Skip to content
View Raavi29's full-sized avatar

Highlights

  • Pro

Block or report Raavi29

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Raavi29/README.md

About

First-year B.Tech CSE (Cybersecurity) student at DBS Global University, currently doing security research at IIT Bhilai under Dr. Dhiman Saha. My work sits across hardware forensics, cryptographic attacks, and penetration testing of secure hardware. I have a paper accepted at IJCACI 2026 and a 9.09 SGPA.

I am not waiting for a later year to do real work.

Right now that means pulling apart a secure element to see if its guarantees actually hold, running a Rowhammer attack in a simulated environment to understand memory-level exploitation from the inside, and attacking a government-backed hardware token whose design changes because of what I find.


Open To

  • Security research collaborations
  • Open source contributions
  • Security engineering roles
  • Graduate research opportunities
  • Hardware security projects
  • Reverse engineering work
  • AI security research

Tech Stack

Programming Languages

Python C C++ Java JavaScript

Hardware Security & Embedded Systems

ChipWhisperer PhyWhisperer SPI Secure Elements

Reverse Engineering & Firmware Analysis

Ghidra Firmware

Digital Forensics

FlareVM REMnux USB Forensics

Network Security

Wireshark Nmap

Cryptography & Hardware Attacks

Rowhammer Cryptanalysis

Web Development

React Node.js REST APIs WhatsApp Business API

Operating Systems & Developer Tools

Linux Git GitHub OWASP


Research Interests

Active Research

Area Focus
Hardware Security Secure element forensics on the TROPIC01 devkit
Cryptographic Attacks Rowhammer implementation in a simulated environment
Power Analysis Side-channel analysis with ChipWhisperer Husky and PhyWhisperer USB
Firmware Reverse Engineering Ghidra-based decompilation and behavioural analysis
Digital Forensics USB and SPI protocol reconstruction, conformance testing
Secure Hardware Verification Empirical key-destruction testing (Mac-and-Destroy), full conformance suites
AI for Security Computational-intelligence-driven ransomware detection literature

Exploring Next

Area Direction
Fault Injection Extending the power analysis phase into fault injection on secure hardware
Secure Hardware Verification Generalising the TROPIC01 conformance methodology to other secure elements

AI / ML Expertise

Domain Experience Application Current Work
Computational Intelligence for Security Literature synthesis across 4 years of ML/DL ransomware research (IJCACI 2026) ML/DL-based ransomware detection, attack-vector analysis, forensic recovery Extending the review methodology toward hardware-level threat detection

This is research and review work, not production ML engineering.


Featured Projects

TROPIC01 Secure Element Forensic Analysis

Forensic and security analysis of the TROPIC01 secure element development board, run end to end at the de.ci.phe.red Lab, IIT Bhilai.

Full case study

Overview Passive USB reconnaissance, active SPI protocol analysis, behavioural conformance testing, empirical key-destruction verification, and firmware decompilation, all on one devkit.

Problem Secure elements are trusted because their internals are supposed to be opaque. That trust is worth testing directly instead of taking the datasheet's word for it.

Methodology USB traffic captured and reconstructed. SPI protocol characterised against the TROPIC01 conformance spec, with a full test suite built from scratch to run it repeatably. Firmware pulled apart in Ghidra. Mac-and-Destroy key-destruction behaviour verified empirically across 11 sequential PIN attempts.

Findings 62 confirmed findings logged against the conformance suite.

Security Perspective Tests whether the chip's documented security guarantees survive direct interrogation, not just whether they read well on paper.

Technologies Ghidra, custom SPI conformance suite, USB forensics tooling, ChipWhisperer Husky, PhyWhisperer USB.

Status Power analysis phase in progress.

Repository Confidential. IIT Bhilai lab-restricted research.


TruToken Security Analysis

Attack, analysis, and penetration testing on TruToken, a secure hardware token built by C-DAC Noida and IIT Bhilai.

Full case study

Overview Structured hardware penetration testing against a token that is still being designed. Findings go straight back into the design process.

Problem A secure token in active development needs adversarial testing before it ships, not after.

Approach Attack and analysis methodology applied against TruToken's hardware security assumptions.

Impact Vulnerability findings feed directly into TruToken's ongoing development.

Technologies Hardware penetration testing methodology, secure token analysis.

Repository Confidential. Government-institutional research (C-DAC Noida, IIT Bhilai).


Rowhammer Attack Implementation

Implementing a Rowhammer attack in a simulated environment as part of broader hardware attack research.

Full case study

Overview Rowhammer turns a physical memory quirk into a security bypass. Understanding it means building it, not just reading the paper on it.

Status In progress, simulated environment.

Technologies Cryptographic and hardware attack research tooling.

Repository Confidential. IIT Bhilai lab-restricted research.


Saheli: WhatsApp-First Labour Marketplace for Women

Full case study

Overview A platform letting homebound women take on MSME contracts directly through WhatsApp.

Problem Skilled women who cannot leave home for work have no easy channel into a gig economy that runs on WhatsApp anyway.

Solution A trust-scoring system to vet contract reliability, UPI payouts for instant settlement, and Hindi voice input so literacy is not a barrier to entry.

Impact Reached the CII Yi Yuva National Grand Finale 2026 and drew investor interest at the event.

