Skip to content
View ronankongala's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report ronankongala

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ronankongala/README.md

Hi, I'm Ronan!

AI Cybersecurity Intern @ Abbott · MS Cybersecurity @ Northeastern, Khoury College

ronankongala.github.io · 25 case studies with write-ups

LinkedIn · kongalaronan@gmail.com · Boston, MA

Featured Projects

Selected work below. The complete log of 25 cases, filterable by tag, lives at ronankongala.github.io.

  • Red Team C2 Lab: Sliver C2 Adversary Emulation (CASE-26)

    • Ran Sliver C2 v1.7.7 against a Windows 11 Enterprise victim on an isolated VMware NAT network, executing 7 MITRE ATT&CK techniques from HTTPS beacon delivery to exfiltration over the C2 channel
    • Dumped the SAM and SYSTEM hives, parsed 5 accounts with pypykatz, and authenticated over SMB with pass-the-hash through impacket
    • Ships with 3 Sigma detection rules, an ATT&CK Navigator layer, and a red team report
    • GitHub Repo
  • FraudSentry: Fraud Detection, SHAP Explainability + Fairness Audit (CASE-25)

    • Compared 4 models on the IEEE-CIS dataset with a time-based split; RandomForest led at 0.748 ROC-AUC, catching 649 of 4,064 held-out fraud cases at a 3% false-positive budget
    • A fairness audit found a 23.7-point false-positive-rate spread across merchant categories, documented next to SHAP explanations and a GDPR DPIA
    • GitHub Repo
  • VulnTrack: Full-Stack Vulnerability Management with a DevSecOps Pipeline (CASE-23)

    • Spring Boot 4 and React vulnerability tracker on PostgreSQL with JWT authentication
    • The Jenkins pipeline's SonarQube SAST gate caught a BLOCKER and a CRITICAL violation, then passed once both were fixed
    • Deployed to Kubernetes with Helm (3 pods, 0 restarts), with Burp Suite DAST findings written up
    • GitHub Repo
  • Zero Trust Test Bed: mTLS, OIDC, OPA + Just-in-Time Vault Credentials (CASE-22)

    • Every request to the 3 microservices clears 4 layers: mutual TLS, Keycloak OIDC, OPA policy, and Vault credentials
    • 7 of 7 Rego tests pass, and a live 403 versus 200 split depends only on token roles
    • Vault credentials expire after 20 seconds and are rejected afterward; each control maps to NIST SP 800-207
    • GitHub Repo
  • FedRAMP RMF Compliance Lab: STIG Hardening, OpenSCAP + POA&M (CASE-21)

    • Took an Ubuntu 24.04 host through a FedRAMP Moderate RMF cycle with OpenSCAP and Ansible
    • The DISA STIG V1R5 score rose from 69.58% to 78.06% after 13 Ansible changes with 0 failures
    • 7 residual findings went into a POA&M, and the SSP covers all 20 NIST 800-53 Rev 5 families
    • GitHub Repo
  • Zeek Network Forensics + Beacon Detection (CASE-17)

    • Zeek 8.2.1 turned an SSLoad and Cobalt Strike PCAP into 17 structured logs
    • RITA flagged 85.239.53.219 as a beacon (score 0.504, 477 second mean interval)
    • 3 Jupyter threat hunting notebooks and 2 Sigma rules, mapped to 6 MITRE ATT&CK techniques
    • GitHub Repo
  • Malware Analysis Lab: AgentTesla Static, Dynamic + Memory Forensics (CASE-16)

    • Reverse engineered an AgentTesla stealer with PEStudio, CAPA, and Ghidra, finding MurmurHash API hashing
    • Wrote 3 YARA rules with zero false positives; the Any.run sandbox produced 87 IOCs, and its verdict also tagged Stealc/Vidar
    • Volatility 3 found code injection in SearchApp.exe and powershell.exe in a 7GB memory dump
    • GitHub Repo
  • AppSec Pipeline + Secrets Management Lab (CASE-15)

