more@fw-lab:~$
Ph.D. Candidate · Cybersecurity · Florida Tech

Sandesh More

I take security apart at the silicon level. Firmware extraction over SPI, JTAG, UART and SWD, reverse engineering of drone and IoT ecosystems, and now AI/ML and MCP protocol security. Credited with 2 CVEs, author of 5 publications, and builder of tools that turn research into practice.

CVE-2023-49199 CVE-2023-49200 Firmware RE Drone Security AI Red Teaming DFIR
MORE SEMICONDUCTOR
SM-2027
SECURITY RESEARCHER · REV 4.0
0CVEs
0Publications
0Citations
0Sources Surveyed
LOT: MELBOURNE-FL · EST. GRAD 2027-05
DFRWS USA 2026 · Arlington VA · NSF Student Travel Award ▣ arXiv:2605.11040 · Multi-Interface Firmware Acquisition methodology INTED 2026 · Docker-based cybersecurity laboratories ▣ NCL Fall 2024 · Ranked 36 / 534 teams nationally ▣ Researching MCP protocol security & LLM agent threat models ▣ CompTIA CySA+ · Certified Network Pentester CNPen
0x01

Active Research

// what's on the bench right now
Upcoming · Jul 2026

DFRWS USA 2026 — Forensic Firmware Acquisition

Presenting poster research on forensically sound firmware acquisition from consumer drones, including a false-acquisition failure mode discovered on the Holy Stone HS360S where the readout silently returns invalid data.

NSF Student Travel Award · Arlington, VA
Preprint · 2026

Multi-Interface Firmware Acquisition & Validation

A methodology for low-cost consumer drones, validated as a case study across three Holy Stone platforms. Covers SPI, JTAG, UART and SWD acquisition paths with integrity verification at each stage.

arXiv:2605.11040 · More, Sudhakaran, Carvalho
Active

AI/ML & MCP Protocol Security

Threat modeling LLM agent ecosystems: MCP protocol attack surfaces, adversarial machine learning, and secret leakage detection in AI-assisted developer workflows.

LLM Agents · Adversarial ML · Shift-Left
Active

Medical & Consumer IoT Teardowns

Hardware-level analysis of medical IoT (EMAY pulse oximeter, SYD8810 BLE SoC) and consumer cameras (Wyze Cam OG), tracing data flows from sensor to cloud.

BLE · Firmware Extraction · Privacy
In Progress

IoT Firmware Extraction Survey

IEEE-format survey synthesizing 150+ sources on firmware extraction and vulnerability analysis techniques, building a taxonomy of acquisition methods across device classes.

Survey · 150+ Sources · Taxonomy
Ongoing

Ph.D. Dissertation

Dissertation research spanning consumer drone firmware security, hardware acquisition methodology, and forensic readiness of low-cost UAV platforms. Expected graduation May 2027.

Advisor: Dr. Sneha Sudhakaran · Florida Tech
0x02

Disclosed Vulnerabilities

// responsible disclosure · MITRE credited
CVE-2023-49199 High Severity

Missing Access Control — Holy Stone HS175D

The drone exposes an unsecured Wi-Fi access network with no access control. Any user can connect, passively capture drone traffic disclosing the RTSP server address, and attach to the live video stream.

Wi-FiRTSPAccess ControlPrivacy
Discovered via protocol analysis & packet capture investigation
CVE-2023-49200 Critical

Undocumented Telnet Root Access — Holy Stone HS720

An undocumented telnet service runs on port 23 with default credentials. A remote attacker can authenticate to the service and is immediately granted root permissions on the flight controller.

TelnetDefault CredsRootRemote
Vendor remediation & published advisories followed disclosure
0x03

Research Domains

// full lifecycle: chip → cloud → report
DOM_01

Hardware & Firmware Extraction

Physical acquisition from flash chips and debug ports. Desoldering, in-circuit reads with SOIC8 clips and CH341A programmers, and validation methodologies that catch silent acquisition failures.

