Sign in

Anant Shrivastava

@anantshri.info
310 followers 233 following 138 posts

Researcher | Trainer | Security Professional | Developer | Admin

PostsRepliesMedia
Anant Shrivastava @anantshri.info · 22/08/2026
Experiments with Intel Arc Pro B70 on Debian 13 kernel and firmware hurdles, SYCL and Vulkan setup, ASPM, custom fan control, xpu-smi, DKMS, and what it takes to make 32 GB VRAM usable. blog.anantshri.info/experiments-...
blog.anantshri.info
Experiments with Intel Arc Pro B70 on Debian 13 | Blog of Anant Shrivastava
Experiments with Intel Arc Pro B70 on Debian 13: kernel and firmware hurdles, SYCL and Vulkan setup, ASPM, custom fan control, xpu-smi, DKMS, and what it takes to make 32 GB VRAM usable.
000
Anant Shrivastava @anantshri.info · 25/07/2026
How is the heat profile with ds4 running these models. I am stuck with macbook which heats up to 100 degree's m4max. is it common, okey or bad?
000
Anant Shrivastava @anantshri.info · 16/05/2026
Watching Devil May Cry Season 2 @ Netflix It feels like they made a super awesome sound track then decided they needed an anime in between to present the sound track. www.youtube.com/playlist?lis...
youtube.com
Devil May Cry Season 2 Soundtrack - YouTube
000
Anant Shrivastava @anantshri.info · 13/05/2026
AI changes attacker iteration cost. AppSec cannot rely only on smarter vulnerability queues. Verification capacity, smaller stacks, attack surface reduction & safe remediation throughput now matter more New Article: AppSec in the New Security Cost Model cyfinoid.com/appsec-in-th...
cyfinoid.com
AppSec in the New Security Cost Model
AI changes AppSec economics. Learn why teams need smaller stacks, stronger verification, & safe remediation.
000
Anant Shrivastava @anantshri.info · 12/04/2026
Panel discussions in Conferences are a gamble sometimes they work mostly they dont. I have noted some things I have learned while being on all 4 sides of it (Audience, Organizer, Panelist, Moderator) blog.anantshri.info/security-panels/
blog.anantshri.info
Security panels are not broken. We just keep using them badly. | Blog of Anant Shrivastava
A practical field guide to making conference panels useful by setting clearer expectations for organizers, moderators, and panelists alike everywhere.
000
Anant Shrivastava @anantshri.info · 31/03/2026
reducetheattacksurface.com/manifesto/so...
reducetheattacksurface.com
Software Attack Surface Reduction | Attack Surface Reduction Manifesto
Implementing Attack Surface Reduction in software development and architecture decisions.
021
Anant Shrivastava @anantshri.info · 19/03/2026
AI should help us move from messy exploration to owned structure. Use models to find patterns, then encode what works, reduce dependence, and keep guesswork only where the world genuinely stays fuzzy. blog.anantshri.info/ai-should-help-…
Post Image
000
Anant Shrivastava @anantshri.info · 08/03/2026
I just need the world to pause for like 60 days; need time to catchup :D
000
Anant Shrivastava @anantshri.info · 28/02/2026
Open source is generosity, not a vendor SLA. Stop treating volunteers like suppliers. Declare your support level, offer paid tiers if you want, and make users fund or fork what they depend on.
blog.anantshri.info
Open Source, Unpaid Expectations
Open source is generosity, not a vendor SLA. Stop treating volunteers like suppliers. Declare your support level, offer paid tiers if you want, and make users fund or fork what they depend on.
010
Anant Shrivastava @anantshri.info · 27/02/2026
AI is making it cheap to replicate small SaaS workflows. Vendors sell suites, teams need slices, and bundling feels shakier at renewal time.
blog.anantshri.info
Vendors Sell Suites. Teams Need Slices. AI Made It Cheap.
AI is making it cheap to replicate small SaaS workflows. Vendors sell suites, teams need slices, and bundling feels shakier at renewal time.