    • Wrapped OWASP WebGoat in a 3-gate CI/CD pipeline: Semgrep SAST (66 findings across 1,002 files), Checkov (3 Dockerfile misconfigurations) and Trivy (71 CVEs in the container image)
    • An OWASP ZAP active scan (961 requests) found 8 vulnerability categories, including missing CSRF protections
    • Moved credentials into the HashiCorp Vault KV engine with a rotation demo, and set up Okta OIDC SSO with MFA through Okta Verify
    • Mapped the environment against 16 PCI-DSS 4.0 requirements with an accepted risk register
    • GitHub Repo
  • Access-Governed RAG Console: LLM Access Control + Entra ID SSO (CASE-14)

    • Role-based access control runs at the retrieval layer, so restricted documents never reach the model for a user without the role
    • Microsoft Entra ID (OAuth2) sign-in maps app-role claims to backend RBAC, with a demo-login fallback that needs no external setup
    • A prompt-injection scanner resisted 10 of 10 cases in an attack battery; every access decision is audit-logged, and the app runs on Azure App Service
    • GitHub Repo

More projects

  • GuardDutySync (CASE-20): polls AWS GuardDuty with boto3, maps 13 finding types to 12 MITRE ATT&CK techniques, and opens Jira tickets. A second run skipped all 10 tickets from the first as duplicates.
  • Authorized Penetration Test, Metasploit Lab (CASE-19): exploited CVE-2011-2523 (vsftpd backdoor), CVE-2007-2447 (Samba RCE) and CVE-2017-0144 (EternalBlue) on Metasploitable2 and TryHackMe Blue, then wrote up 4 findings with CVSS scores, ATT&CK mapping and remediation.
  • Zeek Beacon Detector in OCaml (CASE-18): a functional port of the CASE-17 beacon scoring that isolates 10.0.0.5 at a 477.1s mean interval and variance 1.84.
  • NIST 800-171 / CMMC Compliance Baseline Lab (CASE-13): Active Directory, Group Policy, Intune device compliance and Entra ID Conditional Access, with a System Security Plan. The CMMC Level 2 self-assessment scored 12 of 15 practices met, and the remaining gaps are documented as next steps.
  • Agentic SOC Analyst (CASE-04): Claude queries Microsoft Sentinel through KQL, triages alerts, maps them to MITRE ATT&CK, and drafts incident summaries for human review.
  • AWS CloudTrail Threat Detection Pipeline (CASE-05): CloudTrail events trigger a Lambda function that checks 11 ATT&CK-mapped rules and alerts through SNS. Email alerts fired on all 6 test invocations with no Lambda errors.
  • Suricata IDS + ELK Stack on AWS EC2 (CASE-06): Suricata 7.0.3 with custom rules, shipped through Filebeat to Elasticsearch and charted in Kibana.
  • S3 Security Auditor (CASE-07): a boto3 tool that runs 6 checks per bucket (public ACL, encryption, versioning, logging and more) and writes a JSON risk report.
  • SOC Automation Lab with AI Threat Analysis (CASE-02): Windows event logs flow through Splunk and n8n to OpenAI GPT-4, and the verdict posts to Slack in under 60 seconds. Tested on failed-logon events. Event journey
  • SOC 2 Type I Audit Simulation (CASE-03): a mock audit of that SOC automation lab against CC6, CC7 and A1, with a risk assessment, control mapping and 6 findings.
  • Fake Job Posting Detection (CASE-01, IEEE ICAISS 2025): ensemble ML (Random Forest, XGBoost, Gradient Boosting, AdaBoost) with SMOTE/ADASYN balancing reached 98% accuracy on 9,000+ postings. Presented at the 3rd International Conference on Augmented Intelligence and Sustainable Systems. Read the paper
  • Kali Linux SSH MCP Bridge (CASE-12): connects Claude Desktop to a Kali Linux terminal over SSH through the Model Context Protocol, for AI-assisted penetration testing.

