Skip to content
View Dark-warri0r's full-sized avatar

Block or report Dark-warri0r

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Dark-warri0r/README.md

Hi πŸ‘‹, I'm Kiran Kunjumon

DevSecOps Engineer Β· Penetration Tester Β· UAV Security Researcher


🧭 About Me

  • πŸ” Cybersecurity professional with 3+ years across DevSecOps, penetration testing, cloud/container security, SIEM operations, and UAV security research
  • πŸ› οΈ Architected a zero-downtime CI/CD security pipeline integrating 15+ tools (GitLeaks, TruffleHog, Semgrep, SonarQube, OWASP Dependency-Check, Trivy, SYFT, GRYPE, Hadolint, Checkov, OWASP ZAP, DefectDojo)
  • 🚁 Currently leading funded research at ICFOSS on ROS 2 DDS vulnerabilities, Wi-Fi swarm attack surfaces, and MAVLink protocol security in UAV/autonomous systems
  • ☁️ Skilled in AWS IAM/EC2/VPC security, Docker/Portainer, Wazuh SIEM with CIS benchmark integration, and Prometheus Β· Grafana Β· Loki observability
  • πŸŽ“ M.Sc. Cyber Forensics & Information Security, Madras University
  • πŸ“œ CEH V11 Certified | Pursuing CKS & AWS Security Specialty
  • ✍️ I write about DevSecOps, Wazuh/SIEM hardening, and cloud/container security on Medium
  • 🀝 Active in the open-source security community β€” 500+ professional connections, regularly engaging with the latest AppSec/Cloud/IaC research
  • 🧩 Interested in AI-augmented offensive security β€” exploring how LLMs (OpenAI, Claude, Grok, local models) can accelerate vulnerability detection and reporting
  • 🌱 Constantly experimenting with home-lab setups on Proxmox/KVM to simulate enterprise attack-defense scenarios before applying them in production

πŸ’Ό Current Role

Research Assistant β€” ICFOSS (Mar 2026 – Present) Leading security research on UAV & autonomous systems: ROS 2 DDS attack surfaces (unauthenticated topic subscription, participant spoofing, multicast interception), Wi-Fi de-auth/spoofing on drone swarms, and MAVLink protocol attacks (component ID spoofing, heartbeat hijack, replay). Also performing penetration testing on gateways, web apps, and network infrastructure with CVSS-scored findings.


πŸ› οΈ Skills & Tools

DevSecOps / CI-CD

Secret Scanning / SAST / SCA

Container & IaC Security

Offensive Security / DAST

SIEM & Observability

Cloud & Virtualization

Server & Network

UAV / IoT / OT Security

Scripting & Dev

Frameworks & Standards


πŸ† Key Achievements

  • πŸ”— Designed & deployed a full-lifecycle DevSecOps pipeline: Secret Scan β†’ SAST β†’ SCA β†’ IaC Scan β†’ Docker Build β†’ SBOM + Container Scan β†’ Signing β†’ Policy Gate β†’ Blue-Green Deployment (zero downtime) β†’ DAST β†’ Infra Scan β†’ Vuln Management β†’ SIEM β†’ Alerting
  • 🚁 First in the organization to map ROS 2 DDS and MAVLink attack surfaces to MITRE ATT&CK for Embedded/IoT
  • πŸ•΅οΈ Performed VAPT on ERPNext across 3 production deployments (ICFOSS, Kerala IT Mission, Frappe Cloud); responsibly disclosed multiple high-severity vulnerabilities
  • πŸ“Š Deployed Wazuh SIEM with custom SCA rules org-wide, achieving CIS benchmark compliance with real-time Grafana + Telegram alerting
  • 🌾 Contributed to India's IoT-Enabled Smart Panchayat initiative β€” secured rural precision-agriculture infrastructure under PMKSY, a first-of-its-kind government IoT deployment in Kerala
  • πŸ•ΈοΈ Ran full-scope VAPT engagements across 3 production ERPNext deployments spanning government and enterprise cloud environments

✍️ Writing & Knowledge Sharing

I write technical breakdowns on DevSecOps and security engineering over on Medium:


πŸ”¬ Research Focus

Area Focus
ROS 2 / DDS Unauthenticated topic subscription, participant spoofing, multicast interception, SROS2 & OMG DDS Security spec mitigations
Drone Swarm Wi-Fi De-authentication, spoofing, MITM on inter-drone control channels
MAVLink Component ID spoofing, heartbeat hijacking, replay attacks, MAVLink 2 signing adoption

⚑ Quick Facts

  • πŸ”­ Currently working on: UAV/autonomous systems security research at ICFOSS
  • 🌱 Currently leveling up: CKS (Kubernetes Security) & AWS Security Specialty
  • 🀝 Open to collaborating on: DevSecOps pipeline design, drone/UAV security, and SIEM/threat detection projects
  • πŸ’¬ Ask me about: CI/CD security automation, Wazuh, container security, or MAVLink/ROS 2 attack surfaces
  • βš™οΈ Fun fact: I've built one CI/CD pipeline that chains 15+ security tools into a single zero-downtime deployment gate β€” from secret scanning to SIEM alerting

πŸ“œ Certifications

  • Certified Ethical Hacker V11 (CEH V11) β€” EC-Council
  • Certified Penetration Tester β€” Red Team Hacker Academy
  • Learn Ethical Hacking From Scratch β€” Udemy
  • Pursuing: CKS (Kubernetes Security) Β· AWS Security Specialty

🌐 Connect With Me

"Secure by design, resilient by default."

Popular repositories Loading

  1. Way-to-Coding Way-to-Coding Public

    Forked from techworldthink/Way-to-Coding

    Problems & Solutions

    C

  2. Wuzuh Wuzuh Public

    Installation and configuration of Wuzuh

  3. Linux Linux Public

    Linux commands from beginner to Advance

  4. Simple-Connectivity-Monitor Simple-Connectivity-Monitor Public

    Using Grafana,influx,telegraf

  5. flipperzero_protobuf_py flipperzero_protobuf_py Public

    Forked from flipperdevices/flipperzero_protobuf_py

    Python

  6. demo demo Public