Technologies WhatsApp Business API, React, Node.js, REST APIs.

Repository Not publicly released.


GreenLight: Intelligent Traffic Optimisation

Full case study

Overview A traffic optimisation system built for Smart India Hackathon 2025.

Role Led a 6-member team. Built the frontend and ran the Linux-based SUMO simulations myself.

Result National Finalist at IIIT Dharwad. Handled the full jury Q&A.

Technologies SUMO traffic simulation, Linux, frontend development.

Repository Not publicly released.


Experience

Research Intern · de.ci.phe.red Lab, IIT Bhilai Jun 2026 – Aug 2026 · Supervisor: Dr. Dhiman Saha

Cryptographic attacks, hardware security, digital forensics. Selected via a two-round interview. One of very few undergraduates placed here.

Scope of Work TROPIC01 forensic analysis, TruToken security analysis, Rowhammer attack research, and an in-progress power analysis phase.

Key Contributions 62 confirmed findings on the TROPIC01 devkit. Full conformance test suite built and run. Empirical Mac-and-Destroy verification across 11 sequential PIN attempts.

Technologies Ghidra, ChipWhisperer Husky, PhyWhisperer USB, custom SPI tooling.


Intern · VLED Lab, IIT Ropar Jun 2026 · Supervisor: Prof. Sudarshan Iyengar

India-centric open source problems.

Scope of Work Learning phase on a live public repository focused on India-centric software problems.


Publications

Towards Intelligent Ransomware Defence: A Computational-Intelligence-Driven Thematic Review of Detection, Forensics, and Recovery

Parneet Kaur, Prof. Merry KP · IJCACI 2026 (US) · Accepted · 2025–2026

Summary A systematic review of ML/DL ransomware detection, attack vectors, and forensic recovery across 4 years of literature, in Springer LLNCS format. Techniques validated independently in FlareVM and REMnux.

Research Areas Ransomware detection, computational intelligence, digital forensics.

Technologies FlareVM, REMnux.


Open Source

OWASP Nettacker · GSoC 2026 applicant · 2025–2026

1 merged PR, 2 pending. Researched CVE-2025-32756 (Fortinet FortiVoice RCE) to extend scanner detection coverage. Kept contributing after the GSoC rejection.

GirlScript Summer of Code (GSSoC) Contributor.


Hackathons

Saheli · CII Yi Yuva · National Grand Finale 2026

WhatsApp-first labour marketplace for women. Trust-scoring, UPI payouts, Hindi voice input. Drew investor interest at the finale. Full write-up under Featured Projects.

GreenLight · Smart India Hackathon 2025 · National Finalist, IIIT Dharwad

Intelligent traffic optimisation. Led a 6-member team, built the frontend, ran the Linux SUMO simulations, and handled the jury Q&A. Full write-up under Featured Projects.


Achievements

Achievement Detail
CII Yi Yuva National Grand Finale 2026 Saheli, investor interest at the finale
Smart India Hackathon 2025, National Finalist GreenLight, IIIT Dharwad
Google Gemini Student Ambassador 2026 Shortlisted
Queen's Commonwealth Essay Competition Silver Award
Vidyarthi Vigyan Manthan District Rank 1

Certifications

Blockchain and Applications


Engineering Philosophy

Verify before you assume. A secure element's guarantees mean nothing until someone tests them directly. Conformance suites and empirical key-destruction testing exist because datasheets are not proof.

Build before you claim expertise. First-year does not mean early enough to wait. It means early enough to start.

Understand systems from first principles. Decompiling firmware and reconstructing a protocol from raw SPI traffic teaches more than reading documentation about either.

Open source is a discipline, not a resume line. Getting rejected from GSoC did not stop the Nettacker contributions. The work was never about the label.

Research means being willing to be wrong in public. A published review has to survive scrutiny from people who know the literature better than I do. That is the point of publishing it.


GitHub Analytics

Raavi's GitHub stats Top languages GitHub streak stats GitHub trophies



Contribution snake animation

Current Focus

current_focus:
  learning:
    - Power analysis with ChipWhisperer Husky
    - Fault injection fundamentals
  building:
    - TROPIC01 conformance test suite
    - Personal portfolio site
  researching:
    - Secure element verification methodology
    - Ransomware detection with computational intelligence
  exploring:
    - Fault injection attacks on secure hardware
  open_to:
    - Research collaborations
    - Security engineering roles
    - Graduate research

Connect

Email LinkedIn GitHub GeeksforGeeks Portfolio


Secure systems are proven, not assumed.

footer

Popular repositories Loading

  1. aoop aoop Public

    nope

    HTML

  2. Void-Pointers Void-Pointers Public

    Python

  3. Green_Light_Team_Void_Pointers Green_Light_Team_Void_Pointers Public

    JavaScript

  4. h4cker h4cker Public

    Forked from The-Art-of-Hacking/h4cker

    This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security,…

    Jupyter Notebook

  5. Nettacker Nettacker Public

    Forked from OWASP/Nettacker

    Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

    Python

  6. Anthropic-Cybersecurity-Skills Anthropic-Cybersecurity-Skills Public

    Forked from mukul975/Anthropic-Cybersecurity-Skills

    754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub …

    Python