$ whoami

Sabin Sharma
Security Researcher.

I'm currently

BCA graduate from Biratnagar, Nepal, focused on offensive security, ICS/OT, and the policy side of cybersecurity. I learn by building labs, breaking things safely, and writing it all down.

$ cat about.md

About

Where technical practice meets policy research.

Sabin Sharma

Information Security Graduate & Cybersecurity Researcher

I hold a Bachelor of Computer Applications and am a cybersecurity practitioner focused on offensive security, ICS/OT and critical-infrastructure security, and security tool development. I've completed a 100+ consecutive day streak on TryHackMe (top 2% globally) alongside a Diploma in Cybersecurity covering offensive/defensive security, digital forensics, GRC, cloud, Zero Trust, and AI/LLM security.

My work spans merged security tooling contributions to established open-source projects, a supervised final-year hydropower ICS/OT research project, and an independently authored policy research paper on Nepal's cybersecurity governance and its implications for foreign policy formation. I'm seeking graduate study in cybersecurity and assurance, with a research interest in quantifying risk in cyber-physical and critical-infrastructure systems.

LocationBiratnagar, Nepal
DegreeBCA Completed (2022–2026)
Available forGrad Study, Work & Freelance
Phone+977 9742270999
Web App Security Reconnaissance & OSINT Privilege Escalation Vulnerability Reporting ICS/OT & Critical Infrastructure
$ ls ./skills

Skills

Tools, techniques, and domains built through labs, CTFs, and hands-on testing.

Web Application Security
SQL Injection XSS (Reflected / Stored / DOM) IDOR CSRF Command Injection Auth Bypass Broken Access Control OWASP Top 10
Exploitation & Post-Exploitation
Metasploit Framework Reverse Shells Payload Delivery Privilege Escalation Shell Stabilisation
Cryptography & CTF
XOR / Known-Plaintext RSA (RsaCtfTool) Vigenère / Caesar LFSR Stream Ciphers pwntools
Reconnaissance & OSINT
Nmap Gobuster ffuf Sublist3r Nikto theHarvester
Password Attacks
Hashcat Hydra John the Ripper CeWL Wordlist Crafting
SIEM, Threat Intel & ICS/OT
Wazuh SIEM IOC Analysis Threat Intelligence ICS/OT & Modbus TCP tcpdump
GRC & Frameworks
GRC / Zero Trust Digital Forensics AI/LLM Security PTES MITRE ATT&CK OSSTMM & WSTG
Tools & Environment
Burp Suite Pro Kali Linux Python Bash Git & GitHub Wireshark
Documentation
Vulnerability Reports CVSS Scoring Risk Prioritisation
$ cat resume.pdf

Education & Experience

Academic background, professional experience, and recognitions.

Education

Bachelor of Computer Applications (BCA)

Nihareeka College of IT & Management, Biratnagar · 2022 – 2026

Cumulative GPA 3.55/4.00 (≈88.75%; ECTS Grade A) across eight semesters. Coursework in operating systems, computer networks, database systems, information security, and algorithms & data structures. Final-year research paper on Nepal's cybersecurity governance and its impact on the Ministry of Foreign Affairs' digital foreign policy capacity.

Diploma in Cybersecurity

SkillSikshya, Kathmandu · 2025 – 2026

Offensive/defensive security, digital forensics, SOC, GRC, cloud, Zero Trust, cryptography, and AI/LLM security.

High School — Science (Computer Science)

Xavier International College, Kathmandu, Nepal
Certifications & Achievements

Jr Penetration Tester Path — Completed

TryHackMe

Hackathon Certification

HackAstra · Ranked 92 of 455 teams

Certificate of Participation

Koshi Mini Yantra Project Demonstration 01 & 02
Professional Experience

Cybersecurity Intern

Pigeon Advertising, Biratnagar · Jun – Dec 2025
  • Conducted security assessments of two production websites (www.hamrobiratnagar.com and the company's own site www.cloudadvertising.com.np).
  • Identified and reported findings to support remediation.

Python & Cybersecurity Trainer

Nihareeka College of IT & Management · 2023, 2025
  • Delivered 150 hours of instructor-led training: 60 hours of Python programming (Jan 2023) and 90 hours of cybersecurity (Aug–Sep 2025).
  • Adapted explanations to different learning levels for junior students.
Research & Self-Directed Training

Hydropower ICS/OT Cybersecurity Simulation

Final-Year Research Project (Supervised) · Aug 2026

Simulated a hydropower ICS/OT environment under academic supervision, modelling attacker manipulation of physical control processes over Modbus TCP and evaluating intrusion-detection response to connect offensive scenarios with defensive monitoring.