010
Anant Shrivastava @anantshri.info · 09/02/2026
Hacking Archives of India – Website Revamp Update I am thrilled to announce a major update to Hacking Archives of India (HAI). My mission has always been to document the history and contributions of the Indian information security community. To better serve that mission, I have completely revamped…
blog.anantshri.info
Hacking Archives of India – Website Revamp Update
I am thrilled to announce a major update to Hacking Archives of India (HAI). My mission has always been to document the history and contributions of the Indian information security community. To better serve that mission, I have completely revamped both the looks and the internals of the website. Whether you are looking for specific tools, historical talks, or the journey of specific hackers, the new HAI is faster, cleaner, and now machine-readable. Here is a deep dive into the new features and changes you will find. 1. Visual Overhaul: Big Data, Big Cards…
000
Anant Shrivastava @anantshri.info · 28/01/2026
And badges are live on my website now : anantshri.info/badges/#:~:t... and github.com/anantshri/hu... <- theme has support for boinc badges also now.
anantshri.info
Anant Shrivastava
Specialise in Network, Web Application, Mobile & Linux Security. I prefer defence over offense. I stay @ India (+5.30 GMT). Email : anant{at}anantshri{dot}info
000
Anant Shrivastava @anantshri.info · 28/01/2026
I wanted a simple JSON API to fetch my BOINC stats and badges for my website. There was no clean endpoint, so I built one. boincstats.apps.anantshri.info It is still scraping, just done once on my side instead of everyone doing it badly. You get clean JSON, updated every 24 hours.
boincstats.apps.anantshri.info
BOINC Stats - Cross-Project Statistics
Unified BOINC statistics across all projects. Search by CPID or username to view your aggregated stats and badges.
000
Anant Shrivastava @anantshri.info · 10/01/2026
I have been building zero install security tools where the browser is the base. I wrote about the “why” here: blog.anantshri.info/making-secur... I realized many others are building similar browser-first tools, so I made a curated collection: anantshri.github.io/awesome-in-b... PRs & links welcome
anantshri.github.io
Awesome In-Browser Security Tools
A curated list of open-source security tools that run entirely in your browser — no backend, no installation required.
000
Anant Shrivastava @anantshri.info · 01/01/2026
SBOMPlay v0.0.7 - Custom SBOM support - Improved SBOM auditor: checks against baselines - EOX detection (EOL and EOS) - Dependency confusion detection - Clear rate limit warnings - Explicit list of outbound hosts for paranoid self-hosting deployment cyfinoid.com/sbomplay-v0-...
cyfinoid.com
Introducing SBOMPlay v0.0.7: Enhanced Features Unveiled
Explore the latest updates in SBOMPlay v0.0.7, featuring enhanced capabilities, custom SBOM support, and improved auditing tools.
000
Anant Shrivastava @anantshri.info · 30/12/2025
Discover Readwise Wrapped, your personalized reading recap with stats, insights, and highlights from your reading journey over the year.
blog.anantshri.info
Readwise Wrapped: my year in reading
TL;DR: I built Readwise Wrapped. It gives you a Spotify Wrapped style year-in-review for your Readwise highlights. You paste your Readwise token, pick a year, and it spits out a clean, shareable, good-looking reading recap.Link:
000
Anant Shrivastava @anantshri.info · 29/12/2025
I am assuming people are right now collecting their year wraps. I found it was not available for readwise so i made a tool that can get you a year unwrap for readwise readwise-wrapped.apps.anantshri.info Have a go at it and suggest if you feel something is missing.
readwise-wrapped.apps.anantshri.info
Readwise Wrapped 2025
000
Anant Shrivastava @anantshri.info · 29/12/2025
Discover Fedi Wrap, the easy tool for generating your year in review report from fediverse mastodon api compatible servers, prioritizing privacy and local analysis. blog.anantshri.info/building-fedi-w…
Post Image
000
Anant Shrivastava @anantshri.info · 25/12/2025
🚀 3rd Party Tracer v1.0.6 🚀 New features: • Quick scan mode added • More sources added for subdomain enum • Email security dashboard • Batch analysis • JSON Import • Pdf export Try: cyfinoid.github.io/3ptracer/ Star: github.com/cyfinoid/3pt... Client-side only. No data leaves your browser.