Coursework

  • CS-5770: Software Vulnerabilities and Security

    • Security challenges in network forensics, web exploitation and privilege escalation, with written methodology for packet analysis, SQL injection, command injection and Unix security
    • Tools: Wireshark, Nmap, Burp Suite
    • Private repo (course policy). Write-ups available on request.
  • CY5001: Cybersecurity Technologies, Threats and Defense

    • Linux security, cryptography and network defense: GPG/PGP encryption, OpenSSL operations, digital signatures and hybrid encryption
    • Wrote Bash scripts for system hardening and threat detection
    • Private repo (course policy). Write-ups available on request.

Professional Experience

  • AI Cybersecurity Intern at Abbott, Madison WI (Hybrid) · Sep 2026 to Present

    • Contributing to ExmanIq, an internal vulnerability management platform that tracks 22,000+ vulnerabilities across organizational assets with a predictive Impact x Likelihood risk model enriched with EPSS and NVD threat intelligence
    • Diagnosed a 27-day silent data-pipeline failure after spotting an anomalous flat trend in the platform's composite risk score
    • With a teammate, built CrowdCheck Hive, which pulls CrowdStrike, Microsoft Intune and ServiceNow CMDB data together to find devices missing endpoint security coverage
    • Python, Microsoft Azure Machine Learning
  • Cybersecurity Intern at Exact Sciences, Madison WI (Hybrid) · Jun 2026 to Sep 2026

    • Automated KeyCheck, a credential-risk monitoring pipeline that scans 1,300+ application registrations for expiring credentials before they cause an incident
    • Co-built Baseline Guardian, an endpoint compliance check that compares CrowdStrike, Microsoft Intune, Tanium and ServiceNow CMDB records to assess security posture
  • Teaching Assistant, CY5001 at Northeastern University, Khoury College · Jan 2026 to Apr 2026

    • Ran lab sessions and graded 200+ assignments for 61 graduate students in Cybersecurity Threats and Defenses, resolving 150+ Piazza queries within a 24-hour SLA and cutting lab completion time by 30%
  • Cybersecurity Intern at NIELIT Virtual Academy, Ministry of Electronics and IT · Aug 2024 to Oct 2024

    • Assessed network security across 3 live environments with Nmap and Docker, and used Random Forest models to detect anomalies in security data
  • Web Development Trainee at Quizaro ExtendedEdge (Remote) · Feb 2024 to Apr 2024

    • Completed an ISO 9001:2015 certified specialization in frontend architecture and web technologies
  • Data Science Analyst Intern at Rejolt Edtech Pvt Ltd, Hyderabad · Oct 2023 to Nov 2023

    • Automated data extraction pipelines for client reporting with Python (NumPy, Pandas, scikit-learn)

Industry Simulations

Certifications and Training

View Individual Course Certificates
  • Foundations of Cybersecurity: Certificate
    • CIA triad, security frameworks, threat modeling
  • Risk Management: Certificate
    • Risk assessments, security controls, compliance
  • Network Security: Certificate
    • TCP/IP, subnetting, firewall configuration, VPNs
  • Linux and SQL Security: Certificate
    • System hardening, database security, log analysis

Quick References and Exercises:

Education

  • MS Cybersecurity, Northeastern University, Boston (2025 to 2027)

    • GPA: 3.86/4.0
    • Relevant Coursework: Software Vulnerabilities and Security (CS-5770), Cybersecurity Technologies, Threats and Defense (CY5001), Network Forensics
    • Focus: Applied cryptography, secure systems, threat analysis
  • B.Tech AI and Data Science, Vardhaman College of Engineering (2021 to 2025)

    • Focus: Machine Learning, Data Mining, Statistical Analysis
    • Capstone: AI-based Intrusion Detection System

