The document has the usual ingredients of university administration: a seal, a reference number, a table, signatures, and conditions in small print. It grants permission for a cybersecurity society at Delhi Technological University to begin its activities. For Anuj Rawat, this sheet of paper was something to celebrate. He shared it with a message of relief and gratitude: he had managed to make it happen before graduating. Among the various flags a hacker might capture, university approval is an unusually bureaucratic trophy.
Rawat thanked a string of fellow students by name, including Abhay Yadav, Kartik Vats, Tarush Sonakya, Akshat Jain, Tushar Singh Bisht, Arsh Abbas, Mauray Jain and Mayank Jangid. The list matters. A society needs people who will keep showing up, and his announcement gave those people their place in the story. EHAX had moved from a gathering of enthusiasts to a student body acknowledged by the university. A shared interest had acquired somewhere to live.
Today, Rawat is associated with HighRadius as a cybersecurity engineer and remains named as EHAX’s founder. The two roles put him in different settings: a software business and a university community. His public work adds a third setting, the small, practical world of scripts and security tools. Taken together, these activities offer a useful way into his career: through the things he has helped establish, test and make available to others.
A permission slip with a purpose
The approval notice is refreshingly specific about what the society is for. Its purpose is to deepen students’ understanding of cybersecurity through hands-on workshops, live demonstrations and capture-the-flag competitions. Prof. Anil Singh Parihar is named as faculty advisor; Dr. Pawan Singh Mehra as co-faculty advisor. The ambitions are practical, and the university’s expectations are practical too. There are progress reports to submit, rules to follow and financial responsibilities to handle.
That combination gives the founding moment its texture. Cybersecurity students may enjoy finding a system’s unexpected behavior, but a university society also has to work within an institution’s ordinary procedures. The notice asks for supervision, discipline and reporting. Even an ethical hacking club must occasionally conquer a form. Rawat’s message marked the successful completion of that particular task, without pretending he had done it alone.
His DTU education is listed for 2021 to 2025. During those years, his campus activities included founding and presiding over EHAX, serving as vice president of INNOVA DTU and mentoring cybersecurity enthusiasts through Round Table DTU. He also lists logistics work with Rotaract Club of DTU Regency and membership of Fresources. It is a campus record with both technical work and the organizational duties that make student events possible.

KITKAT enters the scoreboard
One competitive episode comes with a pleasingly ungrand team name. At IronCTF, Rawat competed with Mayank Jangid, Hardik and Aaradhya Bhardwaj as KITKAT. Jangid’s account explains the naming situation with a joke: the EHAX team was already full. Their improvised lineup finished 74th among 1,033 teams. He gave Hardik a special thank-you for carrying the team and included Rawat among the teammates who made the experience worthwhile.
Rawat’s reply was brief: ‘KITKAT FTW’. It fits the occasion better than a solemn declaration about the future of cyberdefense. There was a result to enjoy, teammates to congratulate and another difficult set of puzzles behind them. The placement belongs to the four-person lineup. The affectionate explanation of its formation belongs to the wider student community around it.
In an earlier account of his own learning, Rawat described participating in an IIT Roorkee CTF and gaining root access to a Linux system. He said the experience taught him about creativity, system mechanics and tools. The setting was a competition, and the lesson he drew concerned how systems work. That is a concrete learning anecdote: a challenge, a technical outcome and an explanation of what stayed with him.
Team result, including Anuj Rawat
The instructor’s side of the keyboard
Rawat’s activities also include a volunteer stint as a cybersecurity instructor at the Center for Cyber Security Studies & Research, from July to October 2024. The role sits alongside his campus mentoring rather than replacing it. Teaching and competing appear together in this part of his record. One involves solving a problem; the other involves helping someone else understand how to approach one.
A fellow EHAX member, Soumya Sourav Das, described working under Rawat’s guidance while helping manage IICON at DTU. The Intelligence & Investigation Conference included practical demonstrations, workshops and a concluding CTF conducted by DefHawk. Das’s account credits the team as well as its president. It gives an outside view of Rawat doing the less visible work of an event: helping other students organize and contribute.
His listed certifications include NPTEL’s Cloud Computing credential, issued in October 2023, and Cybrary’s IT and Cybersecurity Foundations, issued the previous month. These are particular steps in his education, alongside competitions and community work. The pattern does not require an invented childhood revelation or a cinematic first encounter with a computer. There is already enough activity in the university years to explain the direction his work took.
