bhavya@auce ~ %

// B.Tech CSE · Andhra University · Class of 2028

Bhavya
Annabattula

Software Development / Cybersecurity

I build things — and then I try to break them. CS undergrad focused on secure systems, from AWS infrastructure to SOC-style threat triage, with hands-on VAPT work from real internship engagements.

// 02 — about

Who I Am

I'm a 3rd-year B.Tech Computer Science student at Andhra University College of Engineering, Visakhapatnam, specializing in cybersecurity. I'm building my path into the field independently — no campus placement cell, just consistent hands-on work: home-lab exploitation, real internship VAPT assignments, and full-stack builds that force me to understand systems from the inside out.

My focus right now is SOC Analyst and cybersecurity analyst roles — triaging alerts, mapping attacker behavior to MITRE ATT&CK, and understanding both sides of the fence, offense and defense.

0.00 CGPA
0 Projects Shipped
0 VAPT Reports
0 Graduating

// 03 — skills

Toolkit

Languages

  • Java
  • Python
  • JavaScript
  • SQL

Web & Cloud

  • HTML/CSS
  • Flask
  • AWS (VPC, EC2)
  • Git/GitHub

Security Tools

  • Burp Suite
  • Nmap
  • Wireshark
  • Metasploit
  • SQLMap
  • Maltego
  • Kali Linux

Security Domains

  • Web App VAPT
  • Network Recon
  • OSINT
  • SOC / Threat Triage
  • MITRE ATT&CK

Data & ML

  • Pandas
  • NumPy
  • Scikit-learn
  • Matplotlib

Fundamentals

  • DSA
  • Computer Networks
  • OS
  • System Design Basics
HackerRank 4★ Java HackerRank 3★ Python IBM Cloud Badge Google Prompt Engineering Kaggle Python Coder

// 04 — projects

Things I've Built

A mix of full-stack, cloud, and applied ML — each one solving a real problem, not a tutorial clone.

PRJ-01 Featured

SentinelAI — SOC Copilot

An AI-powered Security Operations assistant. Runs four sequential LLM calls (Groq / LLaMA 3-70B) to triage alerts, map attacker TTPs to MITRE ATT&CK, recommend response actions, and auto-draft incident reports. Built for a hackathon, deployed live.

  • Flask
  • Groq API
  • Tailwind
  • MITRE ATT&CK
PRJ-02 ML

Phishing URL Detector

Logistic Regression classifier trained on 109,870+ URLs to separate phishing from legitimate links — 97% accuracy. Deployed as a live Flask REST API on Render for real-time prediction.

  • Python
  • Scikit-learn
  • Flask
  • Render
PRJ-03 Security Tool

USB Physical Security Tool

Built during my internship. A Python/Tkinter GUI that toggles USB storage access via the Windows registry (HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR). Auth is PBKDF2-HMAC-SHA256 with 260k iterations and constant-time comparison, with lockout after failed attempts and full audit logging. Packaged standalone with PyInstaller.

  • Python
  • Tkinter
  • PBKDF2-HMAC
  • PyInstaller
PRJ-04 Cloud

AWS VPC Networking

Designed a custom AWS VPC from scratch — public/private subnets, route tables, an internet gateway, a load balancer, and EC2 instances — following AWS best practices for secure network segmentation.

  • AWS
  • VPC
  • EC2
  • Python
PRJ-05 Data

Retail Sales Analysis

SQL (MySQL) + Excel analysis of ~9,700 retail transactions from the Kaggle Superstore dataset — regional sales breakdowns, top-performing products, monthly trends, and category-level profit analysis.

  • MySQL
  • Excel
  • Data Analysis
PRJ-06 Data

COVID-19 Data Pipeline

A Python data-analysis pipeline built with Pandas, Matplotlib, and OOP design. Cleans and explores a global COVID-19 Kaggle dataset, then visualizes trends and regional insights.

  • Python
  • Pandas
  • Matplotlib
PRJ-07 Web

Cybersecurity Learning Tracker

A gamified, standalone learning roadmap tracker with a dark hacker/terminal aesthetic — XP points, badges, and progress persistence via localStorage. Built to keep my own daily learning consistent.

  • HTML
  • CSS
  • JavaScript
PRJ-08 Web

This Portfolio

Fully responsive, animation-driven personal site — hand-built with a terminal-boot hero, scroll reveals, and a security-report-styled project grid. Deployed on GitHub Pages.

  • HTML
  • CSS
  • JavaScript

// 05 — security

Offense-Minded. Defense-Focused.

Real exploitation, real reports. Not just theory.

Home Lab — VAPT Practice

A self-built VirtualBox lab (Kali Linux, Metasploitable 2, Windows 7) for hands-on offensive practice, documented with full write-ups.

DONE Lab 02 — Metasploitable vsftpd 2.3.4 backdoor exploitation (CVE-2011-2523) — real command execution + screenshots
WIP Lab 03 — Windows 7 EternalBlue / MS17-010
DONE Windows Event Log analysis — identified Event IDs 4624, 4672, 4798
View Repo →

Internship VAPT Reports

Ethical hacking / web application VAPT internship at Supraja Technologies (May–Jul 2026). Completed assignment reports covering:

LFI/RFI XSS IDOR iFrame Injection SQL Injection OSINT Recon

Certs & Roadmap

Google Prompt EngineeringCompleted
Supraja Technologies InternshipCompleted · 2026
CompTIA Security+In Progress
eJPT (eLearnSecurity)Planned
CEH (EC-Council)Planned

// 06 — experience

Where I've Worked

May – Jul 2026

Ethical Hacking & VAPT Intern

Supraja Technologies

Completed hands-on web application VAPT assignments — LFI/RFI, XSS, IDOR, iframe injection, SQL injection, and OSINT reconnaissance using Maltego and HTTrack. Built and shipped a USB Physical Security Tool as part of the engagement.

2026

APSSDC Naipunyam AWS Intern

Government-backed program

Enrolled in a government-backed AWS internship carrying academic credit — hands-on cloud infrastructure work building on VPC and EC2 fundamentals.

2025 – Present

Core Member

Edumoon Coding Club, Andhra University

Active member contributing to a student coding community at Andhra University.

Ongoing

Independent Cybersecurity Learner

Self-directed

Daily hands-on learning — home-lab exploitation, TryHackMe, and applied projects — building toward SOC Analyst readiness without a formal placement pipeline.

// 07 — contact

Let's Connect

Open to SOC Analyst, cybersecurity analyst, and software engineering internship/entry-level opportunities.