Kshitija Mhatre (OffSec Lead)
Co-Founder & Lead Security Researcher
Offensive Security Engineer specializing in Android VAPT, IoT Hardware Teardowns & Firmware Exploitation.
Background & Security Philosophy
Kshitija is the co-founder and offensive security lead at Sukshield. With over half a decade in adversarial security testing, he focuses on dissecting Android mobile applications, IoT firmware binaries, and embedded hardware communication buses.
His research has uncovered zero-day vulnerabilities in enterprise smart hardware and consumer connected devices. At Sukshield, he leads the hands-on offensive training modules, translating elite penetration testing methodologies into step-by-step curriculum for developers and beginners.
When not conducting vulnerability research, he works directly with early-stage tech founders to harden attack surfaces before product launch, ensuring robust cryptographic key management and impenetrable API endpoints.
Core Specializations
Industry Credentials
Work History & Research Appointments
Co-Founder & Lead Security Researcher
Directing offensive security curriculum, developing specialized Android/IoT vulnerability labs, and providing bespoke penetration testing for technology startups.
Senior Mobile & IoT Security Analyst
Conducted static and dynamic reverse-engineering across 80+ Android/iOS banking and healthcare apps. Spearheaded hardware teardowns of medical IoT devices.
Vulnerability Assessment & Pen Testing Engineer
Executed network infrastructure audits, web application penetration tests, and authored actionable executive remediation reports for fintech clients.
Automated Android Intent Fuzzing Engine
Engineered an open-source Python daemon that dynamically fuzzes exported IPC components and broadcast receivers in production APKs.
Smart Thermostat Firmware Attack Vector Audit
Extracted SPI flash memory chips to reverse-engineer bootloader cryptographic signatures and intercepted unencrypted telemetry via UART pins.
Zero-Trust MDM Hardening Blueprint
Authored complete architectural blueprint for hardening Android enterprise dedicated kiosk tablets against jailbreaking and side-loading.
