security engineer · bengaluru, india

t0x1n

Sumukh Chitloor

I break things at the kernel level, secure them at the cloud layer, and write about what actually happened in between.

eBPF cloud security kernel research aws ai security
scroll

about

the person behind the handle

Security engineer at CRED by day, kernel gremlin by night. Day job is cloud security across AWS, DLP, Kubernetes, the kind of work that sounds boring until something breaks in prod at 2am and suddenly everyone's very interested.

24, based in Bengaluru. I play guitar terribly, cricket less terribly, and have a PS5 that sees more Netflix than games at this point. Perpetually planning a trip I haven't booked yet.

This site is where I write things down before I forget them. If it ended up here, it either broke something or took long enough to figure out that it deserved a post.

t0x1n — fish

writing

things i've written down


research

active & past projects

active
Nogitsune
eBPF-based process hiding and kernel evasion rootkit. Explores kprobe hooking, map-based PID filtering, and verifier bypass techniques.
eBPF Go Linux kernel CO-RE/BTF
published
Firecracker Runtime Fingerprinting
Reverse engineered a production sandbox binary — extracted protobuf schemas from a Go binary, surveyed /proc and /sys emulation quirks, confirmed Firecracker runtime via dmesg artifacts. Responsible disclosure filed.
Go reverse engineering protobuf Firecracker gVisor