SPIJTAGUARTSWDflashrom
DOM_02

Drone & IoT Vulnerability Research

End-to-end assessments of consumer drones, medical IoT and smart home devices. Attack vector taxonomies, exploit chains, and TTP mapping to MITRE ATT&CK and OWASP frameworks.

GhidraRadare2BinwalkWireshark
DOM_03

AI/ML & Agent Security

Emerging focus on LLM agent threat models, MCP protocol attack surfaces, adversarial machine learning, and automated secret leakage detection in AI-assisted code review.

LLM AgentsMCPAdversarial ML
DOM_04

Digital Forensics & IR

Memory and disk forensics, malware behavioral analysis, and forensically sound acquisition. 20+ malware samples documented with IOC extraction mapped to known TTPs.

Volatility 3FTKSleuth KitYARA
0x04

Publications

// peer-reviewed + preprints
2026

A Multi-Interface Firmware Acquisition and Validation Methodology for Low-Cost Consumer Drones: A Case Study on Three Holy Stone Platforms

arXiv preprint · arXiv:2605.11040
More, S., Sudhakaran, S., Carvalho, M.
Preprint arXiv ↗
2026

Advancing Cybersecurity Competency Through Structured Docker-Based Laboratories in Locally Hosted Student Settings

INTED 2026 Proceedings · Article 1260
More, S.A., Polineni, U.K., Sudhakaran, S.
Conference DOI ↗
2025

Comprehensive Security Assessment of Holy Stone Drones: Examining Attack Vectors

20th International Conference on Cyber Warfare and Security (ICCWS), 20(1), pp. 574–583
More, S., Sudhakaran, S., O'Connor, T.J., Carvalho, M.
Cited ×3 DOI ↗
2025

Enhancing Cybersecurity Education: The Impact of Simulated Learning and Interactive Tutorials on Student Performance and Anxiety Reduction

INTED 2025 Proceedings · Valencia, Spain · pp. 1775–1784
Panakkadan, R.R., Meher, P., More, S.A., Sudhakaran, S.
Cited ×6 DOI ↗
2023

Security Analysis of HolyStone Drones: Examining Attack Vectors and Data Extraction Techniques

Master's Thesis · Florida Institute of Technology Repository
More, S.A.
Cited ×2 Repository ↗
11 citations 5 publications 2 MITRE-credited CVEs 150+ sources synthesized in survey work
0x05

Experience

// 4+ years hands-on
May 2023 — Present

Graduate Research Assistant · Threat & Vulnerability Research

Florida Institute of Technology · Melbourne, FL
  • Discovered and responsibly disclosed CVE-2023-49199 and CVE-2023-49200 in Holy Stone drone communication stacks, resulting in vendor remediation and published advisories.
  • Extract firmware over SPI, JTAG, UART and SWD and reverse engineer binaries in Ghidra, Radare2 and Binwalk to identify hardcoded secrets and exploitable code paths.
  • Authored an IEEE-format survey synthesizing 150+ sources on IoT firmware extraction, alongside peer-reviewed papers, threat advisories and technical reports.
  • Extended research into AI/ML security: LLM agent threat models, MCP protocol risks, adversarial ML, and secret leakage detection in developer workflows.
  • Designed Docker-based CTF lab infrastructure with watermarking and integrity verification; trained 100+ students with 95% satisfaction.
Jan 2023 — May 2023

Graduate Research Assistant · Cyber Forensics & Malware Analysis

Florida Institute of Technology · Melbourne, FL
  • Investigated compromised systems through disk imaging, memory forensics and behavioral malware analysis; documented 20+ malware samples and 15+ active threats with extracted IOCs.
  • Reduced incident response time by 40% and achieved an 85% breach resolution rate via repeatable triage and artifact analysis workflows.
  • Translated technical artifacts into clear forensic case studies for non-specialist readers.
Jan 2021 — Jan 2022

