Skip to content
View NucleiAv's full-sized avatar

Block or report NucleiAv

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NucleiAv/README.md

hi, i'm newklei

just a cybersecurity geek and a grad at nyu. i am currently an ambassador and contributor @wazuh; and a network audio engineer (@hsrn)

Portfolio LinkedIn Email GitHub Security Advisories Resume


"Understand the break, then build the tooling that closes it."

I'm a cybersecurity engineer and researcher working across detection engineering, threat intelligence, GRC automation, and cloud/network security. I'm currently an MS Cybersecurity candidate at NYU Tandon (4.0 GPA), a Wazuh Community Ambassador, and previously spent two years as a Threat Research / GRC Engineer at Safe Security.

My work spans open-source detection engineering (Wazuh, Suricata, Snort, Zeek rulesets that ship upstream), vulnerability research (4 CVEs, 17+ disclosures), GRC automation that cut manual review time by 98%, and applied LLM security research published at Springer LNCS.

Full picture → projects, research, disclosures & certifications at anmol-vats-portfolio.vercel.app


Highlights

4 CVEs assigned 17+ vulnerabilities disclosed
RITSEC CTF 2026, Global Rank 14, US Rank 1 98% reduction in GRC ops time (5 weeks to 15 hrs)
19 Wazuh integrations modernized Published @ Springer LNCS METAVERSE 2026

Experience

  • Community Ambassador & Contributor, Wazuh (Jun 2026, present)
  • Threat Research / GRC Engineer, Safe Security (May 2023, Jul 2025)
  • Course Assistant, Network Security, NYU Tandon (Prof. Damon McCoy)
  • VP, Cybersecurity Club, NYU Tandon
  • Member, OSIRIS Lab & High Speed Research Network (HSRN)

Tech stack

Languages

Python C C++ C# JavaScript Solidity Bash PowerShell SQL

Detection engineering & SIEM/SOC

Wazuh Splunk QRadar Suricata Snort Zeek Sigma YARA Wireshark

GRC & threat intelligence

MITRE ATT&CK STIX 2.1 OWASP FAIR NIST 800-53 ISO 27001 SOC 2

Cloud & infrastructure

AWS Wiz Docker Kubernetes Git

Web & ML tooling

Flask Django FastAPI Bootstrap Tree-sitter

Certifications · AWS Certified Solutions Architect - Associate · CompTIA Security+ · ISO 27001 · PEH · CNSP · MITRE ATT&CK Defender

Focus areas · detection engineering · threat intelligence · GRC & vendor risk automation · cloud & network security · AI/LLM security · vulnerability research


Featured projects

caddy-detection-rules · Wazuh · Suricata · Snort · Zeek 29 MITRE ATT&CK-mapped detection rules for the Caddy web server across four engines, merged upstream into Wazuh v4.14.6 and v5.0.0, validated at a 26/26 unit test pass rate.

snipe · Tree-sitter · FastAPI · VSCode API · Claude API Real-time SAST VSCode extension that flags insecure patterns and cross-file vulnerabilities on unsaved code in under 100ms, using AST analysis and LLM review.

Serverless Cloud Threat Detection & Alerting · AWS Lambda · CloudTrail · CloudWatch · SNS Serverless pipeline detecting CloudTrail tampering, unauthorized API calls, failed logins, and security group changes, with severity-classified Slack/email alerting.

i4cu - Deepfake Detection · TypeScript · Python · Cloudflare Workers Multimodal deepfake detection across image, video, and audio, tested on 300+ media files with 80% accuracy in initial benchmarking.

See all projects → anmol-vats-portfolio.vercel.app/recruiter/projects.html · All repos → github.com/NucleiAv?tab=repositories


Research & disclosures

Securing Metaverse Blockchain Infrastructure. LLM-Assisted Vulnerability Detection on Solana and Algorand Smart Contracts Springer LNCS, METAVERSE 2026 · DOI 10.1007/978-3-032-36773-0_3 216 experiments evaluating zero-shot, CoT, and RAG prompting strategies for automated smart contract vulnerability detection using GPT-4o, Claude 3.5 Sonnet, and Llama 3.3.

Vulnerability disclosures · CVE-2026-36045 (CVSS 8.8, picoclaw) · CVE-2026-36044 (CVSS 8.8, Pensar AI apex) · CVE-2026-31886 (CVSS 9.1, dagu) · CVE-2026-30851 (CVSS 8.1, Caddy), plus 13 additional reported vulnerabilities across open-source and enterprise bug bounty programs.


Open to full-time detection engineering, threat intelligence, GRC, cloud sec and network sec roles.

anmol-vats-portfolio.vercel.app · LinkedIn · anmol.vats.cyber@gmail.com

Pinned Loading

  1. caddy-detection-rules caddy-detection-rules Public

    Multi-engine detection ruleset for the Caddy web server with 29 attack-mapped rules for Wazuh, Suricata, Snort 3, and Zeek, covering everything from path traversal to Log4Shell, with pcap-tested pr…

    Zeek 2

  2. i4cu i4cu Public

    A comprehensive deepfake detection solution with both CLI and Web interfaces.

    Python 1

  3. llm-audit-nonevm llm-audit-nonevm Public

    TeX 1

  4. snipe snipe Public

    Real-time code analysis that detects cross-file semantic errors, type inconsistencies, array bound violations, and function signature drift while you type, before files are saved, without external …

    Python 1 1