cyfinoid.github.io
3rd Party Tracer - Third Party Service Identifier
000
Anant Shrivastava @anantshri.info · 08/12/2025
All the new 3rd party modules must not be installed immediately, unless its a critical zero day, unless the author informs you to do so, unless a gazillion other exceptions. Infosec needs to make up their mind what should dev/admins do. and ya everyone with buy my product can go to hell.
000
Anant Shrivastava @anantshri.info · 02/12/2025
vehicle data has been public for more then a decade. this is a scam message 101 but i think you already know that. apk sideloading has been one of the biggest issues google faced which is why the new norms they are pushing on total opposite side only developers who are registered will be allowed
000
Anant Shrivastava @anantshri.info · 19/11/2025
🚨 BLACK FRIDAY MEGA SALE 🚨 All Cyfinoid security tools are 100% OFF! Get our security tools for the low price of $0.00! SBOM analyzer? FREE 3PTracer? FREE Act fast! This deal expires in... *checks notes* ...never. Because they've always been free cyfinoid.github.io
cyfinoid.github.io
Cyfinoid Research - Security Tools & Projects
Cyfinoid's collection of security tools and research projects including software supply chain analysis, Android assessment, cloud security, and more.
010
Reposted by Anant Shrivastava
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 18/11/2025
With cloudflare being down, and as a result, most things I use being down, I came here to say hi 🤭 I guess I will use other AIs than chatgpt today!
051
Anant Shrivastava @anantshri.info · 10/11/2025
New version of #SBoMPlay is available cyfinoid.github.io/sbomplay/ Source code : github.com/cyfinoid/sbo... Bunch of New Features in experimental mode - Aggregate List of authors - Identify version sprawl amongst projects - common dependencies across projects - License changes in package versions
cyfinoid.github.io
SBOM Play - Client-Side Analysis
010
Reposted by Anant Shrivastava
DEF CON @defcon.bsky.social · 10/10/2025
#DEFCON34 Call for #CTF Organizers is OPEN! After four excellent years, Nautilus Institute is retiring from running the official #DEFCON CTF. The search is on for the next team. Is it your turn? Is your crew the future of live hacking competitions? defcon.org/html/links/d...
defcon.org
DEF CON® Hacking Conference - Call for CTF Organizers
Nautilus Institute is passing the torch, will your group be the next CTF Overlords?.
066
Anant Shrivastava @anantshri.info · 26/09/2025
Final hours for Black Hat EU Early Bird! 🚨 Save £300 today and join my 0wning the Cloud training this December in London. We’ll cover AWS, Azure, GCP, DigitalOcean & Aliyun with hands-on attack + defense labs. 🔗 Register before midnight: www.blackhat.com/eu-25/traini...
blackhat.com
Black Hat
Black Hat
020
Anant Shrivastava @anantshri.info · 23/09/2025
We just dropped GH Navigator 🎉 Paired with KeyChecker, it gives full GitHub coverage: Data plane: what can be read Control plane: what can be changed Check out the release post 👉 cyfinoid.com/gh-navigator...
cyfinoid.com
Introducing GH Navigator: Optimizing GitHub Security Tools
Discover how GH Navigator and KeyChecker enhance GitHub security by providing visibility and testing for both data and control planes.
020
Reposted by Anant Shrivastava
Baldur Bjarnason @baldurbjarnason.com · 21/09/2025
“OpenAI admits AI hallucinations are mathematically inevitable, not just engineering flaws” www.computerworld.com/article/40593…
1118674
Anant Shrivastava @anantshri.info · 16/09/2025
Everyone talking about npm hacks. But is it really more attacks or just more visibility? Maybe attackers are piling on npm Maybe the ecosystem is just easier to monitor Maybe sloppy practices make it an easy catch What nags me more: silence in PyPI, RubyGems, Maven. No attacks, or no one looking?
