Anmol Singh Yadav · Platform Security Engineer
Istudywheresystemsbreak.
I work at the layer most people forget exists — right up until it’s the reason something broke.
My work sits underneath the parts most teams look at directly: the kernel, the container boundary, the model’s execution sandbox. I study how those layers fail, then design controls that make failure hard to reach, hard to hide, and expensive to exploit.

Receipts, not adjectives
Platform Security
Runtime hardening and trust-boundary enforcement for production systems.
Cloud & Container Security
Kubernetes and container isolation, assessed and hardened at scale.
eBPF & Runtime Visibility
Kernel-level detection for privilege escalation and anomalous behavior.
LLM & AI Security
Execution isolation and guardrails for agentic and LLM-driven systems.
Conference Speaking
Talks on API and platform security for practitioner audiences.
The rest is filed under NDA. These are the parts I can actually show you.
Capabilities
Six problems. One recurring question: what shouldn’t be reachable?
Platform and Runtime Security
Hardening the layer applications run on top of — so a compromised process has as little to reach as possible.
Selected work
A few things that survived contact with production.
The one I still actively maintain
pwnspectrum
Threat intelligence that ranks what actually matters.
A cybersecurity intelligence and prioritization system. It aggregates public threat feeds, ranks disclosures by real-world impact, and generates contextual summaries so the signal doesn’t drown in volume.
Most feeds hand you everything and call it intelligence. pwnspectrum combines feed aggregation, ranking, and contextual summarization so practitioners can act on what matters instead of triaging noise.
FaviCreep
Offensive reconnaissance for shadow assets and exposed infrastructure.
AWS Key Hunter
Secret exposure detection and monitoring at scale.
Writing
A few pieces I’d still stand behind.
Picked because I don’t wince rereading them.
Speaking
One talk so far. I’m told it went fine.
API Security in the Real World
A practitioner walk-through of how trust boundaries actually fail in API-driven systems — real vulnerability patterns, not theoretical ones.

About
What I actually do, in plain terms.
I’m a Platform Security Engineer. In practice, that means Linux, containers, and Kubernetes — and lately, figuring out what happens when you let an LLM run commands on your behalf.
Most of my work is about boundaries: what a process can reach, what a container can escape, what an agent can actually do versus what its prompt says it can do. eBPF and runtime tracing are usually how I find out the honest answer is “more than expected.”
I write in plain language on purpose. Security writing has a bad habit of sounding impressive instead of being useful, and I’d rather be the second one.
This page is the highlight reel. For the reasoning behind it, the writing section is a better use of your time than my LinkedIn headline.
Contact
Let’s talk about the parts that break.
Open to conversations on platform security, container and runtime isolation, eBPF, and AI security — as research, as talks, or as work.



