Aayush Shrestha — Penetration Tester & IT Auditor Portfolio

AAYUSH.SEC
SECURITY OPERATOR DATABASE
USER: GUEST / LOCATION: KATHMANDU, NEPAL
00:00:00 SYSTEM ONLINE

OPERATOR ID

potat0

PT AU CTF
Name
Aayush Shrestha
Role
Penetration Tester & IT Auditor
Base
Kathmandu, Nepal
Status
Open to Opportunities
Experience
3+ Years
Education
BSc (Hons) Ethical Hacking & Cybersecurity
Clearance
ISO 27001 Auditor · 5x CTF Podium
Affiliation
Freelance

PHOTO ID

Aayush Shrestha

Identity

About

I'm a Penetration Tester and IT Auditor at Himalayan Integrated Cloud Technologies, where I work at the intersection of offensive security and compliance. On one side, I run VAPT engagements - probing networks, web applications, and infrastructure for exploitable weaknesses and turning findings into clear, actionable reports. On the other, I conduct ISO 27001 Annex A audits for financial institutions across Nepal's capital market ecosystem, helping broker organizations meet SEBON, NEPSE, and CDSC regulatory requirements. Outside of client work, I compete in CTF competitions, tackling challenges in binary exploitation, reverse engineering, and web security. It's where I keep my technical edge sharp - heap exploitation, bypassing sanitizers, reversing custom VMs, whatever the challenge throws at me. I also do frelance works conducting testing for web applications, networks and infrastructure for businesses.

0

Years in Security

0

Projects Shipped

0

CTFs & Hackathons

0

ISO 27001 Controls Audited

Security Architecture

Security Domains

The areas I actively work in, from offense to governance.

Penetration Testing

Simulating real attacks against web apps, networks and infrastructure to surface exploitable weaknesses.

VAPT Recon Exploitation

Network Security

Designing segmented, firewalled network architectures and hardening routing and switching layers.

CCNA Firewalls Subnetting

Digital Forensics

Reconstructing incidents from artifacts, logs and memory to establish what happened and how.

Log Analysis Artifacts

Threat Detection

Building and tuning detection logic across SIEM pipelines to catch anomalous behaviour early.

Wazuh SIEM IDS

Web App Security

Enumerating and exploiting OWASP-class vulnerabilities across authentication, input handling and logic flaws.

OWASP Enumeration

Incident Response

Coordinating audit findings, gap analyses and remediation plans aligned to ISO 27001 and NEPSE formats.

ISO 27001 Audit

Selected Tools and Stack

Nmap Burp Suite Metasploit Wazuh Wireshark Docker Python Bash Evilginx Linux ISO Audit 27001

Narrative

Current Working On

Right now I'm splitting time between offensive engagements and formal compliance work - running VAPT against client web apps, firewalls and databases by day, and mapping vendor evidence to ISO 27001 Annex A controls for SEBON-licensed brokerage firms by the other half of the day. I'm using that overlap to get sharper at translating raw findings into remediation language that actually survives an audit committee, while keeping my CTF and independent research practice active on the side.

Interactive

Terminal

Type help to see what this thing can do.

ops@aayushng:~

Welcome to the terminal. Type help to get started.

guest@aayushng:~$

Technical Stack

Skills

Offensive

Penetration Testing / VAPT Web Exploitation Reverse Engineering Threat Simulation and ATT&CK Mapping

Defensive

SIEM & Threat Detection ISO 27001 Auditing Incident Response Network Packet Analysis

Tooling

Nmap / Burp / Metasploit Docker & Linux Wireshark / Packet Analysis Wazuh (SIEM and Monitoring)

Languages

Python Bash Scripting C / C++ Go

Hands-On Work

Experience

May 2026 — Present

IT Auditor

Himalayan Integrated Cloud Technologies

  • Conducting ISO 27001 Annex A compliance audits for SEBON-licensed brokerage firms, assessing all 93 controls against implemented policies, vendor agreements and IT infrastructure evidence.
  • Drafting formal audit observations, gap analyses and missing policy documents aligned with NEPSE-approved compliance formats.
  • Mapping vendor SLA and third-party evidence to relevant ISO 27001 controls and coordinating with client stakeholders to validate audit findings.

