Available for opportunities

Hi, I'm Kabin Khadka

Cybersecurity learner, CTF player, ethical hacking student, security enthusiast, and lifelong learner.

Cybersecurity student and enthusiast learning ethical hacking, vulnerability research, and how secure systems are built. I break things in labs to learn how to make them stronger.



9+ Certifications
12+ Labs & Case Studies
Nepal Security Focus
Scroll down

Who I Am

Kabin Khadka - Cybersecurity Enthusiast from Nepal

TryHackMe & HackTheBox

I'm a cybersecurity student and enthusiast building hands-on experience in penetration testing, web application security, and digital forensics.

My journey started with curiosity — wanting to understand how systems work and, more importantly, how they break. That curiosity is shaping the path I'm on now: learning, lab by lab, challenge by challenge, toward a career defending systems and helping organisations stay secure.

I practise through hands-on labs and challenges on TryHackMe, Hack The Box, and PortSwigger Web Security Labs — including real-world CTF competitions.

BCS Cybersecurity & Networking — Texas College of Management & IT (Ongoing)

View certifications on Credly

Based in — Bouddha, Kathmandu, Nepal

Let's Connect

Skills I'm Building

Familiarity levels across the areas I practise as a student — tap any card to try a hands-on challenge.

Penetration Testing

Learning web, network, and host penetration testing with industry-standard methodologies and tooling.

Web Exploitation

Practising the OWASP Top 10 — XSS, SQLi, IDOR and more — in deliberately vulnerable lab environments.

Scripting & Automation

Writing Python and Bash scripts for recon, automation, and small security tools.

OSINT & Recon

Passive and active reconnaissance, digital footprinting, and information gathering.

Reverse Engineering

Getting started with binary and malware analysis using Ghidra and GDB in CTF challenges.

Network Security

TCP/IP, Nmap, Wireshark, and network security fundamentals at a CCNA level.

Digital Forensics

Log analysis, disk and memory basics, and malware triage using Autopsy, Volatility, and Binwalk.

Tools I Use

  • Burp Suite
  • Metasploit
  • Nmap
  • Wireshark
  • Ghidra
  • SQLmap
  • Gobuster
  • Hydra
  • Hashcat
  • John the Ripper
  • Nikto
  • Responder
  • BloodHound
  • Impacket
  • ffuf
  • CyberChef
  • Autopsy
  • Volatility
  • Binwalk
  • FTK Imager
  • Strings

Things I've Built

Hands-on projects where I applied security-first thinking. More on my GitHub.

Highlight

Real Estate Net — Secure Real Estate Platform

Built a web lab to simulate exploits and apply code-level hardening.
Exploit Testing: Injected intentional SQLi, IDOR, and Stored XSS flaws.
Defensive Hardening: Patched vulnerabilities using Django ORM and access controls.
Security Auditing: Used Burp Suite to verify all fixes worked.

  • Django
  • Python
  • SQLite
  • Burp Suite

Linux Log Monitoring & Alert System

Built a real-time log analysis parser to simulate SOC monitoring and threat detection.
Log Analysis: Ingested Linux syslog data to track live authentication events.
Threat Detection: Scripted automated alerts to flag brute-force attacks and unauthorized access.
Incident Response: Modeled basic SIEM logic to accelerate defensive triage.

  • PHP
  • Linux Syslog
  • Bash
  • SOC Practice

Case Studies & Research

High-level breakdowns of real incidents and threats I've researched as a learner. These are awareness-focused summaries — the full write-ups and discussion live on my LinkedIn.

Nepal

Vianet Data Breach 2020 (Nepal)

A structured analysis of a Nepali ISP data breach — mapping the incident timeline, the categories of customer data exposed, the cyber-law implications, and the privacy lessons.

Read on LinkedIn
Nepal

Digital Vulnerabilities in Nepal's Passport System

A high-level look at digital risks around national identity and passport infrastructure, and why strong data protection matters for public systems — focused on awareness.

Read on LinkedIn
AI Security

Google Gemini Security Flaw — A New Era of AI Security

Notes on a reported flaw in a major AI assistant and what it signals for the emerging field of AI/LLM security — prompt-handling risks and the defensive mindset required.

Read on LinkedIn
Threat Intel

Transparent Tribe (APT36) RAT Campaign

A threat-intelligence summary of the APT36 group and its remote-access-trojan activity — who they target, why it matters for the region, and the detection signals to watch for.

Read on LinkedIn
Threat Intel

Shai-Hulud — Software Supply-Chain Worm

An explainer on a software supply-chain worm and why dependency security has become critical — the high-level idea and the guardrails (lockfiles, provenance, least privilege).

Read on LinkedIn
Web

WordPress Security Lab

A hands-on lab write-up: finding common web flaws (SQLi, XSS, RCE) in a deliberately vulnerable WordPress setup, then applying patching, access control, and hardening strategies.

Read on LinkedIn

Want the full breakdowns? Follow my case-study posts on LinkedIn.

Get In Touch

Have a project, need a security assessment, or just want to talk hacking? I'm always open to interesting conversations.

Message sent successfully! I'll get back to you soon.