Pushpender Singh Rathore

Cybersecurity Analyst · Malware Researcher · GSoC 2026 @ Metasploit
Bahal, Haryana, India · IST (GMT +5:30)

Second-year B.Tech Computer Science student at BRCM CET focused on offensive security research, malware and botnet analysis, and low-level / systems programming in C, C++, Assembly, and Python. GSoC 2026 contributor at the Metasploit Framework (Rapid7) building inline tracing presenters for Kerberos tickets and X.509 certificates. Hands-on experience across Active Directory abuse, ADCS ESC1-ESC16 exploitation, and reverse-engineering tooling.

Education

B.Tech, Computer Science & Engineering
BRCM College of Engineering & Technology, Bahal, Haryana
Coursework and self-directed study in systems programming, networks, operating systems, and applied cryptography.
RSCIT Computer Diploma
Rajasthan State Certificate in IT · Government of Rajasthan

Experience & Open Source

GSoC 2026 Contributor - Metasploit Framework (Rapid7)
Mentors: @jheysel-r7 (primary), @zeroSteiner (co-mentor)
  • Designing and implementing KerberosTicketTracePresenter and CertificateTracePresenter: two new inline tracing presenters that bring HttpTrace-style transparency to Kerberos tickets and X.509 certificates inside msfconsole.
  • Both presenter classes prototyped against AS-REQ / TGS-REQ flows in a Windows Server 2022 + ADCS lab on TEST.LOCAL; 13 + 14 RSpec examples written.
  • Modelled on the existing HttpTrace architecture and the krb5_ccache_presenter.rb precedent for upstream-merge consistency.
Mirai Source Code - IoT Botnet Research Mirror
github.com/Pushpenderrathore/Mirai-Source-Code
Maintained mirror of the Mirai botnet source code preserved strictly for educational, research, and cybersecurity-analysis purposes. Used to study how large-scale IoT malware operates at a technical level: infection vectors, C2 protocols, scanning routines, and load distribution.
Open-Source Contributor - BlackArch Linux
Working with the BlackArch penetration-testing distribution: package work, tool packaging, and offensive-security tooling research in a controlled environment.

Featured Projects

PyScanner - Network Security Scanner
v10 with ~47 features. Includes a full C++ port with zero-copy kernel TX and a stateless HMAC ISN architecture. Roughly 37% Nmap feature parity with genuine advantages in batch transmission, offline CVE lookup, and the stateless ISN design.
Contactsd - Encrypted Contacts Daemon
Secure CLI-based contacts manager. AES-256-GCM for confidentiality / integrity / authentication; keys derived from a master password via PBKDF2-HMAC-SHA256 (150k iterations, per-record salt). All crypto via OpenSSL.
Venice Firewall - AI-Assisted Network Filter
Integrates offline AI models and online AI services to analyse traffic patterns, detect anomalies, and resolve filtering decisions automatically. Real-time adaptive filtering with admin mail messaging.
MAC Address Randomizer Daemon
Privacy-focused systemd service that periodically randomises MAC addresses for all active interfaces via macchanger. Arch / Debian / Fedora support, dynamic interface detection, and a kill-switch that blocks the network if spoofing fails.

Technical Skills

Languages: Ruby, Python, C / C++, Bash, x86 / x86-64 Assembly
Reverse Engineering: Ghidra, gdb, Binary Ninja, objdump, xxd, YARA
Pentesting: Metasploit, Nmap, Wireshark, Burp Suite, Impacket, Rubeus
CTF Platforms: HackTheBox, TryHackMe, OverTheWire, WeChall
AD & Auth: Kerberos, ADCS ESC1-ESC16, Kerberoasting, Pass-the-Hash, Golden / Silver Ticket
Cryptography: OpenSSL, ASN.1, DER / PEM, X.509, AES-GCM, PBKDF2
ML / Data: PyTorch, TensorFlow, Keras, scikit-learn, NumPy, Pandas, Transformers, Ollama
Tooling: Git, RSpec, pytest, systemd, Kali Linux, BlackArch

Certifications

Profiles & Languages

  • WeChallrootanonymous
  • X (Twitter)@pushpender5177
  • Slack@Pushpender (Metasploit)
  • LanguagesEnglish, Hindi