Penetration Testing
Simulating real attacks against web apps, networks and infrastructure to surface exploitable weaknesses.
OPERATOR ID
potat0
PHOTO ID
Identity
I'm a Penetration Tester and IT Auditor at Himalayan Integrated Cloud Technologies, where I work at the intersection of offensive security and compliance. On one side, I run VAPT engagements - probing networks, web applications, and infrastructure for exploitable weaknesses and turning findings into clear, actionable reports. On the other, I conduct ISO 27001 Annex A audits for financial institutions across Nepal's capital market ecosystem, helping broker organizations meet SEBON, NEPSE, and CDSC regulatory requirements. Outside of client work, I compete in CTF competitions, tackling challenges in binary exploitation, reverse engineering, and web security. It's where I keep my technical edge sharp - heap exploitation, bypassing sanitizers, reversing custom VMs, whatever the challenge throws at me. I also do frelance works conducting testing for web applications, networks and infrastructure for businesses.
0
Years in Security
0
Projects Shipped
0
CTFs & Hackathons
0
ISO 27001 Controls Audited
Security Architecture
The areas I actively work in, from offense to governance.
Simulating real attacks against web apps, networks and infrastructure to surface exploitable weaknesses.
Designing segmented, firewalled network architectures and hardening routing and switching layers.
Reconstructing incidents from artifacts, logs and memory to establish what happened and how.
Building and tuning detection logic across SIEM pipelines to catch anomalous behaviour early.
Enumerating and exploiting OWASP-class vulnerabilities across authentication, input handling and logic flaws.
Coordinating audit findings, gap analyses and remediation plans aligned to ISO 27001 and NEPSE formats.
Selected Tools and Stack
Narrative
Right now I'm splitting time between offensive engagements and formal compliance work - running VAPT against client web apps, firewalls and databases by day, and mapping vendor evidence to ISO 27001 Annex A controls for SEBON-licensed brokerage firms by the other half of the day. I'm using that overlap to get sharper at translating raw findings into remediation language that actually survives an audit committee, while keeping my CTF and independent research practice active on the side.
Interactive
Type help to see what this thing can do.
Welcome to the terminal. Type help to get started.
Technical Stack
Hands-On Work
May 2026 — Present
Himalayan Integrated Cloud Technologies
June 2025 — Present
Himalayan Integrated Cloud Technologies
2024 — 2025
TechX Softwarica
2024 — Present
Attack On Hash Function
Proof Of Work
A lightweight C2 framework built to simulate remote command execution and study post-exploitation tradecraft in a controlled lab.
Secure voting platform using public-key cryptography and digital certificate validation to preserve ballot integrity and voter anonymity.
Python-based IDS combining signature-based rules with anomaly detection to flag suspicious network behaviour in real time.
A scanning tool that enumerates web servers for exposed endpoints, misconfigurations and common vulnerability signatures.
Designed a segmented three-tier secure network model with strict firewall rules and subnet isolation between zones.
Wazuh SIEM deployment for threat detection and response1. Full working implementation for both linux and windows.
Ajax Security Team (MITRE ATT&CK Group G0130) against a simulated corporate endpoint, executed inside a fully isolated virtual lab.
rsyslog with Grafana integration for real-time log analysis and visual dashboard, works for multiple platforms.
Research Notes
I document CTF solves and lab research as I go - box walkthroughs, exploitation chains and the odd rabbit hole into reverse engineering. All of it lives on a dedicated writeups page rather than cluttering this portfolio.
Browse WriteupsAcademic Path
Softwarica College of IT and E-Commerce, Kathmandu
2023 — 2026
Saipal Academy, Dhumbaharai, Kathmandu
2020 — 2022
Download
The full CV, in PDF, with everything on this page plus a few extra details.
Download Resume (PDF)