I build local AI systems, MCP agents, security scanners, and SOC automation tools that help security professionals investigate, test, and defend systems more efficiently.
I'm a cybersecurity practitioner with experience across offensive security, defensive operations, network infrastructure, and security automation. My work combines a purple-team mindset with practical engineering: understand how attacks work, turn that knowledge into detections and controls, and automate repeatable security workflows.
- 🔴 Web application, API, network, and AI/LLM security testing
- 🛡️ SOC operations, SIEM engineering, threat hunting, and incident response
- 🤖 Local AI models, Model Context Protocol (MCP), and tool orchestration
- 🔍 Digital forensics, malware analysis, and reverse-engineering workflows
- 🧰 Python, Bash, PowerShell, Docker, Linux, and security-tool development
- 📡 Network, telecommunications, Active Directory, and infrastructure security
Mission: Find vulnerabilities, strengthen defenses, and build practical tools for security teams.
An open-source, AI-assisted cybersecurity automation platform that connects MCP-compatible AI clients to a controlled security-tool backend.
Highlights
- Two-process architecture: a FastMCP bridge and a Flask execution backend
- Integrates 150+ security tools for authorized assessment workflows
- Provides reusable workflows for reconnaissance, web and API testing, vulnerability validation, reporting, and defensive analysis
- Designed for MCP clients such as Claude Desktop, Cursor, Roo Code, and compatible development environments
- Supports configurable server host, port, tool allowlists, timeouts, and operator-controlled execution
Built with: Python · FastMCP · Flask · REST APIs · JSON · Security CLI tools
A local-first cybersecurity assistant built for Ollama and designed to support the PayloadPilot ecosystem. It focuses on private, on-device analysis and structured assistance for authorized security research.
Core capabilities
- Red-team planning and adversary-simulation support in authorized environments
- VAPT methodology, web/API assessment guidance, and security reporting
- Reverse engineering, malware triage, and binary-analysis assistance
- SOC investigation, SIEM queries, detection engineering, and threat hunting
- DFIR playbooks, incident-response scenarios, and cyber-range training exercises
- MCP-assisted tool selection and workflow orchestration through PayloadPilot
Built with: Ollama · Local LLMs · Prompt Engineering · MCP · Python · Cybersecurity Knowledge Workflows
The model and its connected tools are intended for systems you own or have explicit permission to assess.
An independent Python-based web and API security scanner for structured, repeatable vulnerability assessment.
Highlights
- Reconnaissance, crawling, endpoint discovery, and client-side source analysis
- Authentication-aware testing for websites and APIs
- Checks covering common OWASP risk categories and input-validation weaknesses
- Optional integrations with Nmap, Nuclei, ffuf, Playwright, and other testing utilities
- Report generation in TXT, JSON, Markdown, and HTML formats
- Modular CLI workflow suitable for labs, learning, and authorized assessments
Built with: Python · HTTP · Web Crawling · API Testing · Nmap · Nuclei · Playwright
This is an independent community project and is not an official OWASP Foundation product.
| Project | What it demonstrates |
|---|---|
| SOC Lab | Detection engineering, threat hunting, investigation workflows, and security monitoring. |
| SOC Home Lab | Hands-on SOC architecture and integrations across SIEM, threat intelligence, case management, and automation. |
| Area | Technologies and methods |
|---|---|
| Offensive Security | Web/API VAPT, OWASP Top 10, Burp Suite, Nmap, Nuclei, Metasploit, SQLmap, ffuf, responsible disclosure |
| Defensive Security | Wazuh, Suricata, Wireshark, MISP, TheHive, Cortex, Shuffle, YARA, Sigma, MITRE ATT&CK |
| AI & Automation | Ollama, local LLMs, MCP, prompt engineering, Python automation, REST APIs, AI security testing |
| Infrastructure | Linux, Windows, Active Directory, Docker, Kubernetes, Terraform, Ansible, VLANs, routing and switching |
| Development | Python, Bash, PowerShell, JSON, Git, GitHub, Flask, CLI application design |
- Improving PayloadPilot's MCP workflows and safe tool-negotiation process
- Building practical local-AI workflows for red teams, blue teams, and SOC analysts
- Expanding OWASP Scanner coverage, reporting, and authenticated testing
- Researching prompt injection, model behavior, LLM security, and AI-assisted detection engineering
- Publishing project guides and cybersecurity write-ups on Medium
Follow my latest open-source development, commits, releases, and contributions directly on GitHub:
- Contribution activity: View my GitHub overview
- Repositories: Browse all public projects
- PayloadPilot development: payloadpilot-AI commits
- OWASP Scanner development: OWASP-Scanner commits
Direct GitHub links are used here instead of third-party statistics cards, ensuring this section remains available even when external profile-card services experience outages or rate limits.
I'm open to collaborating on cybersecurity automation, AI security, SOC engineering, open-source tools, and authorized security research.
- GitHub: github.com/BaskaranElilan
- LinkedIn: linkedin.com/in/elilanbaskaran
- Medium: medium.com/@ezhilan094
- Email: baskaranezhilan094@gmail.com
The security projects on this profile are intended for education, defensive research, cyber ranges, and testing performed with explicit authorization. Users are responsible for following applicable laws, program rules, and defined assessment scope.
Build. Test. Detect. Improve.