Cybersecurity Governance & Foreign Policy Formation in Nepal

Independent Research Paper (Unpublished) · 2026

Authored an independent 18 page policy research paper analyzing Nepal's cybersecurity governance failures as a foreign policy formation problem, using structured comparative institutional analysis against Rwanda, Bangladesh, and Estonia. Combined policy document review (Electronic Transactions Act, National Cyber Security Policy 2023, draft IT and Cybersecurity Bill 2082), incident documentation analysis, and cross country institutional comparison to produce a tiered policy reform framework.

TryHackMe — Jr Penetration Tester Path

100+ consecutive day learning streak, ranked top 2% of TryHackMe users globally. Reconnaissance, enumeration, web security testing, exploitation, privilege escalation, and Active Directory fundamentals 40+ published write-ups.

PortSwigger Web Security Academy

Structured labs covering OWASP Top 10 vulnerability classes and manual exploitation techniques.

Open Source Contributions (Merged)

kaifcodec/user-scanner (Python OSINT suite, 3.3k+ stars) added a TryHackMe platform validator module with bot-mitigation handling.
ProjectDiscovery/httpx (HTTP toolkit, 10k+ stars) fixed a CPE version-detection bug from mismatched vendor-dataset naming.

$ ls ./projects

Projects

Research, security tools, and software I've built or contributed to source and details live on GitHub.

ICS/OT · Modbus TCP · Intrusion Detection

Hydropower ICS/OT Cybersecurity Simulation

Supervised final-year research project simulating a hydropower ICS/OT environment modelling attacker manipulation of physical control processes over Modbus TCP and evaluating intrusion-detection response.

Python · FastAPI · Celery · PostgreSQL · Ollama (LLM) · ClamAV · React · Docker

PhishGuard : Self-Hosted Phishing Detection Pipeline

7-layer phishing detection engine with a locally-hosted LLM as final verdict SPF/DMARC checks, homograph detection, and real malware scanning. Fully on prem, nothing ever leaves the host machine.

Python

Sentinel — Automated Security Scanner

Automated web-application security-testing tool supporting multiple vulnerability-testing techniques and payload-based checks, built as a reusable workflow rather than a single-payload checker.

Java · Burp Suite Montoya API · Swing

Burp Suite Custom Intruder Payload Generator

Burp Suite extension generating epoch-timestamp and leetspeak-mutated payload sets for bug-bounty/CTF workflows, with a thread-safe engine and Swing configuration UI.

Wazuh · SIEM · Threat Intelligence

Security Monitoring & Threat Detection Lab

Wazuh SIEM lab across Windows/Linux hosts — performed controlled security testing, investigated evidence, analyzed IOCs, and produced a risk assessment with defensive recommendations.

Python · SQLite · PyQt5

Gurukul Academy Management System

Desktop management system for a tuition centre in Biratnagar — Bikram Sambat date handling, Excel attendance import, PDF receipt generation, and Windows deployment via PyInstaller.

More repositories on GitHub

New tools, scripts, and CTF solutions get pushed to GitHub first — that's the best place to see what I'm currently building.

Browse all repos
$ tail -f writeups.log

Write-ups

Lab documentation and CTF walkthroughs, published and maintained on GitHub.

All write-ups are published on GitHub

Each entry below links out to the full walkthrough — screenshots, commands, and remediation notes included.

Open GitHub
TryHackMePriv Esc

Domino

Write-up covering enumeration through to root, chaining a web foothold into a full privilege escalation.

Read write up
SQLiCmd Injection

Silent Monitor

SQL injection auth bypass, command injection on a health-check endpoint, credential reuse, and a kernel exploit to root.

Read write-up
SQLiSudo Misconfig

Operation Promotion

Admin SQLi to RCE via a ping diagnostic, password cracking with mutation rules, and root through a sudo/find misconfiguration.

Read write-up
$ cat services.md

Services

What I can help with, based on practical experience in offensive security testing.

Web App Penetration Testing

Manual and automated testing for OWASP Top 10 vulnerabilities SQLi, XSS, IDOR, and authentication flaws.

Reconnaissance & OSINT

Active and passive information gathering using Nmap, Sublist3r, theHarvester, and custom OSINT workflows.

Vulnerability Reporting

Clear, professional reports with CVSS scoring, proof of concept steps, and prioritised remediation guidance.

$ ./contact --init

Contact

Open to internships, freelance work, collaborations, and CTF team invitations.

Location

Biratnagar, Morang, Nepal

Phone

+977 9742270999