Penetration Testing
Learning web, network, and host penetration testing with industry-standard methodologies and tooling.
Available for opportunities
Cybersecurity learner, CTF player, ethical hacking student, security enthusiast, and lifelong learner.
Cybersecurity student and enthusiast learning ethical hacking, vulnerability research, and how secure systems are built. I break things in labs to learn how to make them stronger.
TryHackMe & HackTheBox
I'm a cybersecurity student and enthusiast building hands-on experience in penetration testing, web application security, and digital forensics.
My journey started with curiosity — wanting to understand how systems work and, more importantly, how they break. That curiosity is shaping the path I'm on now: learning, lab by lab, challenge by challenge, toward a career defending systems and helping organisations stay secure.
I practise through hands-on labs and challenges on TryHackMe, Hack The Box, and PortSwigger Web Security Labs — including real-world CTF competitions.
BCS Cybersecurity & Networking — Texas College of Management & IT (Ongoing)
Based in — Bouddha, Kathmandu, Nepal
Familiarity levels across the areas I practise as a student — tap any card to try a hands-on challenge.
Learning web, network, and host penetration testing with industry-standard methodologies and tooling.
Practising the OWASP Top 10 — XSS, SQLi, IDOR and more — in deliberately vulnerable lab environments.
Writing Python and Bash scripts for recon, automation, and small security tools.
Passive and active reconnaissance, digital footprinting, and information gathering.
Getting started with binary and malware analysis using Ghidra and GDB in CTF challenges.
TCP/IP, Nmap, Wireshark, and network security fundamentals at a CCNA level.
Log analysis, disk and memory basics, and malware triage using Autopsy, Volatility, and Binwalk.
Hands-on projects where I applied security-first thinking. More on my GitHub.
Built a web lab to simulate exploits and apply code-level hardening.
• Exploit Testing: Injected intentional SQLi, IDOR, and Stored XSS flaws.
• Defensive Hardening: Patched vulnerabilities using Django ORM and access controls.
• Security Auditing: Used Burp Suite to verify all fixes worked.
Built a real-time log analysis parser to simulate SOC monitoring and threat detection.
• Log Analysis: Ingested Linux syslog data to track live authentication events.
• Threat Detection: Scripted automated alerts to flag brute-force attacks and unauthorized access.
• Incident Response: Modeled basic SIEM logic to accelerate defensive triage.
High-level breakdowns of real incidents and threats I've researched as a learner. These are awareness-focused summaries — the full write-ups and discussion live on my LinkedIn.
A structured analysis of a Nepali ISP data breach — mapping the incident timeline, the categories of customer data exposed, the cyber-law implications, and the privacy lessons.
Read on LinkedInA high-level look at digital risks around national identity and passport infrastructure, and why strong data protection matters for public systems — focused on awareness.
Read on LinkedInNotes on a reported flaw in a major AI assistant and what it signals for the emerging field of AI/LLM security — prompt-handling risks and the defensive mindset required.
Read on LinkedInA threat-intelligence summary of the APT36 group and its remote-access-trojan activity — who they target, why it matters for the region, and the detection signals to watch for.
Read on LinkedInAn explainer on a software supply-chain worm and why dependency security has become critical — the high-level idea and the guardrails (lockfiles, provenance, least privilege).
Read on LinkedInA hands-on lab write-up: finding common web flaws (SQLi, XSS, RCE) in a deliberately vulnerable WordPress setup, then applying patching, access control, and hardening strategies.
Read on LinkedInWant the full breakdowns? Follow my case-study posts on LinkedIn.
Have a project, need a security assessment, or just want to talk hacking? I'm always open to interesting conversations.