010
Anant Shrivastava @anantshri.info · 16/09/2025
am i the only one who goes like lets finish all updates on one version then do version upgrade.
000
Anant Shrivastava @anantshri.info · 12/09/2025
bsky.app/profile/anan... :P
010
Reposted by Anant Shrivastava
BSides London @bsideslondon.bsky.social · 08/09/2025
#BSidesLDN205 Call for Workshops is still open! Want to pass on the knowledge you have? Here's your chance: cfp.bsides.london/bsides-londo... Any topic. 2-4hrs long Not a commercial presentation 30 people minimum audience (mixed experienced levels) #Security #BSIdes #London
077
Reposted by Anant Shrivastava
Nathan Hamiel @nhamiel.bsky.social · 03/09/2025
To all of the people pushing hard to coin the term “vibe security,” the joke is on you. Security has always been about vibes. 😆
001
Anant Shrivastava @anantshri.info · 30/08/2025
Determinism builds trust, non-determinism builds discovery. The art lies in knowing when the world needs certainty - and when it needs the unexpected gift of surprise.
blog.anantshri.info
Not Every Nail Needs a Non-Deterministic Hammer
Determinism builds trust, non-determinism builds discovery. The art lies in knowing when the world needs certainty - and when it needs the unexpected gift of surprise.
010
Anant Shrivastava @anantshri.info · 29/08/2025
Most say ‘think like a hacker,’ but infosec fights adversaries with goals, not curiosity. Real defense means blending hacker creativity with adversary realism.
blog.anantshri.info
Hacker Vs Adversary
Most say ‘think like a hacker,’ but infosec fights adversaries with goals, not curiosity. Real defense means blending hacker creativity with adversary realism.
000
Anant Shrivastava @anantshri.info · 28/08/2025
My thoughts on how LLM behaviour makes me rethink my own brain’s inner workings. A prediction engine as a mirror for a mind.
blog.anantshri.info
What LLMs Teach Me About My Own Brain
My thoughts on how LLM behaviour makes me rethink my own brain’s inner workings. A prediction engine as a mirror for a mind.
000
Anant Shrivastava @anantshri.info · 25/08/2025
Readwise reader is replacing google reader for me plus some more stuff.
reader.readwise.com
100
Anant Shrivastava @anantshri.info · 22/08/2025
🔑 Introducing KeyChecker – a CLI to fingerprint SSH private keys & map them to Git hosting accounts. 📖 Blog: cyfinoid.com/automating-a... 🐍 PyPI: pypi.org/project/keyc... #bugbountytips #ssh #git #github #infosec
cyfinoid.com
Enhance Software Security with KeyChecker for Developer Keys
Discover how 'keychecker' automates SSH key validation to enhance supply chain security for developers and defenders alike.
000
Anant Shrivastava @anantshri.info · 22/08/2025
github.com/njelich/Link... This is what i use.
github.com
GitHub - njelich/LinkOff: Cleans the LinkedIn feed based on keywords and filters.
Cleans the LinkedIn feed based on keywords and filters. - njelich/LinkOff
010
Anant Shrivastava @anantshri.info · 30/07/2025
Its funny how current ai tooling plays out and a few years ago self help courses use to use this same tactic. We are giving you tool if you dont use it properly it will not give you result. So user pays you for stuff and if it doesnt work its their problem not yours.
000
Anant Shrivastava @anantshri.info · 29/07/2025
Making Security Tools Accessible: Why I Chose the Browser Tired of tools that need Docker to read a JSON file? I built browser-native, client-side tools like SBOMPlay and 3ptracer to prove you don’t need servers, tracking, or setup. Just open index.html and go. Minimalist, secure, and surprisingly…
blog.anantshri.info
Making Security Tools Accessible: Why I Chose the Browser
Tired of tools that need Docker to read a JSON file? I built browser-native, client-side tools like SBOMPlay and 3ptracer to prove you don’t need servers, tracking, or setup. Just open index.html and go. Minimalist, secure, and surprisingly powerful.
