Kailash Parshad β Ethical Hacker Β· Penetration Tester Β· Security Tool Builder Β· YouTube Educator
Greetings! I'm Kailash Parshad β a dedicated Ethical Hacker, Penetration Tester and ardent Cybersecurity Enthusiast. I build security tools that tell the truth: hardware and software that let an ordinary person check whether the thing in their pocket, their car park or their wall is actually safe. Then I give them away, and teach how they work on YouTube.
π Counter-surveillance Β· π‘ RF & hardware security Β· π‘οΈ Blue team tooling Β· π€ AI agent security Β· π Free education
Defence first, by love. Red team by necessity β to sharpen the defence.
- A tool that can't be honest about its limits is a liability. Every detector I ship says out loud what it cannot see. Nyx admits it's deaf to steady infrared. Janus admits a full-speed BadUSB is indistinguishable from a real flash drive. They never grade a device "safe".
- If it grades, it grades the truth. Bastion gives every 125 kHz badge an F β because not one of them actually authenticates. That verdict is the lesson.
- Consent is physical, never covert. No default credentials, no hidden modes, no silent capture. Offensive tooling is scope-gated and built for authorised labs only.
- Passive beats loud. Most of my radio work only listens. Pharos fences transmit at link time so the firmware cannot talk back.
| Project | What it does | |
|---|---|---|
| Specter | Sweeps for a hidden 13.56 MHz NFC reader buried in an ATM or card terminal β using nothing but the Flipper's own antenna. | |
| VMware Hidden Mode | 13 tiers of VMX patching plus guest cleanup, so malware stops noticing it's being watched in a lab. | |
| RollCall | Press your own key fob and prove the rolling code actually rolls. Graded A/B/C/F. | |
| GhostTag | Anti-stalking tracker hunter β tells you an AirTag has been following you, not merely that one exists. | |
| Nyx | Finds covert night-vision cameras by the infrared light they leak β and is honest about the ones it can't. | |
| Sibyl | Shazam for RF. Capture any Sub-GHz burst and find out what kind of device sent it. | |
| Sinon | AI agent pentest kit β a 54-probe corpus for prompt injection, tool abuse and over-permission, with canary-verified verdicts. | |
| Cracking OSCP | My full roadmap to OSCP β the companion to the PEN-200 series on the channel. |
29 apps, all open source, all written in C against the official SDK. Most of them only listen.
π Catch someone watching you β counter-surveillance (11)
| App | What it finds |
|---|---|
| Specter | A hidden 13.56 MHz reader inside an ATM, door panel or fuel-pump card slot |
| Nyx | Covert night-vision cameras, by the near-IR light they leak |
| GhostTag | An AirTag, Tile or SmartTag that has been following you |
| Vulpes | The transmitter itself β hot-and-cold hunt, then a body-shielded bearing rose |
| Skimscan | The two-dollar Bluetooth bridge inside a skimmed fuel pump or ATM |
| Argus | Deauth floods and evil-twin access points on your Wi-Fi |
| Bulwark | BLE popup-spam, using RF test mode on the onboard radio |
| Cerberus | Jamming, flooding and replay across the 433 / 868 / 915 MHz bands |
| Cardea | A relay attack on your keyless car β by listening for the key's reply |
| Meridian | GPS spoofing, via 11 integrity checks across 4 independent measurements |
| Janus | Whether a USB port charges or talks β and whether that "flash drive" is a keyboard |
π Hold a thing, get an honest grade (10)
| App | Grades | The uncomfortable truth it tells |
|---|---|---|
| Warden | 13.56 MHz access badges | Most office badges are a serial number in a costume |
| Bastion | 125 kHz badges | Every single one gets an F β none of them authenticate |
| Talos | iButton / Dallas 1-Wire keys | 41 families, and sequential serials you can guess |
| RollCall | Car fobs & garage remotes | Proves the code advances β or that it never did |