Cybersecurity Intern · Offensive Security & Detection Engineering

IRT Technologies Pvt. Ltd. · India
  • Developed Python-based detection and automation tooling, improving threat detection coverage by 40%.
  • Conducted penetration tests against web applications and OS environments, remediating 12+ vulnerabilities aligned with OWASP Top 10.
  • Delivered audit findings to senior leadership; eliminated 15 high-risk vulnerabilities and cut incident response time by 50%.
0x06

Built & Shipped

// research → working tools
ai_code_review/ACTIVE

AI Code Review & Secret Leakage Detection Platform

Security scanning platform combining secret leakage detection, static analysis and LLM agent security rules to flag exposed credentials and insecure patterns in developer workflows. Built around Zero Trust and shift-left principles.

FastAPIReactLLM Agents
GitHub ↗
drone_skb/LIVE

Drone Security Knowledge Base

Full-stack threat intelligence platform aggregating 50+ drone and UAV vulnerabilities mapped to the OWASP Drone Top 10 and MITRE ATT&CK, with an automated CVE ingestion pipeline pulling real-time data from NVD.

ReactPythonNVD APICI
GitHub ↗
iot_privacy_viz/LIVE

IoT Privacy Risk Visualizer

Automated analysis tool that parses firmware binaries and network captures to detect 15+ sensor types, identify data exfiltration destinations, and generate privacy risk scores for IoT devices.

FastAPIReactD3.js
GitHub ↗
drone_assessment/PUBLISHED

Consumer Drone Security Assessment

End-to-end vulnerability assessments on Holy Stone drones. Authored 9 security guidelines and a published attack vector taxonomy, reducing the potential breach surface by 45%. Foundation of both CVEs and the ICCWS paper.

REWirelessProtocol Analysis
Paper ↗
firmware_analyzer/OSS

Firmware Analyzer

Automated firmware analysis tool written in Go for security assessment of embedded systems and IoT devices: unpacking, string and secret hunting, and structure identification.

GoBinwalkEmbedded
GitHub ↗
ctf_lab_infra/DEPLOYED

Docker-Based CTF Lab Infrastructure

Locally hosted cybersecurity laboratory environment with challenge watermarking and integrity verification, used to train 100+ students. Published as a pedagogy study at INTED 2026.

DockerLinuxCTF
Paper ↗
0x07

The Lab Bench

// tooling organized by port
HW

Hardware & Firmware

CH341ASOIC8 ClipsflashromSPIJTAGUARTSWDGhidraRadare2Binwalk
AI

AI/ML Security

LLM Agent Threat ModelingMCP Protocol SecurityAdversarial MLSecret Leakage Detection
OFF

Offensive Security

MetasploitBurp SuiteNmapNessusOWASP ZAPKiterunnerffufwfuzzExploit Dev
DFIR

Forensics & IR

Volatility 3FTK ImagerSleuth KitEnCaseAutopsyBelkasoft XSIFTYARA
DET

Detection & Intel

SplunkWazuhELK StackQRadarZeekSuricataSnortMITRE ATT&CKOSINT
DEV

Code & Cloud

PythonC/C++GoBashPowerShellSQLAWSAzureDockerGit
0x08

Teaching & Community

// knowledge transferred
100+Students Trained

Across security courses, CTF labs, and tutoring with 95% satisfaction

36/534NCL Fall 2024 Rank

Two-person team in the National Cyber League graduate bracket

15+CTF Challenges Built

Memory forensics, crypto and network security challenges for FITSEC & Cyber Heroines

4Courses Supported

Algorithms, Big Data, Python, Formal Languages: grading, labs & instruction

CompTIA CySA+Verification: 99WEL64YTJVEQ6CM
Certified Network PentesterThe SecOps Group · ID 9315107
CVE-Credited ResearcherMITRE · Holy Stone disclosures
NSF Student Travel AwardDFRWS USA 2026

Open Port.
Initiate Handshake.

Research collaboration, AI red teaming, firmware security, or speaking opportunities. Serious inquiries decoded at full baud rate.