REGAAN R
Security researcher & systems engineer.
SEC_LAB // R&D PORTFOLIO

REGAAN R

Offensive Security Engineer | Security Researcher
Researching Web Security, AI Red Teaming, Protocol Fuzzing and Offensive Engineering.

  • CVE Research
  • AI Security
  • Web Application Security
  • WebSocket Security
  • Open Source Tools

Security Researcher and Full-Stack Engineer specializing in Offensive Security, Systems Programming, and Mobile Application Security.

26Public Repositories
15Core Security Tools Built
50+Students Mentored
4+Years of R&D Experience

Technical Arsenal

  • WebSocket Security
  • Penetration Testing
  • OWASP Top 10
  • AST Evasion & WAF Bypass
  • OAST & Session Hijacking
  • XSS / SQLi / SSRF / XXE

Core Stack

  • Go / Python / Java / C++
  • LLVM Compiler Design
  • React / Next.js / Node.js
  • React Native / Smali
  • Docker / Redis / MongoDB
  • Burp Suite / OWASP ZAP

Core Domains

  • Vulnerability Research
  • Compiler Engineering
  • Malware Analysis
  • Exploit Development
  • Android & iOS Posture
  • Full-Stack Security Architecture

Timeline.

2021

Research Inception

Initiated self-directed study in assembly logic, reverse engineering, and low-level malware analysis paradigms.

2022

First Open-Source Security Tools

Released SQLMap tamper collections implementing AST queries to bypass Enterprise WAF rules, gaining initial community adoption.

2023

Founded Rot Hackers

Established Rot Hackers security R&D lab to deliver advanced security tool writeups, building core framework infrastructures.

2024

Academy & Mobile Launch

Architected and deployed Rot Hackers Academy SaaS and mobile applications with end-to-end encrypted logic.

2025

Offensive Systems Scaling

Released WSHawk WebSocket fuzzer, Basilisk red-teaming AI framework, and lectured mobile app security to 50+ students.

CVE Disclosures.

High SeverityCWE-918

lollms-webui Server-Side Request Forgery via /api/proxy

Platform: ParisNeo/lollms-webui

View Exploit PoC ↗
Critical SeverityCWE-95

lollms-webui Unauthenticated Remote Code Execution via Insecure eval()

Platform: ParisNeo/lollms-webui 20.0 Alpha

View Exploit PoC ↗
Critical SeverityCWE-770

Ollama GGUF String Length Panic Denial of Service

Platform: Ollama < v0.3.14

View Exploit PoC ↗
High SeverityCWE-400

Ollama Resource Exhaustion via Unbounded vocab_size

Platform: Ollama < v0.3.14

View Exploit PoC ↗
High SeverityCWE-184

LiteLLM Sandbox Escape via Unicode Normalization Bypass

Platform: LiteLLM < v1.51.5

View Exploit PoC ↗
High SeverityCWE-918

LiteLLM Server-Side Request Forgery inside Custom Guardrails

Platform: LiteLLM < v1.51.0

View Exploit PoC ↗
Critical SeverityCWE-287

LiteLLM Authentication Bypass via Pass-the-Hash

Platform: LiteLLM < v1.50.0

View Exploit PoC ↗

Experience.

2024 — Present

ROT Independent Security Lab

Security Research Engineer [ACTIVE]

Leading offensive R&D and engineering production-grade security artifacts, specializing in high-performance fuzzer development and protocol research.

  • Architected WSHawk, achieving benchmarks of 350k+ executions/sec using raw syscall optimization in Go for distributed vulnerability discovery.
  • Developing AI/LLM security frameworks (Basilisk) for automated red teaming and genetic prompt evolution, achieving zero-false-positive XSS verification.
  • Managing community-driven open-source projects with significant adoption (900+ clones in 14 days).
Workshop Instructor

eHackify

Modern Cyber Attack Engineering [COMPLETED]

Delivered a 2.5-hour workshop covering malware development concepts, reverse engineering, exploitation flows, C2 frameworks, OPSEC, and red-team methodology.

Guest Lecturer

Dwaraka Doss Goverdhan Doss Vaishnav College

Mobile App Development [COMPLETED]

Led an intensive 30-day certification program covering full-stack logic, API integration, and database management for mobile environments, mentoring 50+ students through the end-to-end lifecycle.

Guest Speaker

Mohamed Sathak Polytechnic College

Cybersecurity Fundamentals [COMPLETED]

Delivered a 4-hour comprehensive workshop on modern cybersecurity landscapes, vulnerability research, secure coding practices, and industry career paths.

Self-Directed Study

Independent Research

Cybersecurity & Software Engineering [ONGOING]

Focused on offensive security, secure full-stack engineering, AI systems, compiler design, and security tool development through structured, hands-on learning.

Research.

Preprint2026-07-09

WSHawk: Stateful Security Assessment of WebSocket Applications through Adaptive Payload Mutation and Browser-Assisted Validation

Most automated web-application scanners are built around the request/response model of HTTP and do not translate cleanly to WebSocket endpoints, where a single ...

Read Publication ↗
Preprint2026-03-08

Basilisk: An Evolutionary AI Red-Teaming Framework for Systematic Security Evaluation of Large Language Models

Basilisk is an open-source artificial intelligence (AI) red teaming and large language model (LLM) penetration testing framework. It maps the adversarial attack...

Read Publication ↗

Feedbacks.

"The 30-day mobile security and development workshop helped bridge the gap between building logic and understanding runtime exploit paths."

— DDGDVC Student Certification Review

"Demonstrated exceptional technical clarity in detailing how user-mode kernel hooks are bypassed in C2 simulations."

— eHackify Attendee Review

Works.

Let's talk.

Security Consulting & Vulnerability Research

  • Response Latency: < 24 Hours
  • Engagement Types: Code Auditing, Protocol Fuzzing, Red Teaming
Download CV (PDF)