| Gatekeeper | NFC tag URLs | Leads with the registrable domain, because people read the wrong part |
| Moneta | Contactless bank cards | Exactly what your own card hands out, and what it doesn't |
| Faraday | Faraday bags & pouches | Real measured dB, not marketing |
| Odograph | Tyre pressure sensors | Your car has a licence plate you cannot cover |
| Pheme | POCSAG pagers | Hospitals still page patient details in the clear |
| Echo | Wi-Fi probe requests | Your phone shouts the names of every network you've saved |
π¬ Learn the radio, take it apart (8)
| App | What it's for |
|---|---|
| Sibyl | Identify what kind of device sent a Sub-GHz signal β Shazam for RF |
| Aurora | Live spectrum over a scrolling waterfall, on the internal CC1101 |
| Rosetta | Animated walkthroughs of Mifare Crypto1, OOK/PSK and 1-Wire, with live capture |
| Hermes | UART baud detector and console tap β measures the bit time, then verifies it |
| Gauntlet | An on-device CTF box with loadable challenge packs and a decoder toolkit |
| GlitchTrigger | Cycle-accurate GPIO pulses for fault-injection study on your own boards |
| Wraith | Controller for ESP32 Marauder boards β dual-band Wi-Fi, BLE, GPS and 433 MHz |
| Trident | One app, three radios: ESP32 + NRF24 + CC1101 on a 3-in-1 board |
ESP32, Pico and friends (9)
| Project | Board | What it does |
|---|---|---|
| Pharos | ESP32-S3 round AMOLED | Receive-only RF observatory β transmit is fenced at link time |
| Aegis | ESP32-S3-GEEK | Passive Wi-Fi/BLE blue-team airspace guardian |
| Dolos | ESP32-S3-GEEK | Aegis's red-team sibling β safety-gated USB-HID payload runner |
| Basanos | ESP32-S3 LCD 1.54" | A proving ground for the detectors above. Manual, single-target, RBAC-gated |
| Orthrus | M5Stack Cardputer-Adv | Handheld LoRaWAN security assessment β presence is proof, absence is not |
| NightWatchGuard | Raspberry Pi Pico | IoT security gateway with TLS |
| Kali Pi5 Image Builder | Raspberry Pi 5 | Automated custom Kali image builds |
| pico-sync | Pico / MicroPython | Copy files and folders over the serial port |
| ATtiny85 Flasher | ATtiny85 | Burn the bootloader using an Arduino as ISP |
Tools you run on a real machine (16)
| Project | What it does |
|---|---|
| VMware Hidden Mode | Defeat VM detection in a malware-analysis lab β Intel and Apple Silicon |
| DuckHound | Catch BadUSB / Rubber Ducky keystroke injection by its inhuman typing rhythm |
| Lares | Autonomous Windows hardening agent with an embedded local LLM β verify and auto-rollback, never freehand code |
| DeepSentinel | Deepfake detection and education β FFT, ELA, face geometry, SRM noise |
| MacRecon | macOS information gathering and security audit, identity redacted by default |
| WinRecon | The Windows counterpart β 7 collectors plus a security-findings pass |
| AirDriver | Wi-Fi adapter driver manager for Kali & Parrot β 1258 chipset IDs, sysfs-native detection |
| Charon | SFTP / FTPS client with copy-paste transfers and host keys checked before auth |
| Tessera | Install, configure and remove WireGuard, OpenVPN and Tailscale on any Linux server |
| ArtifactScope | Cross-platform digital forensics toolkit |
| Metadateditor | Universal metadata editor for OSINT and forensics |
| NmapAutomator | Menu-driven Nmap automation for OSCP / HTB workflows |
| Windows Security Enhancer | PowerShell hardening utility |
| DiskImager | Cross-platform disk imaging, cloning and flashing |
| archive-cracker | Multi-format archive password recovery β ZIP, RAR, 7Z, TAR |
| human-type | Types text the way a person does β drifting rhythm, per-key effort, real mistakes |
Securing the things that now write the code (5)
| Project | What it does |
|---|---|
| Sinon | AI agent pentest kit β 54 probes for prompt injection, tool abuse and over-permission. Skips are not passes |
| PurpleMCP | Purple-team lab for the Model Context Protocol β 23 attacks, 18 guardrails |
| Whetstone | A purple-team runtime where every attack must name the detection that should catch it β silence is the finding |
