Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View bb1nfosec's full-sized avatar
  • India

Block or report bb1nfosec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bb1nfosec/README.md

bb1nfosec


LinkedIn Medium HackTheBox Security SE  


Security practitioner since 2009 — red team, AI/LLM security, IoT, and application security. Sixteen years spanning infrastructure penetration testing, purple teaming, threat intelligence, forensics, and incident response. Conference speaker. Hall of fame. Builder of open tools.

Currently working at the edge of offensive security and AI systems: red teaming LLM agents, building runtime defenses for agentic pipelines, and researching privilege escalation patterns in multi-agent tool-chaining.


Talks

Conference Location Year Title
ThreatCon Kathmandu, Nepal 2019 Hacking Human Lives via Body Area Network
BalCCon Novi Sad, Serbia 2018 Hybrid Cloud Seeding
DEFCon Trivandrum Kerala, India 2018

Writing  ·  bbinfosec.medium.com  ·  831 followers


Projects

Description
AgentGuard Runtime security for LLM agents. HMAC-signed tool calls, semantic anomaly detection, prompt injection interception before the model acts.
DVAI Deliberately Vulnerable AI ecosystem — the DVWA equivalent for AI red teamers. Prompt injection, insecure tool use, model inversion.
distill Scans any codebase for LLM token cost and waste. Auto-applies fixes. CI budget gate. MCP server for org-wide deployment.
agni Open-source EDR simulator written in Rust. For red teamers who need to test evasion without burning production sensors.
bheeshma Runtime dependency monitor for Node.js. Catches supply-chain attacks that static analysis misses. Zero deps. SARIF output. GitHub Action.
InfoSec Tasks ⭐ 176 Daily infosec problem statements for practitioners — forensics, OSINT, malware analysis, red and blue team.
Vaathi Free cybersecurity education for India. Because the barrier to entry shouldn't be financial.

  

Pinned Loading

  1. bheeshma bheeshma Public

    The strace for npm packages. Runtime dependency behavior monitor for Node.js — catches supply-chain attacks that static analysis misses. Zero dependencies. SARIF output. GitHub Action. CI/CD pipeli…

    JavaScript 1 2

  2. dvai dvai Public

    DVAI - Damn Vulnerable AI Ecosystem. Open-source, zero-infrastructure-cost AI red team training range.

    TypeScript 1

  3. vaathi vaathi Public

    🛡️ Vaathi — India's Open Source Cybersecurity Learning OS. From zero to ethical hacker — in your language, at your pace, on your machine.

    Python 20 6

  4. Information-Security-Tasks Information-Security-Tasks Public

    This repository is created only for infosec professionals whom work day to day basis to equip ourself with uptodate skillset, We can daily contribute daily one hour for day to day tasks and work on…

    Python 180 56

  5. chanakya-opsec chanakya-opsec Public

    Multi-layer OPSEC failure analysis framework - Research-grade threat modeling and signal correlation

    Python 3 3

  6. Distill Distill Public

    See which files burn your LLM tokens — fix them automatically. CI budget gate + MCP server + adapters for Claude, GPT-4o, Gemini, Ollama.

    Python 3