REGAAN R
Security researcher & systems engineer.
SEC_LAB // R&D PORTFOLIO

REGAAN R

Offensive Security Engineer | Security Researcher
Researching Web Security, AI Red Teaming, Protocol Fuzzing and Offensive Engineering.

  • CVE Research
  • AI Security
  • Web Application Security
  • WebSocket Security
  • Open Source Tools

Security Researcher and Full-Stack Engineer specializing in Offensive Security, Systems Programming, and Mobile Application Security.

22,806WSHawk Payloads
46Basilisk Lab Scenarios
50+Students Mentored
4+Years of R&D Experience

Technical Arsenal

  • WebSocket Security
  • Penetration Testing
  • OWASP Top 10
  • AST Evasion & WAF Bypass
  • OAST & Session Hijacking
  • XSS / SQLi / SSRF / XXE

Core Stack

  • Go / Python / Java / C++
  • LLVM Compiler Design
  • React / Next.js / Node.js
  • React Native / Smali
  • Docker / Redis / MongoDB
  • Burp Suite / OWASP ZAP

Core Domains

  • Vulnerability Research
  • Compiler Engineering
  • Malware Analysis
  • Exploit Development
  • Android & iOS Posture
  • Full-Stack Security Architecture

Timeline.

2021

Research Inception

Initiated self-directed study in assembly logic, reverse engineering, and low-level malware analysis paradigms.

2022

First Open-Source Security Tools

Released SQLMap tamper collections implementing AST queries to bypass Enterprise WAF rules, gaining initial community adoption.

2023

Founded Rot Hackers

Established Rot Hackers security R&D lab to deliver advanced security tool writeups, building core framework infrastructures.

2024

Academy & Mobile Launch

Architected and deployed Rot Hackers Academy SaaS and mobile applications with end-to-end encrypted logic.

2025

Offensive Systems Scaling

Released WSHawk WebSocket fuzzer, Basilisk red-teaming AI framework, and lectured mobile app security to 50+ students.

Security Disclosures.

Critical SeverityCWE-95

lollms-webui Unauthenticated Remote Code Execution via Insecure eval()

Platform: ParisNeo/lollms-webui 20.0 Alpha

View Technical Advisory ↗

Experience.

2024 — Present

ROT Independent Security Lab

Security Research Engineer [ACTIVE]

Leading offensive R&D and engineering production-grade security artifacts, specializing in high-performance fuzzer development and protocol research.

  • Architected WSHawk, a stateful HTTP and WebSocket security toolkit with a 22,806-payload corpus, paired ground-truth labs, and separate Python and Go-backed desktop editions.
  • Developing Basilisk for AI/LLM security testing with Smart Prompt Evolution, 33 attack modules, 263 deterministic probes, and evidence-backed reporting.
  • Maintaining reproducible security labs and cross-platform release workflows for Windows, Linux, and macOS.
Workshop Instructor

eHackify

Modern Cyber Attack Engineering [COMPLETED]

Delivered a 2.5-hour workshop covering malware development concepts, reverse engineering, exploitation flows, C2 frameworks, OPSEC, and red-team methodology.

Guest Lecturer

Dwaraka Doss Goverdhan Doss Vaishnav College

Mobile App Development [COMPLETED]

Led an intensive 30-day certification program covering full-stack logic, API integration, and database management for mobile environments, mentoring 50+ students through the end-to-end lifecycle.

Guest Speaker

Mohamed Sathak Polytechnic College

Cybersecurity Fundamentals [COMPLETED]

Delivered a 4-hour comprehensive workshop on modern cybersecurity landscapes, vulnerability research, secure coding practices, and industry career paths.

Self-Directed Study

Independent Research

Cybersecurity & Software Engineering [ONGOING]

Focused on offensive security, secure full-stack engineering, AI systems, compiler design, and security tool development through structured, hands-on learning.

Research.

Preprint2026-07-09

WSHawk: Stateful Security Assessment of WebSocket Applications through Adaptive Payload Mutation and Browser-Assisted Validation

Most automated web-application scanners are built around the request/response model of HTTP and do not translate cleanly to WebSocket endpoints, where a single ...

Read Publication ↗
Preprint2026-03-08

Basilisk: An Evolutionary AI Red-Teaming Framework for Systematic Security Evaluation of Large Language Models

Basilisk is an open-source artificial intelligence (AI) red teaming and large language model (LLM) penetration testing framework. It maps the adversarial attack...

Read Publication ↗

Feedbacks.

"The 30-day mobile security and development workshop helped bridge the gap between building logic and understanding runtime exploit paths."

— DDGDVC Student Certification Review

"Demonstrated exceptional technical clarity in detailing how user-mode kernel hooks are bypassed in C2 simulations."

— eHackify Attendee Review

Works.

Let's talk.

Security Consulting & Vulnerability Research

  • Response Latency: < 24 Hours
  • Engagement Types: Code Auditing, Protocol Fuzzing, Red Teaming
Download CV (PDF)