Rukshana Alikhan

// threat research · detection engineering · offensive testing · governance

Threat Research Detection Engineering ICS/OT Security Incident Response GRC & Risk Malware Analysis Bug Bounty CompTIA Security+ eJPT

Research

Threat modelling for industrial control system malware

Projects

Things I've built and created

$ python app.py
* Running on http://localhost:5000
Scanning target...
Found 12 technologies, 3 CVEs
🛡️ Security Tool

TechScan

A web security scanner that fingerprints technologies and checks them against the OSV and NVD CVE databases to surface known vulnerabilities, with automated risk scoring.

Python Flask CVE Vulnerability Analysis
View on GitHub
[IDS] Alert: Port scan detected
[IDS] Alert: SQLi attempt blocked
[IPS] DROP 192.168.1.105
🎓 University Project • First Class (80%)

Network IDS/IPS Architecture

Designed and analysed intrusion detection architecture, investigating real packet captures in Wireshark to reconstruct attack lifecycles from reconnaissance through to data exfiltration. Applied signature-based, anomaly-based, and stateful protocol analysis aligned with NIST IDPS guidance.

Wireshark IDS/IPS NIST Network Security
$ ssh iam1@iamlabs.local -p 2220
Level 1: password reuse discovered
Level 6: misconfigured capabilities found
Privilege escalation path identified
🎮 Training Lab · Delivered at CyberNI Week 2026

IAM Labs

A Linux-based wargame teaching Identity and Access Management through hands-on exploitation — permissions, groups, capabilities, SSH keys, backups, and privilege escalation. Delivered as a live workshop at CyberNI Week 2026.

Linux Bash IAM Privilege Escalation
$ open risk-register.xlsx
Loaded 15+ identified risks
Risk scoring applied
Treatment plan mapped
📊 Governance

UK GRC Risk Register

A structured cybersecurity risk register aligned with ISO 27001 and UK GDPR, applying risk scoring, prioritisation, and treatment strategies across data protection, vendor risk, and regulatory compliance.

ISO 27001 UK GDPR Risk Management
View on GitHub
$ ./evilTwinDetector.sh
Checking duplicate SSIDs...
⚠ Suspicious SSID detected
CafeNet → 2 BSSIDs
🛡️ Security Tool

WiFi Evil Twin Detector

A lightweight Bash tool that detects duplicate SSIDs advertising different BSSIDs — a common indicator of rogue access points used in Evil Twin and machine-in-the-middle attacks.

Bash Linux WiFi Security Network Analysis
View on GitHub

Security Writeups

Analysis of challenges, vulnerabilities, and what defenders should take from them

Flare × SANS × WiCyS CTF

Pantalones Got Pantsed

A ransomware gang forgot to delete their exfil script before zipping victim data. That one mistake handed us their backend panel URL, API key, and admin credentials. Solved in under two hours. #28 of 250.

CTF OPSEC Web Forensics
📖 8 min read
TryHackMe Analysis

The Concierge Knew Too Much

An AI agent leaked its system prompt and an internal code — not to a jailbreak, but to a question that sounded like small talk. Why every loud attack failed and the boring one worked, mapped to OWASP LLM07 and MITRE ATLAS.

AI Security Prompt Injection OWASP LLM Top 10 Detection
📖 9 min read
TryHackMe Easy

W1seGuy

Breaking XOR encryption using known plaintext attacks. Why repeating-key XOR fails when attackers know part of the message.

Cryptography XOR Python
📖 10 min read
TryHackMe Easy

SimpleCTF

Nmap scanning, Gobuster enumeration, CVE exploitation, and privilege escalation via vim.

Pentesting SQLi PrivEsc
📖 8 min read
TryHackMe Easy

Takeover

Subdomain enumeration using ffuf and SSL certificate inspection to discover hidden services.

Recon ffuf SSL
📖 5 min read

Blog Series

Deep-dives into topics I'm actively researching — written in my own words

🦠
Series

Malware Analysis

Understanding how malware works by learning the systems it runs on — from CPU architecture through to reverse engineering fundamentals.

01 x86 Architecture Overview ✓ live

About Me

I'm a cyber security practitioner with deliberately wide interests — threat research, detection engineering, offensive testing, and governance. I'm currently completing an MSc in Applied Cyber Security at Queen's University Belfast, where my research builds a threat modelling framework for ICS malware.

Before the MSc I spent three years in security operations and governance — ISO 27001 initiatives, Microsoft Purview DLP, audit readiness, incident analysis, and stakeholder reporting across multi-regional environments. That background is why I care about whether a detection can actually be operationalised, not just whether it fires in a lab.

Alongside the research I work part-time as a security analyst doing passive reconnaissance and attack surface analysis, hunt bugs on YesWeHack and HackerOne, and write up what I find.

9
ICS Malware Families Profiled
3
Years' Industry Experience
500+
Users Covered by DLP
QUB
MSc Applied Cyber Security

TryHackMe Progress