Creation of scripts/functions with new programming language to commence Computer & Network forensic analysis without triggering security solutions
National Technical Research Organisation (NTRO) · Blockchain & Cybersecurity · Software
As written this asks for an antivirus-evasion and covert-C2 toolkit, which a student team should not build or demonstrate — if you engage the organisation at all, reframe it toward authorised, allow-listed forensic collection rather than the evasion tradecraft the description details, and confirm scope with them directly.
What it actually is
This problem statement asks for a framework and language whose stated purpose is to run forensic tooling on a system while evading antivirus and endpoint security — explicitly using polymorphic engines, custom encryption, in-memory execution, bring-your-own-vulnerable-driver techniques and domain fronting to route command traffic. Regardless of the defensive framing, the described capability is an offensive malware-development and endpoint-evasion toolkit.
What to build
Not advisable to attempt as specified. The described system — a language and framework that alters control-flow graphs to avoid signature and heuristic detection, combines polymorphic engines with custom encryption and multi-vector in-memory execution, exploits vulnerable drivers to gain kernel access, and hides command-and-control traffic behind domain fronting through trusted CDNs — is a catalogue of the exact techniques used by advanced malware to evade defences and maintain covert control, and building it would produce a weaponisable evasion toolkit rather than a legitimate forensic tool.
Smallest thing that wins the room
Not applicable — a demonstration of the described capability would mean showing malware successfully evading endpoint security and establishing covert command channels, which is the harmful outcome itself.
How crowded this one gets
A guess, projected from the 2025 statements — the last year where both the submission counts and the winners were published.
Quieter than 84% of the 226 · #38 of 226 by expected field
Few teams are likely to go here. The best odds on the board come from statements like this.
Why: defence, intelligence and space bodies drew small fields.
This is a guess, not a fact
Nobody has published 2026’s numbers yet. This is an analysed estimate from last year’s pattern, so please do not take it as the truth — check the live counter on the SIH portal before you decide anything. The range covers the middle half of likely outcomes, so one statement in two lands outside it. Entry closes at 500 ideas per statement, so no range goes past that — a statement that reaches the cap fills and shuts rather than drawing an unlimited crowd. The model reads only three things a team can see before choosing — software or hardware, the theme, and what kind of body posted it — and those explain about a quarter of the variation in last year’s field sizes (R² 0.25 on held-out statements). Trust the band more than the number, and the ordering more than either. It cannot see how good your idea is, which is the part that actually decides it.
The scores
The number is the shorthand. The line under it is the reason.
Acceptance potential
1/5This should be avoided — the described capability is an antivirus-evasion and covert-C2 malware toolkit whatever the forensic framing, it is not something a student team should build or demonstrate, and the technical scope is nation-state-grade regardless.
Feasibility
1/5Beyond the ethical problem, each named element — a custom polymorphic language frontend, BYOVD kernel access, in-memory injection, domain-fronted C2 — is individually a serious specialist undertaking, and integrating them is a nation-state-grade offensive tooling effort far outside a hackathon's reach.
Innovation scope
2/5The techniques named are established offensive tradecraft rather than open ground, so the work is reproducing known evasion methods, and the framing leaves little legitimate room to be creative in.
Clarity
3/5The techniques are named specifically, but the stated forensic purpose sits incoherently on top of a description of malware evasion tradecraft, so what a legitimate deliverable would even look like is genuinely unclear.
Effort
MassiveA custom compiler frontend, polymorphic engine, kernel-level driver exploitation and covert channel infrastructure is an enormous undertaking quite apart from whether it should be built.
Demo-ability
HardDemonstrating success means demonstrating evasion of security products and covert control, which is both the harmful outcome and something that cannot be shown responsibly.
In its favour
- Green flag: The legitimate need behind it — forensic tools being blocked by security software on systems an investigator is authorised to examine — is a real problem worth solving in a sanctioned, allow-listed way
- Green flag: The forensic-analysis and evidence-gathering portion, done openly and with proper authorisation, is a legitimate area to work in
- Green flag: The domain is one NTRO genuinely cares about, so a responsibly reframed submission could still resonate
Against it
- Red flag: The described capability — polymorphic evasion, BYOVD kernel access, domain-fronted C2 — is offensive malware tradecraft, and building it produces a weaponisable toolkit regardless of the stated defensive intent
- Red flag: Demonstrating it means showing security products being defeated, which is the harmful outcome and cannot be responsibly presented
- Red flag: Anti-forensic and evasion tooling is exactly the kind of dual-use capability that should not be developed as a student project without a sanctioned framework
- Red flag: Even setting ethics aside, the technical scope is nation-state-grade and unreachable in a hackathon
What you will be writing
- (not advisable to build as specified — describes offensive evasion tradecraft)
- Endpoint security evasion
- Offensive tooling
- Digital forensics
Prior art to read before you start
antivirus and EDR evasion · covert command and control · in-memory execution tradecraft
Analysed by Claude Opus. Every score above is a judgment call with its reasoning attached — kindly cross-check this against the official statement on the SIH portal before your team commits to it.