Pratiksha BandeFinal-year engineering student

Security startswith howyou think.

Cybersecurity × IoT × Blockchain Technology

Full-Stack × Cloud Security × AI Security × DevSecOps

I build and explore secure systems across cybersecurity, cloud, AI security and privacy.

Portrait of Pratiksha Bande
Studying
B.E. in C.S.E., IoT and Cyber Security including Blockchain Technology
College
Guru Nanak Dev Engineering College, Bidar (VTU), 2023 – 2027
Academics
CGPA 8.08 / 10, First Class with Distinction. 8.89 SGPA in 6th semester.
Based in
Bidar, Karnataka, India
Status
Final year, open to internships

About

I'm a final-year engineering student at Guru Nanak Dev Engineering College in Bidar, studying C.S.E. with IoT and Cyber Security including Blockchain Technology.

Security is the thread through all of it. I'm CEH v13 certified, comfortable in Kali Linux, Burp Suite, Nmap, Wireshark and Zeek, and across three internships I've worked on vulnerability assessment, network monitoring, log analysis and static code analysis. Alongside that I build my own projects: red-teaming machine learning models, automating infrastructure across clouds, and designing a blockchain-backed privacy system for healthcare data. I can also build the applications and APIs I'm securing, with React and TypeScript on the front end and Flask or Node.js with MongoDB behind it, which makes it easier to see where a system can go wrong.

I tend to think about how a system could be misused before I think about how it's supposed to work. That habit shapes what I build, and it's why I'm drawn to the places where security meets other fields: connected devices, distributed ledgers and AI.

What I work on

Security is the common thread. Some areas are central to my degree; others are where I apply it.

At the core

Offensive security

Finding weaknesses before someone else does. VAPT, ethical hacking, vulnerability assessment, threat modelling, web and network security, with Kali Linux, Burp Suite, Nmap and Metasploit.

Defensive and network security

Intrusion detection, traffic analysis, monitoring, log analysis and threat detection, using Wireshark and Zeek, with foundational Splunk.

IoT and connected systems

Part of my degree, and part of how I think about attack surface. I look at connected devices through the network layer they all depend on: traffic analysis, intrusion detection, and my published research on ARP poisoning prevention.

Blockchain and data privacy

Ethereum, smart contracts, Web3.py, DPDP Act 2023 compliance and secure healthcare systems.

Where I apply it

AI and ML security

Adversarial ML with FGSM and PGD, prompt injection, LLM security and AI-based phishing detection. Certified as an LLM Security Expert (CLLMSE).

Cloud and DevSecOps

AWS, OCI, Terraform and Docker. Infrastructure as code and deployment automation, so environments are consistent and repeatable.

Selected work

Four projects I'm most proud of. More of my practical work follows further down.

Red teamFGSMPGDConfigurable strength Target modelPyTorch Blue teamAdversarial trainingDenoisingRandomized smoothing BenchmarkAttack success vs defence effectiveness
Architecture sketch

AI security, independent project

Adversarial AI Attack and Defence Simulator

Why I built it
Claims about model robustness mean little until you attack the model yourself and measure how its defences hold up.
What I built
A PyTorch simulator organised as a Red Team vs. Blue Team framework. The red side runs FGSM and PGD attacks with configurable strength. The blue side defends with adversarial training, denoising and randomized smoothing.
What I explored
Robustness isn't a fixed property. I benchmarked attack success against defence effectiveness to compare how well each defence holds against the attacks.

Built with Python, PyTorch, FGSM, PGD, adversarial training, denoising, randomized smoothing

View on GitHub
Docker Patient Doctor Admin React + TypeScript dashboards Flask APIJWT authentication, AES-256 encryption MongoDB Ethereum (Ganache)via Web3.pyConsent verificationImmutable audit trailChameleon Hash redaction Supports Right to Correctionand Right to Erasure
Architecture sketch

Blockchain, privacy and healthcare, independent project, 2026 – present

DPDP Act 2023 Compliance and Data Privacy Protection System

Why I built it
India's DPDP Act 2023 puts consent and data-subject rights at the centre of how personal data is handled. I wanted to see what that looks like when it's built into a healthcare system itself.
What I built
A full-stack, Docker-containerized platform: React and TypeScript dashboards for Patient, Doctor and Admin roles, with a Flask API and MongoDB behind them, secured with JWT authentication and AES-256 encryption.
What I explored
A blockchain is meant to be unchangeable, which collides with correction and erasure. I used Chameleon Hash redaction on an Ethereum (Ganache) ledger, through Web3.py, so consent verification and audit trails stay immutable while still supporting Right to Correction, Right to Erasure and compliance monitoring.