Technical Skills

Network Forensics: Zeek • RITA • Wireshark • Beacon Detection • PCAP Analysis • Jupyter • Sigma Rules
Malware Analysis: PEStudio • CAPA • Ghidra • YARA • CAPE Sandbox • Any.run • winpmem • Volatility 3
Vulnerability Management: Nessus • OpenSCAP • DISA STIG • EPSS • NVD • CVSS v3.0 • Risk Scoring • POA&M
Detection and SIEM: Splunk • Microsoft Sentinel • KQL • Suricata • Elastic/ELK • AWS GuardDuty
Offensive Security: Metasploit • Nmap • Burp Suite • Kali Linux • OWASP ZAP • Sliver C2 • impacket • pypykatz
AppSec and CI/CD: Semgrep • SonarQube • Trivy • Checkov • Jenkins • GitHub Actions • Terraform • HashiCorp Vault • Okta OIDC
Endpoint and Asset: CrowdStrike • Microsoft Intune • Tanium • ServiceNow CMDB
Identity and Compliance: Active Directory • Group Policy • Microsoft Entra ID • Conditional Access • NIST 800-171 • CMMC • FedRAMP Moderate • SOX/COSO • GDPR (Article 35 DPIA, Articles 15/17)
Zero Trust and Access Control: Keycloak (OIDC / SAML 2.0) • Open Policy Agent • Rego • mutual TLS / PKI • HashiCorp Vault just-in-time credentials • NIST SP 800-207
Cloud Security: AWS CloudTrail • AWS Lambda • Amazon S3 • boto3 • GCP • Azure • Azure App Service
AI and Automation: Claude AI • OpenAI GPT-4 • n8n • Model Context Protocol (MCP) • RAG • LLM Security • Prompt Injection Defense • Jira REST API
ML and Model Assurance: scikit-learn • XGBoost • SHAP • imbalanced-learn (SMOTE) • Subgroup Fairness Auditing • Model Explainability
Cryptography: OpenSSL • GPG/PGP • AES • RSA • Digital Signatures
Programming: Python • Java (Spring Boot) • SQL • Bash • PowerShell • KQL • JavaScript • TypeScript (React) • OCaml
Platforms: Linux • Windows Server • Docker • Kubernetes • Helm • PostgreSQL • VMware • AWS • Azure • GCP • Ansible
Frameworks: MITRE ATT&CK • NIST SP 800-30 • NIST SP 800-207 • NIST SP 800-53 Rev 5 • NIST SP 800-171 • NIST CSF • CMMC • FedRAMP • CIS Controls • OWASP Top 10 • PCI DSS 4.0 • SOC 2

Connect With Me

LinkedIn Email GitHub


Seeking Summer and Fall 2027 cybersecurity co-op and internship roles in SOC and detection engineering, malware analysis, cloud security, vulnerability management, GRC, and AI/LLM security.

Pinned Loading

  1. fedramp-rmf-lab fedramp-rmf-lab Public

    FedRAMP-aligned RMF compliance lab: DISA STIG hardening via Ansible, OpenSCAP/SCAP scanning, POA&M, SSP, FedRAMP control mapping, and SOX/COSO access certification on Ubuntu 24.04.

  2. fraudsentry fraudsentry Public

    Transaction fraud detection pipeline: modeling, SHAP explainability, subgroup fairness audit, case tracking and a GDPR Article 35 DPIA. Run on both synthetic and real IEEE-CIS data.

    Python

  3. guardduty-sync guardduty-sync Public

    Python automation pipeline that polls AWS GuardDuty findings, enriches each finding with MITRE ATT&CK context, and auto-creates triage tickets in Jira Cloud.

    Python

  4. malware-analysis-lab malware-analysis-lab Public

    AgentTesla static, dynamic, and memory forensics using Ghidra 12.1.2, CAPA, YARA 4.5.5, and Volatility 3. 3 custom YARA rules, 87 IOCs, 11 MITRE ATT&CK techniques.

    YARA

  5. ot-honeypot-gcp ot-honeypot-gcp Public

    Internet-facing OT honeypot on GCP with Suricata and SIEM integration. 66,185 events captured in the first hour, 15,315 Suricata alerts, Telnet port 23 as top target.

  6. zeek-network-forensics-lab zeek-network-forensics-lab Public

    Zeek 8.2.1 and RITA v5.1.2 beacon hunt on a live SSLoad plus Cobalt Strike PCAP. 17 structured logs, beacon score 0.504 at 477s intervals, 6 MITRE ATT&CK techniques, 2 Sigma rules.

    Jupyter Notebook