pranavc.me

security engineer · oscp-track

Pranav Chaturvedi

I build things, then try to break them — offensive security tooling, ML-based detection, and infrastructure-as-code, practiced on a homelab I run and defend myself.

zsh — pranav@coldcoffee
$ whoami
View projects Download resume Get in touch

01 · about

I break things on purpose, then build the tooling to catch it happening again.

Cybersecurity & Digital Forensics graduate from VIT Bhopal, focused on web application security, exploit development, and system hardening. Two internships in — CSI Cyber Secured India and Unified Mentor — doing vulnerability assessment and security audits against real client systems. I build offensive security tooling and ML-based detection systems from the ground up in Python, currently working toward OSCP.

Most recently, I designed and built a two-node cybersecurity homelab from bare metal: an isolated pentest range, a scaled-down detection stack, and full observability — all defined as code and reproducible from a clean install. It's documented publicly as proof of how I actually work, not just what I know.

Certified: Google Cybersecurity · Networking & Cyber Security, Google · EC-Council CEH (in progress)

status.sh online
  • Offensive SecurityBurp Suite · Nmap · sqlmap · hydra
  • Detection & MLSuricata · CrowdSec · scikit-learn
  • Infrastructure as CodeAnsible · Docker · KVM/libvirt
  • NetworkingTailscale · Cloudflare Tunnel

02 · projects

Selected work

Aug 2024 – Jan 2025

WebGuardian

A Python framework orchestrating 24+ open-source security tools into 80+ automated checks — recon, SSL/TLS weakness detection (Heartbleed, POODLE, FREAK, LogJam), injection flaws (SQLi, XSS, RFI/LFI), and WAF fingerprinting, with severity-based report generation.

PythonWeb AppSec80+ checks
Jan – Apr 2025

Intrusion Detection System (ML)

Trained and compared 5 classification algorithms — Random Forest, SVM, Decision Tree, Naive Bayes, Logistic Regression — on the KDD Cup 1999 dataset, covering DoS, Remote-to-Local, User-to-Root, and Probing attack categories.

Pythonscikit-learnML detection
Feb 2026

Zero-Trust Self-Hosted Infra

A production-style Nextcloud/MariaDB/Redis stack on Docker Compose with zero exposed inbound ports — admin access via Tailscale, public HTTPS via Cloudflare Tunnel, version-pinned images, an isolated DB container, and automated volume-level backups.

DockerTailscaleCloudflare Tunnel

03 · experience & education

Timeline

04 · contact

Let's talk

Open to opportunities in offensive security, detection engineering, and infrastructure roles.