Available · Jaipur, India

I trap
hackers
for fun.

Systems & security engineer. I built a honeypot that's caught 44,000+ real attackers, patched a CVSS 10.0 RCE within 24 hours of disclosure, and manage production infra for 2,160 students.

View my work GitHub
44k+
attacker sessions captured
82%
Docker image reduction
45
repos in production
24h
CVSS 10.0 patch turnaround

Selected work

Featured project Live in production

MIRAGE

Production SSH honeypot & threat intelligence platform — engineered from scratch in Go. It listens on the open internet, pretends to be a real server, and captures everything attackers do. Over 44,000 of them fell for it. Still counting.

44,204+
sessions captured
13
coordinated botnet IPs identified
5
normalized PostgreSQL tables
0
API keys exposed client-side
Custom SSH emulator in Go
Full handshake via golang.org/x/crypto, PasswordCallback capture, PTY handling, fake interactive shell with stateful directory traversal. Very convincing to bots.
Botnet fingerprinting via SQL CTEs
Discovered coordinated IPs hitting exactly 1,522 sessions each. Caught Solana validator credential targeting across automated scanners.
Zero infrastructure exposure
REST API (Chi router + API key middleware) tunneled through Cloudflare. No public endpoint. CI/CD publishes live stats daily via GitHub Actions.
ML classification layer
Co-authored PyTorch behavioral embeddings for session clustering. Turns out attackers have very predictable personalities.
Experience
DevOps Intern
Software Development Centre, MUJ — Jaipur, India
Aug 2025 – Present
CVE-2025-55182 — patched in 24h
CVSS 10.0 unauthenticated RCE across 8 production services. Simultaneously hardened all Dockerfiles to non-root execution.
2 GB → 358 MB Docker images
Restructured Dockerfiles across 45 repos with incremental GitHub Actions workflows. Up to 82% image size reduction.
Zero Trust mesh across bare-metal + VPS
Deployed Tailscale across Hostinger and bare-metal nodes. Eliminated all public SSH exposure. cgroups for kernel-level resource governance.
Production infra for 2,160 students
NPTEL verification, Elective Management, IT ticketing. MinIO S3 migration with 1-hour RPO across 7 databases. Sub-5-min RTO.
Docker GitHub Actions Tailscale Linux MinIO cgroups
Open Source PR merged to main
Honeynet Project — EventHorizon
github.com/honeynet/eventhorizon
View on GitHub
Real-time attacker input capture in C
Non-blocking read() after each IAC write to the Telnet tarpit. Sanitized non-printable bytes and emitted per-keystroke metrics via sendMetric().
Prometheus exporter extension in Go
Added telnet_pit_input CounterVec enabling per-session behavioral metrics. PR reviewed and merged to main by Honeynet maintainers.
C Go Prometheus Telnet Protocol

A bit
about me.

I'm Vinayak — a systems and security engineer with a habit of deploying things that probably shouldn't exist on the open internet, then writing detailed reports about what happens when they do.

Currently a DevOps Intern at SDC, MUJ, where I manage production infrastructure for 2,160+ students and occasionally patch critical vulnerabilities before anyone notices.

When I'm not staring at logs or reading CVE disclosures, I'm watching football (the version played with feet, just to be clear), losing at video games, and building things for fun. MIRAGE started as a weekend experiment. Then 44,000 attackers showed up.

Education
Manipal University Jaipur
B.Tech, Computer Science & Engineering
Expected 2028

Let's build
something
worth deploying.

Whether it's infrastructure, security research, or you just want to talk football — my inbox is open. Response time: much faster than 24 hours. Unless there's a match on.

vinayaktyagi.ed@gmail.com
Email copied to clipboard