000
Anant Shrivastava @anantshri.info · 27/07/2025
Updates and plan for HackerSummerCamp USA 2025
blog.anantshri.info
HackerSummerCamp USA 2025
It’s that time again : HackerSummerCamp @ Vegas 2025.This one's special for me: it's my 10th BlackHat USA. What started back in 2015 as a support trainer gig has snowballed into… well, let’s just say the badge can no longer fit all the hats I wear. Here’s how the madness unfolds this year: 📆 2nd–5th Aug 2025: BlackHat Trainings&hellip;
000
Anant Shrivastava @anantshri.info · 26/07/2025
Vibe coding with AI feels magical until your project spirals into chaos. This guide explores how to stay grounded while building with AI tools; covering minimalism, context limits, testing, & code hygiene. A practical read for developers navigating the fine line between productivity & hallucination.
blog.anantshri.info
A Rational Survival Guide to Vibe Coding with AI
Vibe coding with AI feels magical until your project spirals into chaos. This guide explores how to stay grounded while building with AI tools, covering minimalism, context limits, testing, and code hygiene. A practical read for developers navigating the fine line between productivity and hallucination.
000
Anant Shrivastava @anantshri.info · 21/07/2025
If anyone here is already on @peerlist.bsky.social connect with me and if you are not signup here peerlist.io/anantshri/si... seems like a fun place especially if you want to be connected to builders.
peerlist.io
Anant has invited you to join Peerlist!
000
Anant Shrivastava @anantshri.info · 21/07/2025
This and a lot more is convered in my Defcon 2025 Training : training.defcon.org/collections/...
training.defcon.org
Cyfinoid Research - Attack and Defend Software Supply Chain - DCTLV2025
Name of Training: Attack and Defend Software Supply ChainTrainer(s): Anant ShrivastavaDates: August 11-12, 2025Time: 8:00 am to 5:00 pm PTVenue: Las Vegas Convention CenterCost: $1800 Course Description:  In today's interconnected world, software development relies heavily on third-party components---up to 80% of your
000
Anant Shrivastava @anantshri.info · 21/07/2025
Introducing SBOM Play: A Privacy-First SBOM Explorer with Vulnerability & License Insights cyfinoid.com/introducing-... A fully client side browser based SBoM Explorer. more details on the link. #SBoM
cyfinoid.com
SBOM Play: Simplified SBOM Visualization Tool for Developers
Discover SBOM Play: a user-friendly tool to visualize SBOMs with vulnerability insights and licensing analysis—no complex setup required!
122
Anant Shrivastava @anantshri.info · 21/07/2025
As i finalize my "Attack and Defend Software Supply Chain" Training. I am sprinkling newer content and one of the thing would be AI supply chain attacks. Join me @ Defcon 2025 : training.defcon.org/collections/... for a deep dive into the amazing world of software supply chain security.
salt sprinkler meme but instead of salt sprinkling AI
000
Anant Shrivastava @anantshri.info · 14/07/2025
I can understand your side of concern too. its not about who is right or wrong. we all look at the elephant from our sides. Now a days i tell the camera person to keep the camera not too tight, i try to stick within a big box of 4-5 fts to allow movement yet stable but i ensure i stand in center.
010
Anant Shrivastava @anantshri.info · 14/07/2025
however if I as a speaker is part of the whole game then its like performance art you cant ask an artist to stick to conforming norms, they need to be able to freely express themselves. and walking is one way of expression. hope that makes sense.
100
Anant Shrivastava @anantshri.info · 14/07/2025
If a person speaking is not comfortable then output does'nt services anyone. Part of being comfortable means being able to freely interact with the environment. if i am standing stuck behind podium i have already lost 3/4th of my body to the podium. this can work when slides are king cont.
100