Built with React, TypeScript, Flask, MongoDB, Docker, JWT, AES-256, Ethereum, Ganache, Web3.py. A compliance-oriented prototype, not a certified compliance product.

View on GitHub
TerraformInfrastructure as code Cloud environmentContainerized with Docker Cloud environmentContainerized with Docker Cloud environmentContainerized with Docker
Architecture sketch

Cloud and DevSecOps, independent project, since March 2026

AI-Powered Multi-Cloud Portability and Deployment Automation Platform

Why I built it
Setting up the same infrastructure by hand in every environment is slow, and small differences between environments are a common source of cloud misconfiguration.
What I built
Scalable multi-cloud infrastructure defined in Terraform, with application environments containerized in Docker so the same deployment behaves consistently everywhere it runs.
~35–40%approximate reduction in manual
provisioning effort

Built with Terraform, Docker, multi-cloud infrastructure

View on GitHub

Team project, cybersecurity and blockchain hackathon

GramKavach

ADVAYA 2.0, a 24-hour national hackathon at BGS College of Engineering and Technology, Bengaluru. 1 – 2 April 2026.

  1. DetectSuspicious activity enters the workflow
  2. AlertAn alert is generated for the user
  3. VerifyThe user confirms or flags it
  4. EscalateSuspicious or unresolved cases move up
  5. RespondThe right response can be started
The problem
Many security tools assume reliable connectivity, strong digital literacy and quick access to help. Rural and digitally vulnerable users often have none of the three, which leaves them more exposed to fraud and unauthorised account activity. Our idea was that security should reach the user, rather than depend on the user reaching it.
What our team built
A prototype alert-and-verification layer between suspicious financial activity and the people who need to respond to it: alerts, user verification, escalation, an SMS-oriented notification workflow, and offline-first considerations for low-connectivity areas. The front end is React, TypeScript and Vite. The back end is Supabase/PostgreSQL, with Row Level Security for database-level access control.
Where it stands
A hackathon proof of concept, not a production banking system, and the repository says so too. Risk scoring and blockchain-backed audit trails are on its roadmap, not shipped.

Built with React, TypeScript, Vite, Supabase, PostgreSQL, Row Level Security

View on GitHub
In progress

Currently building: SafeStack

An AI-powered software supply-chain defence platform.

SafeStack scans a project's dependencies for known vulnerabilities, explains what it found, proposes a fix, tests that fix in isolation and opens a pull request. It never edits your main branch. You decide whether the change goes in.

  1. Detectnpm audit, OSV API
  2. ExplainGoogle Gemini
  3. RecommendA suggested fix
  4. Safe fixOn an isolated SafeStack branch
  5. TestIn a Docker sandbox
  6. Re-testConfirm the fix holds
  7. Create PRGitHub App, scoped tokens
  8. User decidesYou review and merge

Design principles

  • No direct changes to main or master
  • Isolated SafeStack branches for every fix
  • Untrusted code runs in Docker isolation
  • No stored user tokens
  • Scoped GitHub permissions
  • JWT authentication
  • Polling instead of WebSockets

Planned architecture

Frontend
React 18, TypeScript, Vite, TailwindCSS
Backend
Node.js, TypeScript, Express, MongoDB, Mongoose
Isolation
Docker for untrusted code
AI
Google Gemini
GitHub
GitHub App with scoped installation tokens
Scanning
npm audit and the OSV API

Data model

  • User
  • Project
  • Scan
  • Vulnerability
  • Fix
  • TestResult
  • PullRequest

SafeStack is under active development. This is the architecture and the principles I'm building toward, not a finished product.

More security work

Smaller builds and internship tasks, each with its own repository.

  • Network Intrusion Detection

    Network monitoring that analyses traffic patterns and flags anomalies.

    CodeAlphaGitHub
  • Network Traffic Analysis Toolkit

    Capture and analyse network traffic for security monitoring and threat detection.

    IndependentGitHub
  • Vulnerability Assessment and Threat Modeling

    A vulnerability scanner for assessing systems and modelling threats.

