RETURN TO FOUNDERS DIRECTORY
STATUS: ACTIVE_RESEARCH
FOUNDER_01
// PHOTO_PLACEHOLDER
VERIFIED RESEARCHERIndia / Global Remote

Kshitija Mhatre (OffSec Lead)

Co-Founder & Lead Security Researcher

Offensive Security Engineer specializing in Android VAPT, IoT Hardware Teardowns & Firmware Exploitation.

// SEC_DOSSIER.01EXECUTIVE_BACKGROUND

Background & Security Philosophy

Kshitija is the co-founder and offensive security lead at Sukshield. With over half a decade in adversarial security testing, he focuses on dissecting Android mobile applications, IoT firmware binaries, and embedded hardware communication buses.

His research has uncovered zero-day vulnerabilities in enterprise smart hardware and consumer connected devices. At Sukshield, he leads the hands-on offensive training modules, translating elite penetration testing methodologies into step-by-step curriculum for developers and beginners.

When not conducting vulnerability research, he works directly with early-stage tech founders to harden attack surfaces before product launch, ensuring robust cryptographic key management and impenetrable API endpoints.

// COMPETENCY.02TECHNICAL_DOMAINS

Core Specializations

Android Mobile VAPT (Frida, Drozer, MobSF)
IoT Firmware Reversing (Ghidra, Binwalk)
UART / JTAG Hardware Interception
API Security & Broken Access Control
Network Penetration Testing (Burp Suite Pro)
Secure Coding Guidelines & Countermeasures
// CREDENTIALS.03CERTIFIED_ATTESTATIONS

Industry Credentials

OffSec2022
Offensive Security Certified Professional (OSCP)
ID: OS-102948
EC-Council2021
Certified Ethical Hacker (CEH v12)
ID: ECC-748392
INE Security2020
eLearnSecurity Mobile Application Penetration Tester (eMAPT)
ID: INE-394821
// TIMELINE.04PROFESSIONAL_RECORD

Work History & Research Appointments

2023 — PresentSukshield Technologies

Co-Founder & Lead Security Researcher

Directing offensive security curriculum, developing specialized Android/IoT vulnerability labs, and providing bespoke penetration testing for technology startups.

2021 — 2023CyberDefense Labs

Senior Mobile & IoT Security Analyst

Conducted static and dynamic reverse-engineering across 80+ Android/iOS banking and healthcare apps. Spearheaded hardware teardowns of medical IoT devices.

2019 — 2021InfoSec Solutions Inc.

Vulnerability Assessment & Pen Testing Engineer

Executed network infrastructure audits, web application penetration tests, and authored actionable executive remediation reports for fintech clients.

// HIGHLIGHTS.05DISCLOSED_RESEARCH_&_PROJECTS
Mobile AppSec Tooling

Automated Android Intent Fuzzing Engine

Engineered an open-source Python daemon that dynamically fuzzes exported IPC components and broadcast receivers in production APKs.

Impact: Identified privilege escalation vulnerabilities in 12 enterprise apps.
PythonFridaADBAOSP
IoT Hardware Teardown

Smart Thermostat Firmware Attack Vector Audit

Extracted SPI flash memory chips to reverse-engineer bootloader cryptographic signatures and intercepted unencrypted telemetry via UART pins.

Impact: Responsible disclosure acknowledged by manufacturer with firmware patch CVE-2023-XXXX.
GhidraLogic AnalyzerBus PirateUART
Corporate Defense

Zero-Trust MDM Hardening Blueprint

Authored complete architectural blueprint for hardening Android enterprise dedicated kiosk tablets against jailbreaking and side-loading.

Impact: Adopted by 15+ logistics startups across Asia and Europe.
Android Enterprise APIKnox SDKMDM