OT Vulnerability Management: A Risk-Based Approach
A framework for prioritizing remediation in operational-technology environments where patching is constrained by uptime and safety.
PhalanxCyber is a new model for security innovation — an entire platform engineered by a single cybersecurity strategist with 25+ years of hands-on experience. A deliberate demonstration of what becomes possible when decades of practitioner expertise converge with AI-augmented development.

Krishnendu De, a Cyber Enthusiast and Evangelist at PhalanxCyber, is an accomplished cybersecurity leader with over 25 years of experience across security engineering, threat intelligence, product development, and enterprise security strategy. He is the sole architect and creator behind the Phalanx Cyber platform — a comprehensive portfolio of 54 open-source security repositories on GitHub, spanning every layer of the enterprise stack: Application Security, Cloud Infrastructure, SaaS platforms, ERP Security, Threat Intelligence and Hunting, Network and Security Appliances, and the security of OT/ICS environments and equipment like PLCs, RTUs and FRTUs.
His career spans senior roles across India, the United Kingdom, the Netherlands, and international markets — building and leading security programs for complex, regulated enterprises. Krishnendu brings a rare intersection of deep technical capability, cyber product vision, and fluent boardroom risk communication — equally at home writing a SAST scanner from first principles, designing a zero-trust architecture, or presenting a risk-quantified business case to a board of directors.
He holds a master's degree from the Indian Institute of Technology, Kharagpur — one of Asia's most selective engineering institutions — along with the Offensive Security Certified Professional (OSCP) and Offensive Security Experienced Penetration Tester (OSEP) from OffSec, and CISSP from ISC2, anchoring his practitioner-first approach in validated adversarial expertise.
What makes Krishnendu's approach distinctive is the ability to operate across three domains rarely combined in a single practitioner: deep engineering, product thinking, and business strategy.
Not a security manager who delegates to engineers — a hands-on builder who writes production security tools from scratch. Every scanner in the platform is personally architected and coded, across Python, Bash, PowerShell and JavaScript, and protocols from SSH/SNMP to OData/REST to the PAN-OS XML API.
Every scanner is designed as a complete product, not a proof-of-concept — consistent CLIs, structured JSON/HTML reporting, severity-based CI/CD exit codes, dark-themed interactive dashboards, and thorough documentation. A product-management mindset applied to security tooling.
Security tools without business context are noise generators. Every finding maps to business risk, a compliance framework, and remediation cost — so the platform produces board-ready output, not just technical scan results, letting CISOs communicate risk in the language of the business.
Every repository on GitHub is personally built — from architecture design to the last line of code — together forming one of the most comprehensive open-source enterprise security platforms available today.
Krishnendu regularly publishes technical research and strategic analysis on LinkedIn — red teaming, threat intelligence, AI in security, and enterprise defense.
A framework for prioritizing remediation in operational-technology environments where patching is constrained by uptime and safety.
Documented methodology and findings from a production red-team engagement — attack chain from initial access through lateral movement to domain dominance.
Deep-dive into a ransomware operation: C2 infrastructure, initial-access vectors, and defensive detection strategies for SOC teams.
How agentic AI systems can augment penetration testing — automating reconnaissance, vulnerability discovery, and exploit-chain construction.
A methodology for attacking Kubernetes — RBAC exploitation, container escapes, service-account abuse, and secrets exfiltration.
AD Certificate Services exploitation — how misconfigured certificate templates enable privilege escalation to domain administrator.
India's first and most prestigious IIT (est. 1951), consistently ranked among Asia's top engineering institutions. A rigorous foundation for first-principles thinking in security architecture, algorithm design, and systems engineering.
The world's premier cybersecurity certification, held since 2008, validating mastery across all eight security domains. An ISC2 member for over 17 years.
The industry's gold-standard penetration-testing certification from OffSec — hands-on exploitation under exam conditions. The offensive skillset that informs how every detection rule is written.
OffSec's advanced evasion and exploit-development certification — crafting custom payloads, bypassing antivirus and enterprise defenses, and chaining sophisticated techniques against hardened environments. The offensive depth behind PhalanxCyber's detection engineering.
Validates expertise in designing distributed systems on AWS — grounding the cloud scanners' detection logic in hands-on architectural knowledge of why a misconfiguration creates real risk.
The most important credential isn't a certificate — it's two-and-a-half decades of defending real enterprises: penetration testing, SOC operations, incident response, security architecture, red teaming, and board-level risk communication.
If you'd like to connect, drop me an email and I'll try to respond. We can always set up a meeting to discuss further.