Siddhant Mandal

Computer Science (Cyber Security) student

  • Detect.
  • Analyze.
  • Defend.

Computer Science (Cyber Security) student specializing in Linux security, malware analysis, and detection engineering. Designs and builds system-level security tools — including a behavioral shellcode analysis framework and a Linux privilege-drift monitoring system — to detect and analyze security-relevant system behavior.

02About

Computer Science (Cyber Security) student specializing in Linux security, malware analysis, and detection engineering. Designs and builds system-level security tools — including a behavioral shellcode analysis framework and a Linux privilege-drift monitoring system — to detect and analyze security-relevant system behavior.

  1. 01DetectBuilds tooling that surfaces suspicious system and binary behavior before it becomes an incident.
  2. 02AnalyzeEmulates and traces low-level execution — shellcode, syscalls, privilege state — to understand real intent.
  3. 03DefendTurns analysis into deterministic, auditable detection systems that security teams can trust.

03Operations

Two system-level security tools — one for analyzing unknown binaries, one for watching privilege state drift over time.

01Operation · Analysis

Sandboxed Shellcode Behavioral Analysis Framework

A Python framework for sandboxed shellcode behavioral analysis, safely emulating raw shellcode with Unicorn Engine and disassembling instructions via Capstone instead of executing samples natively.

  • Python
  • Unicorn Engine
  • Capstone
  • Scikit-learn
  1. 01
    Unicorn Engine emulates raw shellcode in an isolated CPU/memory context.
  2. 02
    Capstone decodes executed instructions for inspection and tracing.
  3. 03
    A pipeline captures instruction flow, memory writes, Linux int 0x80 syscalls, loop structures, NOP sleds, and write-then-execute patterns.
  4. 04
    A Random Forest model (scikit-learn) scores the extracted features against known behavioral families.
  5. 05
    Results are serialized to JSON with classification confidence for downstream review.

02Operation · Monitoring

Linux Privilege Drift Monitoring Framework

A lightweight, zero-dependency Linux framework that captures trusted system baselines and performs deterministic snapshot comparison to detect drift across SUID/SGID bits, sudo rules, privileged groups, UID 0 accounts, and cron entries.

  • Python
  • Linux
  • HTML
  • JSON
  1. 01
    Gathers current system state: SUID/SGID bits, sudo rules, privileged group membership, UID 0 accounts, and cron entries.
  2. 02
    Stores a trusted snapshot of system state to compare future collections against.
  3. 03
    Performs deterministic snapshot comparison between the baseline and current state.
  4. 04
    Applies rule-based risk scoring and renders results as JSON reports and an HTML dashboard.

04Arsenal

Grouped by how each skill actually gets used — from writing the tools to running them against real systems.

    • Python
    • Java
    • C
    • C++
    • Bash
    • SQL
    • Burp Suite
    • Wireshark
    • Nmap
    • Autopsy
    • Unicorn Engine
    • Capstone
    • Scikit-learn
    • Arch Linux
    • BlackArch Linux
    • Windows
    • TryHackMe
    • Hack The Box
    • Linux Security
    • Malware Analysis
    • Threat Detection
    • Detection Engineering
    • Behavioral Analysis
    • Privilege Escalation
    • Digital Forensics
    • Reverse Engineering
    • Cryptography
    • Security Research
    • Security Automation
    • Network Security

05Field log

Internships, chapter leadership, and community organizing across the Nagpur security scene.

  1. Cyber Security Intern

    Jun 2026 – Jul 2026120 Hours

    BharatCares®

    • Performed malware and shellcode analysis using controlled execution and behavioral analysis techniques to examine sample activity.
    • Applied reverse engineering methods to support analysis and built internal security tooling to strengthen detection workflows.
  2. Core Team Member

    May 2026 – Present

    OWASP Nagpur

    • Coordinate chapter operations and technical programming as part of the core organizing team for a local OWASP chapter.
    • Collaborate on planning and delivery of security-focused sessions and community initiatives within the chapter.
  3. Management Lead

    Nov 2025 – Present

    The Hacker’s Meetup — Nagpur Chapter

    • Lead end-to-end planning and execution of cybersecurity meetups as chapter head, coordinating speakers, logistics, and technical session delivery.
  4. Technical Team Member

    Aug 2025 – Present

    Phoenix Cybersecurity

    • Assist in organizing cybersecurity workshops and national-level events, co-coordinating Hacker’s Heist (Cyberpunk 3.0) and hosting EncipherX 4.0 at SVPCET.
  5. Cyber Security Intern

    Jun 2025 – Jul 2025

    SkillCraft Technology

    • Performed vulnerability assessments and penetration testing to identify security weaknesses and attack vectors.
    • Applied attack-simulation techniques to evaluate system security posture under controlled conditions.

06Milestones

  • HackFusion 3.0
    National Hackathon
  • Signal CTF
    YCCE
  • ACN CTF
    Amrita Vishwa Vidyapeetham
  • Gigagen
    AI Verse 2.0

07Credentials

St. Vincent Pallotti College of Engineering & Technology

B.Tech in Computer Science & Engineering (Cyber Security)

Nagpur, India · Aug 2024 – Present · CGPA 9.29 / 10

Certifications

  • 01IBM Cybersecurity Fundamentals
  • 02Security Operations Center in Practice
  • 03NPTEL Cyber Security and Privacy (Elite)
  • 04EC-Council Ethical Hacking

08ESTABLISH CONNECTION

Open to internships, research collaboration, and CTF teams. Reach out through any channel below.

Download résumé