I break things so they can't be broken in the wild. As a Penetration Tester at Biz Serve IT Pvt. Ltd., Lalitpur, I assess web applications, mobile apps, and APIs — uncovering vulnerabilities, validating real-world impact, and helping teams ship more secure software.
Offensive security services focused on finding what attackers would — before they do.
End-to-end testing of web applications against OWASP Top 10 — auth flaws, IDOR, injection, SSRF, access control, and business-logic abuse.
Android app assessments following MASVS/MASTG — static & dynamic analysis, insecure storage, IPC abuse, and runtime instrumentation with Frida.
REST/GraphQL API assessments — broken object-level authorization, mass assignment, rate-limit bypass, and token/JWT weaknesses.
Vulnerability research and responsible disclosure — reconnaissance, exploit development, and clear, reproducible impact-driven reports.
The tools and techniques I reach for across an engagement.
Biz Serve IT Pvt. Ltd., Lalitpur — Performing security assessments of web, mobile, and API targets; identifying, exploiting, and reporting vulnerabilities with actionable remediation guidance.
Vulnerability research and bug bounty hunting — reconnaissance, exploitation, and responsible disclosure of real-world security issues.
St. Xavier's College, Maitighar, Kathmandu — Completed.
IOE Pulchowk Engineering Campus — Representing and promoting one of Nepal's largest tech events.
St. Xavier's College — Collaborating on technology and security initiatives.
eLearnSecurity Junior Penetration Tester — INE Security
Certified Red Team Analyst — CyberWarFare Labs
TryHackMe — Penetration Testing Pathway
Where I spend my time digging — and where you'll find my write-ups and tooling.
Hunting access-control flaws, injection, SSRF and business-logic bugs across modern web stacks.
View on GitHubReverse engineering and runtime analysis of Android apps — bypasses, insecure storage, and IPC abuse via MASTG methodology.
View on GitHubDocumenting vulnerability research, methodology, and proof-of-concepts for the security community.
View on GitHubHave an app or system that needs testing, or a security question? Drop me a message.