I'm a Master's student in Information Security at Carnegie Mellon University (graduating Dec 2026), with industry experience in offensive security, vulnerability research, and security engineering. My interests span AI/LLM security, hardware and firmware security, red teaming, RF/wireless sensing, cloud security, and application/API security.
🌐 Portfolio: https://keyuraghao.github.io/Portfolio/
- 🥇 1st place, internationally, at MITRE's Embedded Capture the Flag (eCTF) 2026, against 100+ university teams: hardware fault injection, side-channel analysis, and firmware exploitation.
- 🔓 Published the first public proof-of-concept for CVE-2025-20260 (CVSS 9.8, Critical), a buffer overflow in ClamAV's PDF scanner.
- 🛡️ 2× Microsoft MSRC acknowledged for coordinated vulnerability disclosures.
- 🛰️ Firmware and wireless-protocol security research on consumer drones (multiple zero-day findings, responsible disclosure in progress).
| Project | What it is |
|---|---|
| AISRF | AI Security & Research Framework: a human-in-the-loop gateway that turns every LLM/agent request into a ticket a person approves, with analyzers, guardrails, a red-team engine (garak, promptfoo, PyRIT) and an MCP server. |
| Mobile Security Research Framework | Cross-platform Mobile & IoT SAST/DAST/pentest toolkit over MobSF, Frida, objection and mitmproxy, as a desktop app, CLI and MCP server. |
| EDB Explorer | Cross-platform GUI, CLI and MCP server for forensic database analysis (ntds.dit, SRUM, Exchange, SQLite, EVTX, LevelDB), strictly read-only. |
| wifisense | Device-free WiFi RF sensing: detect motion/objects from ordinary WiFi RSSI, with an ESP32 mesh for 3D radio-tomographic imaging. Python pipeline + firmware for 6 ESP32 families. |
| CVE-2025-20260 | First public PoC for a CVSS 9.8 ClamAV PDF-scanning buffer overflow, with core-dump analysis. |
| Cloud_Piercer_V2 | Multi-cloud CSPM tool that discovers publicly reachable storage across AWS S3, Azure Blob and GCP, with AI-based risk prioritization. |
| SubHunter | Installable CLI for enterprise-grade subdomain enumeration and vulnerability scanning, unifying multiple OSINT/offensive sources. |
| AMSI-Bypass | Red-team reference for PowerShell-only and global AMSI evasion techniques, with defender detection notes, for defensive testing. |
| vscode-code-hierarchy | A VS Code extension: a live function/class hierarchy docked beside your code, with fuzzy search. |
- AI / LLM security: red teaming LLM apps and agents, guardrails, and human-in-the-loop review (AISRF)
- Embedded systems & RF sensing: ESP32 firmware and a device-free WiFi sensing / radio-tomography mesh (wifisense)
- Cloud & application security: posture management, vulnerability management, secure SDLC
Languages: Python, Go, C/C++, Bash, PowerShell, TypeScript, x86 Assembly, VHDL
AI security: AI red teaming, prompt injection, jailbreak testing, adversarial ML, OWASP LLM Top 10, PyRIT, promptfoo, garak, Rebuff, LLM Guard, NeMo Guardrails, Lakera Guard
Security: Burp Suite, Metasploit, Cobalt Strike, Nmap, Nessus, Wireshark, Ghidra, IDA, Splunk, QRadar, Maltego, Autopsy
Hardware: ChipWhisperer, fault injection, KiCad, UART/SPI/I2C
Platforms: AWS, Azure, GCP, Docker, ADB, Qiskit, Xilinx
Focus: Offensive Security, AI/LLM Security, Hardware/Firmware Security, Cloud Security, Application & API Security, Incident Response, Digital Forensics
Certifications: CEHv11, CND, Cryptography and Network Security, OSCP (In-Progress)
- Email: kaghao@andrew.cmu.edu
- LinkedIn: https://www.linkedin.com/in/keyur-aghao
- Portfolio: https://keyuraghao.github.io/Portfolio/
- Calendly: https://calendly.com/kaghao-andrew