June 2025 — Present

Penetration Tester

Himalayan Integrated Cloud Technologies

  • Conducting Vulnerability Assessment and Penetration Testing (VAPT) on web applications, network infrastructure, firewalls, antivirus systems and databases.
  • Identifying security vulnerabilities and providing remediation recommendations.
  • Preparing detailed technical reports for clients and internal teams.

2024 — 2025

Community Speaker

TechX Softwarica

  • TechX Softwarica 2024 — presented a Wazuh SIEM and Evilginx phishing demonstration.
  • TechX Softwarica 2025 — demonstrated a custom C2 framework and a real-time CTF platform.

2024 — Present

CTF Player

Attack On Hash Function

  • My focus is on reverse engineering and PWN challenges.
  • Coordinate with team members to solve complex challenges.

Proof Of Work

Projects

[+] c2-framework.sh ACTIVE

Command & Control Framework

A lightweight C2 framework built to simulate remote command execution and study post-exploitation tradecraft in a controlled lab.

Python Sockets C2
[+] e-voting.html ACTIVE

Cryptography-Based E-Voting System

Secure voting platform using public-key cryptography and digital certificate validation to preserve ballot integrity and voter anonymity.

Cryptography PKI Web
[+] ids-monitor.py ACTIVE

Intrusion Detection System

Python-based IDS combining signature-based rules with anomaly detection to flag suspicious network behaviour in real time.

Python IDS Networking
[+] web-enum.py ACTIVE

Web Enumeration Tool

A scanning tool that enumerates web servers for exposed endpoints, misconfigurations and common vulnerability signatures.

Python Recon Web
[+] network-arch.yaml DOCS

Three-Tier Network Architecture

Designed a segmented three-tier secure network model with strict firewall rules and subnet isolation between zones.

CCNA Firewall Segmentation
[+] siem-lab.log LAB

Wazuh SIEM

Wazuh SIEM deployment for threat detection and response1. Full working implementation for both linux and windows.

Wazuh SIEM Defence
[+] MITRE_ATT&CK.pdf DOCS

MITRE_ATT&CK

Ajax Security Team (MITRE ATT&CK Group G0130) against a simulated corporate endpoint, executed inside a fully isolated virtual lab.

Red Team Simulation Offence
[+] syslog.md LAB

Custom Syslog Implementation

rsyslog with Grafana integration for real-time log analysis and visual dashboard, works for multiple platforms.

Blue Team Syslog Defence

Research Notes

Writeups

I document CTF solves and lab research as I go - box walkthroughs, exploitation chains and the odd rabbit hole into reverse engineering. All of it lives on a dedicated writeups page rather than cluttering this portfolio.

Browse Writeups

Recognition

Achievements

1st

Softwarica CTF Competition

Winner · 2024

2nd

Softwarica Hackfest

2nd Runner-Up · 2025

Link
1st

OWASP Nepal Cybersecurity Challenge

1st Runner-Up · 2025

Link
T10

IEEE LogPoint CTF, TU

Top 10 · 2025

Link
2nd

Pentester Nepal CTF Competition

2nd Place · 2025

Link
1st

HackAstra CTF, Herald College

1st Runner-Up · 2026

Link

Training

Certifications and Labs

CCNA 1: Introduction to Networks

Cisco Networking Academy · 2023

CCNA 2: Switching, Routing & Wireless Essentials

Cisco Networking Academy · 2024

Wazuh SIEM Fundamentals Lab

Self-directed lab · 2024

Practical VAPT Methodology

Himalayan Integrated Cloud Technologies · 2025

Certified Cybersecurity Educator Professional (CCEP)

Red Team Leaders · 2025

Link

APIsec Certified Practitioner

APIsec University · 2025

Link

Certified Red Team Analyst (CRTA)

CyberWarfare Labs · 2025

Academic Path

Education

BSc (Hons) Ethical Hacking and Cybersecurity

Softwarica College of IT and E-Commerce, Kathmandu

Cambridge A-Levels

Saipal Academy, Dhumbaharai, Kathmandu

Download

Resume

The full CV, in PDF, with everything on this page plus a few extra details.

Download Resume (PDF)