Sabin Sharma
Security Researcher.
BCA graduate from Biratnagar, Nepal, focused on offensive security, ICS/OT, and the policy side of cybersecurity. I learn by building labs, breaking things safely, and writing it all down.
About
Where technical practice meets policy research.
Information Security Graduate & Cybersecurity Researcher
I hold a Bachelor of Computer Applications and am a cybersecurity practitioner focused on offensive security, ICS/OT and critical-infrastructure security, and security tool development. I've completed a 100+ consecutive day streak on TryHackMe (top 2% globally) alongside a Diploma in Cybersecurity covering offensive/defensive security, digital forensics, GRC, cloud, Zero Trust, and AI/LLM security.
My work spans merged security tooling contributions to established open-source projects, a supervised final-year hydropower ICS/OT research project, and an independently authored policy research paper on Nepal's cybersecurity governance and its implications for foreign policy formation. I'm seeking graduate study in cybersecurity and assurance, with a research interest in quantifying risk in cyber-physical and critical-infrastructure systems.
Skills
Tools, techniques, and domains built through labs, CTFs, and hands-on testing.
Web Application Security
Exploitation & Post-Exploitation
Cryptography & CTF
Reconnaissance & OSINT
Password Attacks
SIEM, Threat Intel & ICS/OT
GRC & Frameworks
Tools & Environment
Documentation
Education & Experience
Academic background, professional experience, and recognitions.
Bachelor of Computer Applications (BCA)
Cumulative GPA 3.55/4.00 (≈88.75%; ECTS Grade A) across eight semesters. Coursework in operating systems, computer networks, database systems, information security, and algorithms & data structures. Final-year research paper on Nepal's cybersecurity governance and its impact on the Ministry of Foreign Affairs' digital foreign policy capacity.
Diploma in Cybersecurity
Offensive/defensive security, digital forensics, SOC, GRC, cloud, Zero Trust, cryptography, and AI/LLM security.
High School — Science (Computer Science)
Jr Penetration Tester Path — Completed
Hackathon Certification
Certificate of Participation
Cybersecurity Intern
- Conducted security assessments of two production websites (www.hamrobiratnagar.com and the company's own site www.cloudadvertising.com.np).
- Identified and reported findings to support remediation.
Python & Cybersecurity Trainer
- Delivered 150 hours of instructor-led training: 60 hours of Python programming (Jan 2023) and 90 hours of cybersecurity (Aug–Sep 2025).
- Adapted explanations to different learning levels for junior students.
Hydropower ICS/OT Cybersecurity Simulation
Simulated a hydropower ICS/OT environment under academic supervision, modelling attacker manipulation of physical control processes over Modbus TCP and evaluating intrusion-detection response to connect offensive scenarios with defensive monitoring.
Cybersecurity Governance & Foreign Policy Formation in Nepal
Authored an independent 18 page policy research paper analyzing Nepal's cybersecurity governance failures as a foreign policy formation problem, using structured comparative institutional analysis against Rwanda, Bangladesh, and Estonia. Combined policy document review (Electronic Transactions Act, National Cyber Security Policy 2023, draft IT and Cybersecurity Bill 2082), incident documentation analysis, and cross country institutional comparison to produce a tiered policy reform framework.
TryHackMe — Jr Penetration Tester Path
100+ consecutive day learning streak, ranked top 2% of TryHackMe users globally. Reconnaissance, enumeration, web security testing, exploitation, privilege escalation, and Active Directory fundamentals 40+ published write-ups.
PortSwigger Web Security Academy
Structured labs covering OWASP Top 10 vulnerability classes and manual exploitation techniques.
Open Source Contributions (Merged)
kaifcodec/user-scanner (Python OSINT
suite, 3.3k+ stars) added a TryHackMe platform validator
module with bot-mitigation handling.
ProjectDiscovery/httpx (HTTP toolkit, 10k+
stars) fixed a CPE version-detection bug from mismatched
vendor-dataset naming.
Projects
Research, security tools, and software I've built or contributed to source and details live on GitHub.
Nepal Cybersecurity Governance & Foreign Policy Capacity
Independent 18-page policy research paper analyzing Nepal's cybersecurity governance failures as a foreign policy formation problem, using comparative institutional analysis against Rwanda, Bangladesh, and Estonia to produce a tiered policy reform framework for the Ministry of Foreign Affairs' digital foreign policy capacity.
Hydropower ICS/OT Cybersecurity Simulation
Supervised final-year research project simulating a hydropower ICS/OT environment modelling attacker manipulation of physical control processes over Modbus TCP and evaluating intrusion-detection response.
PhishGuard : Self-Hosted Phishing Detection Pipeline
7-layer phishing detection engine with a locally-hosted LLM as final verdict SPF/DMARC checks, homograph detection, and real malware scanning. Fully on prem, nothing ever leaves the host machine.
Sentinel — Automated Security Scanner
Automated web-application security-testing tool supporting multiple vulnerability-testing techniques and payload-based checks, built as a reusable workflow rather than a single-payload checker.
Burp Suite Custom Intruder Payload Generator
Burp Suite extension generating epoch-timestamp and leetspeak-mutated payload sets for bug-bounty/CTF workflows, with a thread-safe engine and Swing configuration UI.
Security Monitoring & Threat Detection Lab
Wazuh SIEM lab across Windows/Linux hosts — performed controlled security testing, investigated evidence, analyzed IOCs, and produced a risk assessment with defensive recommendations.
Gurukul Academy Management System
Desktop management system for a tuition centre in Biratnagar — Bikram Sambat date handling, Excel attendance import, PDF receipt generation, and Windows deployment via PyInstaller.
New tools, scripts, and CTF solutions get pushed to GitHub first — that's the best place to see what I'm currently building.
Write-ups
Lab documentation and CTF walkthroughs, published and maintained on GitHub.
Domino
Write-up covering enumeration through to root, chaining a web foothold into a full privilege escalation.
Read write upSilent Monitor
SQL injection auth bypass, command injection on a health-check endpoint, credential reuse, and a kernel exploit to root.
Read write-upOperation Promotion
Admin SQLi to RCE via a ping diagnostic, password cracking with mutation rules, and root through a sudo/find misconfiguration.
Read write-upServices
What I can help with, based on practical experience in offensive security testing.
Web App Penetration Testing
Manual and automated testing for OWASP Top 10 vulnerabilities SQLi, XSS, IDOR, and authentication flaws.
Reconnaissance & OSINT
Active and passive information gathering using Nmap, Sublist3r, theHarvester, and custom OSINT workflows.
Vulnerability Reporting
Clear, professional reports with CVSS scoring, proof of concept steps, and prioritised remediation guidance.
Contact
Open to internships, freelance work, collaborations, and CTF team invitations.
Location
Biratnagar, Morang, Nepal
Phone
+977 9742270999