About the Founder

Built by a Practitioner. Not a Product Company.

PhalanxCyber is a new model for security innovation — an entire platform engineered by a single cybersecurity strategist with 25+ years of hands-on experience. A deliberate demonstration of what becomes possible when decades of practitioner expertise converge with AI-augmented development.

Krishnendu De

Krishnendu De

Cyber Enthusiast and Evangelist · PhalanxCyberPhalanxCyber is an Open Source Not-for-Profit cyber security community Initiative to promote innovation and collaboration
IIT Kharagpur · 25+ Years in Cybersecurity · Kolkata, India

Krishnendu De, a Cyber Enthusiast and Evangelist at PhalanxCyber, is an accomplished cybersecurity leader with over 25 years of experience across security engineering, threat intelligence, product development, and enterprise security strategy. He is the sole architect and creator behind the Phalanx Cyber platform — a comprehensive portfolio of 54 open-source security repositories on GitHub, spanning every layer of the enterprise stack: Application Security, Cloud Infrastructure, SaaS platforms, ERP Security, Threat Intelligence and Hunting, Network and Security Appliances, and the security of OT/ICS environments and equipment like PLCs, RTUs and FRTUs.

His career spans senior roles across India, the United Kingdom, the Netherlands, and international markets — building and leading security programs for complex, regulated enterprises. Krishnendu brings a rare intersection of deep technical capability, cyber product vision, and fluent boardroom risk communication — equally at home writing a SAST scanner from first principles, designing a zero-trust architecture, or presenting a risk-quantified business case to a board of directors.

He holds a master's degree from the Indian Institute of Technology, Kharagpur — one of Asia's most selective engineering institutions — along with the Offensive Security Certified Professional (OSCP) and Offensive Security Experienced Penetration Tester (OSEP) from OffSec, and CISSP from ISC2, anchoring his practitioner-first approach in validated adversarial expertise.

Expertise

The Three Lenses

What makes Krishnendu's approach distinctive is the ability to operate across three domains rarely combined in a single practitioner: deep engineering, product thinking, and business strategy.

Engineering Depth

Not a security manager who delegates to engineers — a hands-on builder who writes production security tools from scratch. Every scanner in the platform is personally architected and coded, across Python, Bash, PowerShell and JavaScript, and protocols from SSH/SNMP to OData/REST to the PAN-OS XML API.

  • 54 open-source security repositories on GitHub
  • 120,000+ lines of production security tooling
  • Scanners for 23+ platforms and technologies
  • Custom SAST engines, API scanners, CIS auditors

Product Thinking

Every scanner is designed as a complete product, not a proof-of-concept — consistent CLIs, structured JSON/HTML reporting, severity-based CI/CD exit codes, dark-themed interactive dashboards, and thorough documentation. A product-management mindset applied to security tooling.

  • Unified Finding schema across all tools
  • 3-phase architecture: Collect, Analyze, Report
  • Multi-format output: JSON, HTML, CSV, SARIF
  • CI/CD native with exit-code conventions

Business Strategy

Security tools without business context are noise generators. Every finding maps to business risk, a compliance framework, and remediation cost — so the platform produces board-ready output, not just technical scan results, letting CISOs communicate risk in the language of the business.

  • 20+ compliance frameworks mapped (CIS, NIST, ISO, PCI)
  • Open-source security strategy and implementation
  • Risk-based prioritization with CVSS, EPSS, CISA KEV
  • Executive-ready reporting and posture scoring
Open-Source Portfolio

54 Repositories. One Vision.

Every repository on GitHub is personally built — from architecture design to the last line of code — together forming one of the most comprehensive open-source enterprise security platforms available today.

0
GitHub Repositories
0
Security Rules
0
CVE Database
0
Platforms Covered
0
Compliance Frameworks
0
LinkedIn Followers
Browse all 54 tools
Thought Leadership

Published Research & Writing

Krishnendu regularly publishes technical research and strategic analysis on LinkedIn — red teaming, threat intelligence, AI in security, and enterprise defense.

Research

OT Vulnerability Management: A Risk-Based Approach

A framework for prioritizing remediation in operational-technology environments where patching is constrained by uptime and safety.

Case Study

Live Red Teaming Assignment: Real-World Engagement

Documented methodology and findings from a production red-team engagement — attack chain from initial access through lateral movement to domain dominance.

Threat Intel

Cobalt Strike & BlackSuit Ransomware: Technical Analysis

Deep-dive into a ransomware operation: C2 infrastructure, initial-access vectors, and defensive detection strategies for SOC teams.

AI + Security

Agentic AI-Based Red Teaming: Pentest Copilot

How agentic AI systems can augment penetration testing — automating reconnaissance, vulnerability discovery, and exploit-chain construction.

Cloud

Penetration Testing in Kubernetes Clusters

A methodology for attacking Kubernetes — RBAC exploitation, container escapes, service-account abuse, and secrets exfiltration.

Identity

ESC8 Attack: Exploiting ADCS for Domain Dominance

AD Certificate Services exploitation — how misconfigured certificate templates enable privilege escalation to domain administrator.

Read all articles on LinkedIn →
Credentials

Education & Certifications

Education

Indian Institute of Technology, Kharagpur

India's first and most prestigious IIT (est. 1951), consistently ranked among Asia's top engineering institutions. A rigorous foundation for first-principles thinking in security architecture, algorithm design, and systems engineering.

ISC2 · Since 2008

CISSP — Certified Information Systems Security Professional

The world's premier cybersecurity certification, held since 2008, validating mastery across all eight security domains. An ISC2 member for over 17 years.

Offensive Security

OSCP — Offensive Security Certified Professional

The industry's gold-standard penetration-testing certification from OffSec — hands-on exploitation under exam conditions. The offensive skillset that informs how every detection rule is written.

Offensive Security · Advanced

OSEP — Offensive Security Experienced Penetration Tester

OffSec's advanced evasion and exploit-development certification — crafting custom payloads, bypassing antivirus and enterprise defenses, and chaining sophisticated techniques against hardened environments. The offensive depth behind PhalanxCyber's detection engineering.

Cloud

AWS Certified Solutions Architect

Validates expertise in designing distributed systems on AWS — grounding the cloud scanners' detection logic in hands-on architectural knowledge of why a misconfiguration creates real risk.

Expertise

25+ Years of Practitioner Experience

The most important credential isn't a certificate — it's two-and-a-half decades of defending real enterprises: penetration testing, SOC operations, incident response, security architecture, red teaming, and board-level risk communication.

Additional Certifications & Credentials

Microsoft Identity & Access AdministratorEntra ID, Conditional Access, PIM, App Registrations
Google Cloud Platform (GCP) CertifiedCloud architecture, security, and infrastructure on GCP
Certified Kubernetes Administrator (CKA)Cluster operations, networking, security, and workloads
Splunk CertifiedSIEM administration, SPL development, detection engineering
CyberArk CertifiedPrivileged Access Management, vault architecture, secrets
Contact

Start the Conversation

If you'd like to connect, drop me an email and I'll try to respond. We can always set up a meeting to discuss further.

Write me an email
LinkedIn GitHub Email