    ThiranexGitHub
  • AI-Powered Phishing Email Detection

    A machine-learning model that classifies emails as phishing or legitimate.

    ThiranexGitHub
  • Secure Login System WebApp

    A web application built around secure authentication practices.

    ThiranexGitHub
  • Secure Coding Review

    Static analysis of an intentionally vulnerable Python application, with the flaws documented.

    CodeAlphaGitHub
  • Password Strength Analyzer

    Security task from the Thiranex internship.

    ThiranexGitHub
  • Automated Cloud Infrastructure Setup

    Cloud infrastructure provisioned with Terraform on OCI. About 40% less manual provisioning and about 30% fewer configuration errors.

    IndependentGitHub
  • Cloud Security Engineering Labs

    Hands-on labs for practising cloud security engineering.

    IndependentGitHub

Experience

Three cybersecurity internships, most recent first.

May 2026 – Jun 2026

Thiranex

Cyber Security Intern

  • Conducted vulnerability assessments and completed practical cybersecurity projects under industry mentorship.

Four practical tasks: Password Strength Analyzer Vulnerability Scanner Phishing Detection Secure Login

Internship repository

May 2026

CodeAlpha

Cyber Security Intern

  • Engineered and deployed a network monitoring solution to analyse traffic patterns and detect anomalies.
  • Ran static code analysis to identify vulnerabilities and support secure software practices.

Tasks: Network Intrusion Detection Secure Coding Review

Internship repository

Jun 2025 – Jul 2025

Future Interns

Cybersecurity Intern (Trainee), security monitoring and incident documentation

  • Analysed and tested web applications and network systems, identifying issues and supporting their resolution.
  • Helped monitor system activity, analysed application logs and documented findings to improve reliability.
Internship repository

Toolkit

What I reach for most is in bold.

Security

Penetration testing, VAPT, ethical hacking, threat analysis, network security, OWASP Top 10, LLM security, prompt injection, RAG security, MCP security, SIEM fundamentals, log analysis.

Security tools

Kali Linux, Burp Suite, Nmap, Wireshark, Zeek, Metasploit, Splunk (foundational), Git, GitHub, VS Code, VirtualBox, Vagrant.

Cloud and DevSecOps

AWS, OCI, Terraform, Docker, Kubernetes, GitHub Actions, Jenkins, Azure (foundational exposure).

Programming and full-stack development

Python, JavaScript, TypeScript, React.js, Flask, Java, C, SQL, Node.js, Express, FastAPI, MongoDB, REST APIs, Web3.py, HTML, CSS.

Operating systems

Linux, Windows.

Credentials

Certifications

  • Certified Ethical Hacker (CEH v13)

    EC-Council

    View
  • Certified Online Fraud Prevention Specialist (COFPS)

    Hack & Fix Academy

    View
  • Oracle Cloud Infrastructure 2025 Certified Foundations Associate

    Oracle University

    View
  • Certified Large Language Model Security Expert (CLLMSE)

    Red Team Leaders

    View
  • Microsoft AI Skills Fest 2026

    Microsoft

    View
  • AWS Foundations: Getting Started with AWS Cloud Essentials

    Amazon Web Services

    View
  • Getting Started with Cybersecurity

    IBM SkillsBuild

    View

Publication

HBRP Research Publication, Vol. 01, Issue 02, 2025

ARP Poisoning Prevention Using ICMP-Based Validation and Centralized Voting

Read the publication

Beyond the code

Hackathons, community work and GitHub achievements.

  • GNDEC Bidar

    Secretary, Cyber Samurai Association

    Planned and coordinated Hacktober, a cybersecurity awareness event for 150+ students.

  • Apr 2026

    ADVAYA 2.0, 24-hour national hackathon

    BGS College of Engineering and Technology. This is where GramKavach was built.

    Proof
  • 2026

    Cyber Kushti Hackathon

    Participant.

    Proof
  • 2026

    National Financial Literacy Quiz

    Organised by NISM and SEBI. Participant.

    Proof
  • GitHub

    Pull Shark and Pair Extraordinaire

    Badges for merged pull requests and co-authored commits.

    Proof

Let's talk security.

I'm looking for cybersecurity internships and opportunities in security research, cloud security, AI security and secure systems, anywhere that kind of thinking is genuinely needed.

Bidar, Karnataka, India
+91-7204845588