp Suite, Nessus, Nmap, Kali Linux,
Docker, OPNsense, and CIS Benchmark compliance.
Education
2024 – 2028
Vellore Institute of Technology (VIT), Chennai
BTech — Computer Science & Engineering (Cybersecurity)
Chennai, Tamil Nadu, India
Work Experience
May 2025 – Present
Cyber Dome, Kerala Police
Kozhikode, Kerala, India · Government Cybersecurity Division
Community Volunteer – Aug 2025 – Present
Continued contributions to cybersecurity threat analysis, community security awareness programs, and
operational security support.
Security Intern – May 2025 – Jul 2025 (3 months)
Performed phishing campaign analysis — mapped attacker TTPs , identified malicious
infrastructure, and contributed to threat detection improvements.
Deployed and configured OPNsense next-generation firewalls ; documented firewall rule bypass
techniques for internal red-team research.
Supported red teaming exercises and network reconnaissance to identify security gaps.
2024 – Present
ACM VIT Chennai
VIT Chennai, Tamil Nadu, India
Vice Chair – Oct 2025 – Present
Elected Vice Chair; lead chapter strategy, manage website security posture , and oversee
technical operations for a 200+ member student tech community.
Membership Chair & Web Lead – 2024 – Oct 2025
Managed and hardened the ACM VIT Chennai website; led technical event operations and membership onboarding.
May – Jul 2025
VIT Chennai — SCOPE (SRIP 2025)
Research Intern
Supervisor: Dr. T. Subbulakshmi · VIT Chennai
Built a comprehensive cloud-native attack dataset and ML categorization model to classify
cloud security threats.
Bridged threat intelligence with machine learning; research culminated in a peer-reviewed IJCNC
publication .
Publications
2026
Analysis and Visualization of Cloud Native Attacks in a Secure Testbed
Subbulakshmi T, Adithyan P, Sidharth M, Arun Santhosh R A
International Journal of Computer Networks & Communications (IJCNC), Vol. 18, No. 2 ·
aircconline.com/ijcnc/V18N2/18226cnc06.pdf
Jul 2025
Setting Up A Security Testbed In Windows Using Docker
T. Subbulakshmi, Aditya Kushwaha, Sidharth M
Open Source For You (OSFY) Magazine ·
opensourceforu.com
Book Chapter
Next Generation Firewall: A Comprehensive Analysis and Practical Applications
Brindha Subburaj, Subbulakshmi T, Sidharth M
In-depth technical exploration of NGFW architectures, deep packet inspection, and enterprise deployment
strategies.
Projects
2025 – 2026
CIS Benchmark Hardening Toolkit — Level 1
Modular Bash toolkit implementing CIS Ubuntu 22.04 LTS Level 1 hardening across
authentication, SSH, filesystem, kernel/network sysctl, logging, firewall (UFW + iptables), AppArmor, and sudo
controls.
Firewall module implements defence-in-depth: SSH brute-force rate limiting, anti-spoofing (RFC 1918 drops),
scan protection (NULL/XMAS/FIN/non-SYN drops), ICMP hardening, and strict outbound allowlist.
Compliance validator runs 73 CIS controls , generating PASS/FAIL/WARN HTML dashboard —
achieved 73% compliance score (54 PASS) with auto-rollback on failure.
Technologies: Bash, UFW, iptables, auditd, rsyslog, AppArmor, Linux (Ubuntu 22.04).
2025
AEGIS ExamLab — Secure Proctored Exam Platform
Production-ready, open-source examination management platform built on Next.js 14 + MongoDB ;
deployed via Docker on Vercel.
Enforced 5-point server-side validation chain : PC approval → student mapping → exam
assignment → status check → duplicate submission guard.
AI-powered question bank using Google Genkit (Gemini) — auto-classifies difficulty, generates
semantic tags, supports LaTeX and code rendering.
Real-time PC telemetry: heartbeat polling every 15 seconds with liveStatus tracking (Online →
Attempting → Finished); full admin audit logging.
Technologies: Next.js 14, TypeScript, MongoDB, Google Genkit, Docker, Tailwind CSS, Vercel.
2022
DDoS Visual Forensic Analysis
Conducted comprehensive forensic analysis of a volumetric UDP flood attack (152k+ PPS) targeting a FiveM gameserver.
Stream-parsed and analyzed over 18.3 million packets from raw binary PCAP data using Python (`dpkt`).
Developed an automated data pipeline to compute traffic metrics, detect IP spoofing through TTL analysis, and perform geo-enrichment via MaxMind GeoLite2.
Created interactive visual synthesis using Plotly and Folium to map global botnet distribution, attack origin clusters, and temporal protocol shifts.
Technologies: Python, PCAP analysis, `dpkt`, MaxMind GeoLite2, Plotly, Folium.
2021 – 2022
Kidu Safe — Digital Safety & Content Filtering Platform
Developed a content filtering platform for safe online learning environments; reached advanced prototype stage
with recognition for digital safety impact in educational settings.
Technical Skills
Security Disciplines:
Web Application Penetration Testing (WAPT/VAPT), Network Penetration Testing, Red Teaming, Phishing Analysis, OSINT,
Threat Detection, Threat Intelligence, Firewall Bypass, Network Reconnaissance, Attack Simulation, Zero Trust, CIS
Benchmark Compliance, Linux Hardening, Information Security.
Security Tools:
Burp Suite, Nessus, Nmap, Wireshark, TCPDump, Hydra, VirusTotal, Kali Linux, Fortinet, OPNsense, UFW, iptables,
auditd, AppArmor, Cisco Packet Tracer.
Frameworks & Standards:
OWASP Top 10, OWASP Testing Guide, CIS Benchmarks (L1), Zero Trust Architecture, Site-to-Site VPN, SSH Hardening.
Development:
Python, C, C++, SQL/MySQL, Bash, TypeScript, Next.js, MongoDB, Flask, Nginx, Docker, Git, Cloudflare.
OS & Platforms:
Kali Linux, Ubuntu, Windows, Vercel, Cloudflare Pages.
Certifications & Achievements
Security Intern — Cyber Dome, Kerala Police (Government Cybersecurity Division), May–Jul 2025.
Publication — IJCNC (Cloud Native Attacks), 2026.
Publication — Open Source For You (Security Testbed in Windows using Docker), July 2025.
Book Chapter — IGI Global (Next-Generation Firewall).
Research Intern — VIT Chennai SCOPE, SRIP 2025, under Dr. T. Subbulakshmi.
Vice Chair — ACM VIT Chennai Chapter, Oct 2025–Present.