| Hermes Agent Console | Hire AI agents, give them jobs, watch them work. Zero dependencies, human-in-the-loop on anything that leaves the box |
| ClaudeForge | Installer, hardware benchmarker and model recommender for Claude Code |
Blue-team stacks, CTFs and coursework (10)
| Project | What it covers |
|---|---|
| Cracking OSCP | The full roadmap to OSCP, companion to the PEN-200 video series |
| PortSwigger Web Security Academy | Worked solutions and code walkthroughs |
| Sysmon β ELK | End-to-end SIEM pipeline from Windows endpoints |
| HELK on Docker | Hunting ELK deployment for container security |
| T-Pot + Elasticsearch | Honeypot telemetry, visualised |
| REMnux + Volatility | Malware dissection and memory forensics |
| Mercury General Hospital | A hospital-network CTF machine built in PHP and Docker |
| Slot Machine Analysis | Adversarial review of a backdoored gaming system |
| AID System Analysis | Threat modelling an artificial insulin delivery system |
| Smart Thermostat Security | Secure-by-design IoT build in Go |
βοΈ Offensive proofs-of-concept β authorised labs only
These exist to be studied and defended against. Run them only against systems you own or have written permission to test.
| Project | Scope |
|---|---|
| C2-Server | Educational command-and-control framework |
| Wifi-Killer | Host discovery, ARP MITM and per-device internet cut-off |
| ethical-keylogger | Keystroke / clipboard / screen capture for lab use |
| alexa-attack | ARP MITM and DoS against a smart speaker you own |
| parrot-bebop2-exploits | Two DoS PoCs against a Parrot Bebop 2 drone |
Mobile tooling and off-duty watchOS builds (11)
Android forensics & recovery
| Project | What it does |
|---|---|
| AndroidROMExtractor | Back up, extract and analyse Android ROM images |
| RootDroid | Rooting and bootloader toolkit β fastboot, BROM exploit, Magisk |
| AndroidUniversalRecovery | Dockerised unbricking via adb, TWRP and friends |
Apple Watch β because a wrist is a fun constraint
| App | What it is |
|---|---|
| WatchTube | Standalone, keyless YouTube client for watchOS β on-watch search and HLS playback |
| Cipher | iPhone + Watch cybersecurity course β red team, blue team, daily drills |
| Firewall | A packet-defence arcade. Block malware, pass the good traffic |
| Pulsar | Neon space arcade β orbit a star with the Digital Crown |
| Lumen | Lights Out puzzler, 40 levels across 4 worlds |
| NovaWing | Galaga-style shooter with Crown steering |
| TiltMaze | CoreMotion labyrinth β tilt to roll |
| DepthDiver | Arcade dive game for Apple Watch Ultra |
I teach ethical hacking and cybersecurity for free on HackProKP β OSCP / PEN-200 walkthroughs, hardware builds and protocol deep-dives.
Currently pursuing a specialization in Cyber Security, Ethical Hacking and Penetration Testing at Vellore Institute of Technology, I've honed skills in leadership, programming languages like Python and C, and effective communication. My educational journey has empowered me to bring a holistic approach to cybersecurity problem-solving.
I'm a firm believer in keeping life simple and meaningful. My primary goal is to succeed β not just for myself, but to honour the sacrifices my family made to support my dreams. As I strive for success, I'm driven by the desire to ensure their dreams come true too. In the end, I encourage everyone to chase their dreams, follow their hearts, and pursue happiness relentlessly. Success, in any field, is attainable when driven by passion and guided by dedication.
I firmly believe education is a birthright, and it should be accessible to all. With this conviction I launched HackProKP, where I'm committed to offering free education in ethical hacking and cybersecurity. It's my way of contributing to a safer digital world, and ensuring that knowledge knows no boundaries.
β¨ Arise, awake, and stop not till the goal is reached β¨