A scanner gets a new conversation
By July 2023, Rawat was writing about a specific application of AI to security: improving the configuration of scanning and fuzzing tools so they could detect vulnerabilities more efficiently. That aspiration is more focused than a general enthusiasm for artificial intelligence. It identifies a task within security testing, and asks whether software can help make the task work better.
His ZAP-MCP repository later put AI and scanning in the same project. It describes a bridge between AI models and OWASP ZAP through the Model Context Protocol. The exposed operations cover starting a scan, checking its status, retrieving alerts and obtaining a summary. In everyday terms, the project gives a model a structured way to communicate with a security-testing tool.
The repository credits TAZER, Rawat’s online alias, for initial work and maintenance, and acknowledges Cursor AI’s assistance in development. Its short description is considerably less formal than the documentation. There is room in his public presentation for both a technical explanation and a joke. A tool can have a serious purpose without its creator adopting the tone of a procurement brochure.
Small utilities, visible habits
Some of Rawat’s public code addresses modest chores. WebpUtil is a shell script for converting JPEG and PNG files into WebP. A published solution to the fast_hasher challenge uses Python to process input strings and hashing operations. Another script tackles nested archive extraction. These are different jobs, but each leaves a tangible artifact: code that a reader can inspect rather than a claim about being interested in technology.
His public gists extend that habit beyond security puzzles. A September 2026 script automates parts of selecting and loading LinkedIn connections. A video montage script published in October 2025 handles images and videos, with options for cropping, blurred backgrounds and synchronization to audio. These projects concern ordinary friction as much as technical specialization. File formats and repetitive browser actions can claim an unreasonable amount of a person’s afternoon.
The online identity around the code is playful. He uses Tazer and ajtazer, opens his GitHub profile with ‘Namaste’, and links his own site, X account, Instagram and LinkedIn. That public network helps connect the campus founder with the developer publishing repositories. It also gives the reader several ways to follow his work without borrowing achievements from another person who happens to share his name.
When the next cohort takes over
EHAX’s later achievements belong to the students who earned them. At HackIITK 2026, Tarush Sonakya, Kartik Vats, Stavya Pathak and Tushar Singh Bisht took third prize in the CTF track, worth ₹1,00,000. DTU described a 15-hour overnight contest covering cryptography, web exploitation, reverse engineering and digital forensics. The university named the competitors and the two faculty advisors. Rawat congratulated the team in the comments.
That distinction is essential to the founding story. Rawat helped establish the society; the four named competitors earned that result. The society continued to recruit, organize and compete with later members. Its 2025 offline-meet announcement described new recruits arriving after a 24-hour CTF and an interview. Rawat left a short comment expressing his fear of missing out. The founder was following a gathering that had its own new participants.
A student organization has an unusual timetable. Its members are expected to leave. Success therefore includes giving the next cohort something usable: a recognized society, advisors, events and a community in which to learn. EHAX’s continuation provides the next chapter of the institution Rawat helped start. It does not need every later achievement to be reassigned to him for that chapter to matter.
“Glad that I was able to make it possible before graduating”Anuj Rawat, on EHAX’s recognition
The work beyond graduation
HighRadius provides another professional setting for Rawat’s cybersecurity work. The company develops software for finance processes, including accounts receivable, treasury and financial close. His role places him in a business whose products deal with enterprise financial operations. The specifics of his internal assignments remain his employer’s business; the publicly visible connection is the cybersecurity engineer and the company he works for.
The throughline in his public activity is more concrete: competitions, instruction, organizing and tool building. In his 2023 interview answers, he spoke about learning from experienced professionals and contributing to an organization’s security. Those stated interests sit comfortably beside the projects and campus roles that followed. They describe work to do, rather than a destination announced in advance.
Return to the approval notice and its sober table. The purpose written there was to help students learn cybersecurity through practice. Rawat celebrated getting the society recognized before his university years ended. Other students have since added their own results and gatherings. The paper has signatures; the community has successors. For a founder approaching graduation, that is a satisfying arrangement: something he helped begin still has people turning up to continue it.
Follow the work
Explore Rawat’s GitHub, his public gists, ZAP-MCP and the EHAX website.
Find him on LinkedIn, X and Instagram, or visit his personal site. Read the recognition announcement, KITKAT recap and DTU’s HackIITK announcement.