Skip to content
View liyander's full-sized avatar
:copilot:
Focusing
:copilot:
Focusing

Block or report liyander

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
liyander/readme.md
CyberGhost05 threat dossier banner Deadpool GIF
Threat console introduction

Status: operational 18 published CVEs Maximum CVSS score 10.0 Profile views



LinkedIn Hack The Box Email

Threat actor profile section

Threat Level Designation Rules

identity: Liyander Rishwanth L
alias: CyberGhost05
class: Security Engineer
specialization:
  - Cloud Security & DevSecOps
  - Vulnerability Research
  - Offensive Security
active_operation: Black Pearl DFIR
location: Tamil Nadu, India
clearance: "responsible disclosure only"

SUBJECT ANALYSIS
Security engineer operating at the intersection of cloud defense, DevSecOps, application security, and offensive research. Attack paths are mapped, exploited under authorization, documented, and converted into resilient infrastructure.

Zero-day ledger section

Published Maximum Recognition

CASE 0x01 // GOOGLE MESOP AI

Critical RCE CVSS

Attack chain: Path traversal escalated into full remote code execution.
Identifiers: CVE-2026-33054 + CVE-2026-33057

CASE 0x02 // APPLE SWIFT-NIO

High DoS

Attack vector: Excessive 64-bit payload length destabilized the WebSocket frame decoder.
Identifier: CVE-2026-43678

CASE 0x03 // ACCESS CONTROL COLLAPSE

Budibase Directus

Budibase: Authorization bypass and unauthenticated credential exposure - CVE-2026-50137.
Directus CMS: Access-control failure enabling unauthorized data exposure - CVE-2026-35441.

CASE 0x04 // VENDOR BREACH REPORTS

APPLE CONTAINER - 2 official advisories: integer overflow + symlink traversal
MICROSOFT + ORACLE - 5 responsibly disclosed infrastructure and critical software flaws

APPLE ACKNOWLEDGED  •  GOOGLE ACKNOWLEDGED  •  MICROSOFT ACKNOWLEDGED  •  ORACLE ACKNOWLEDGED


◈ MSRC RESEARCHER CELEBRATION // BLACK HAT USA 2026 // INVITED ◈

Active deployments section

OPERATION 01 // DEVOPS DEFENDER // AI REMEDIATION ENGINE

Autonomous agent analyzes logs, isolates root causes, and deploys remediations across Kubernetes, Terraform, Jenkins, ArgoCD, Prometheus, and Grafana.

Impact State

OPERATION 02 // CYBERSECURITY ACADEMY // AI-POWERED LMS

Hybrid cyber labs, automated skill-gap analysis, personalized job matching, and a full administrative command center.

Users Stack

OPERATION 03 // CYBER RANGE // ADVERSARY SIMULATION GRID

Attack-and-defend range loaded with CTF, privilege-escalation, CVE, blue-team, and APT adversary-emulation scenarios.

Challenges AD

Operational history section

MISSION 01 // BLACK PEARL DFIR // 2026 - PRESENT

Role Status

Centralized threat-intelligence visibility across 5 critical networks. Automated response workflows cut resolution time by 30%, reclaimed 15 hours weekly, and processed approximately 50 threat alerts per week.

MISSION 02 // ISRO // 2025 - 2026

Role Status

Assessed 6 secured aerospace network segments, investigated critical event logs, and authored 10 incident-response protocols that improved workflow efficiency by 25%.

Arsenal matrix section

Domain Weapons loaded
Cloud & DevSecOps AWS, Azure, IAM, Kubernetes, Docker, Terraform, Jenkins, ArgoCD, Prometheus, Grafana
Offensive Security Web/API pentesting, Active Directory, adversary emulation, EDR evasion, OWASP Top 10, lateral movement
Detection & Response Splunk, SIEM, threat intelligence, detection engineering, incident response, vulnerability management
Security Tooling Burp Suite Pro, Metasploit, Nmap, Nessus, Wireshark, Ghidra, Postman
Engineering Python, JavaScript, Bash, PowerShell, React, Node.js, Express, Flask, MongoDB, MySQL
Engineering and cloud stack

Battle record section

Placement Campaign
WINNER Exploit-X International Hacking Event - KPR & EC-Council
WINNER L3m0nCTF National Hacking Event
RUNNER-UP ACNCTF National Hacking Event
2x 2ND RUNNER-UP HackQuest National Hacking Event
2ND RUNNER-UP KICTF State Hacking Event
Star Wars GIF

Certifications section

ASCP GitHub Advanced Security SOC 101

API Penetration TestingPractical Web HackingLinux Privilege Escalation

// ORIGIN_RECORD

B.Tech - Computer Science and Engineering (Cybersecurity)
Sri Shakthi Institute of Engineering and Technology, Coimbatore · 2023 - 2027 · GPA 8.6 / 10.0

Live telemetry section

GitHub contribution overview
GitHub streak GitHub statistics
GitHub activity graph
OPEN CLASSIFIED GITHUB TELEMETRY

Detailed GitHub metrics Yearly contribution calendar Terminal-style metrics

INTERCEPT ANILIST TRANSMISSION

AniList metrics Favorite AniList characters


THE SYSTEM IS NEVER SECURE. IT IS ONLY UNTESTED.

SECURITY ENGINEERING • CLOUD SECURITY • DEVSECOPS • RED TEAMING • VULNERABILITY RESEARCH

Threat dossier footer

Pinned Loading

  1. React2shell-poc React2shell-poc Public

    Python 15 5

  2. blackops-field-vulnerability-exploiter blackops-field-vulnerability-exploiter Public

    Python 1 1

  3. Red-Vault Red-Vault Public

    A modern, hacker-themed cybersecurity knowledge base and resource hub with curated links and docs

    HTML 1

  4. Threat-intell Threat-intell Public

    TypeScript

  5. quixel200/billing_management quixel200/billing_management Public

    PHP