Connect →
RED TEAM // ACTIVE RECON

Investigating
Web Security

Hands-on security researcher and ethical hacker from Nepal. Exploring web application vulnerabilities, network protocols, defensive architecture, and automated threat intelligence.

6+
REPOSITORIES
3
LAB PLATFORMS
100%
ETHICAL SCOPE
NEPAL
ORIGIN // 0x07
TECHNICAL CAPABILITIES

Specialized Security Arsenal

Rigorous, self-directed exploration across web security vulnerabilities, protocol auditing, and Linux environments.

Web Application Security

OWASP Top 10 & Input Sanitation

Intercepting and manipulating HTTP traffic with Burp Suite. Dissecting SQL Injections, Cross-Site Scripting (XSS), CSRF tokens, and bypassing broken access controls ethically in laboratory sandboxes.

BURP SUITE SQLI XSS OWASP TOP 10 HTTP/2

Network Auditing & Recon

Port Scanning & Protocol Analysis

Mastering TCP/IP packet exchange, OSI layer behavior, Wireshark packet capture analysis, DNS records, and raw socket banner grabbing with Nmap stealth scans.

NMAP WIRESHARK TCP/IP DNS / WHOIS RAW SOCKETS

Linux Internals & Hardening

Operating System Security

Fluency in the Linux CLI across Debian/Kali distributions. Investigating SUID privileges, file permission matrices, systemd service management, and authentication log audits.

KALI LINUX BASH SUID / PERMISSIONS LOG FORENSICS SSH HARDENING

Security Automation

Python 3 & Shell Tooling

Developing lightweight, modular scripts for automated security sweeps: calculating hash baselines across directories, parsing auth logs for bruteforce attempts, and API integrations.

PYTHON 3 REGEX HASHING JSON APIS GIT CLI
INTERACTIVE CLI SANDBOX // 0x02

Command Line Telemetry Shell

Simulated security shell. Type commands below or click quick-run chips to inspect open ports, skills, or resume data.

root@sohankharel:~ (bash v5.2)
status: interactive
Quick Run:
=============================================================== SOHAN KHAREL // CYBERSECURITY RESEARCH TELEMETRY SHELL =============================================================== Type 'help' for a list of available commands or click the chips above. Try 'nmap sohankharel.sys', 'skills', or 'resume'.
root@sohan:~$
root@sohankharel:~/projects
integrated_sources.sh
$ cat featured_repositories.txt
FEATURED REPO TYPESCRIPT

sohankharelwebsite

Personal cybersecurity portfolio engineered with modern TypeScript and responsive UI. Integrates 2D atmospheric clouds, network graphs, and real-time telemetry.

TYPESCRIPT HTML5 CANVAS 2D
PORTFOLIO CODEBASE CSS3 / JS

sohankharel

Offensive security research repository and cyber platform layout with status telemetry and architectural minimalism.

VANILLA JS CSS GRID RESPONSIVE
SECURITY HUB RESEARCH

sohankharel01 Research Hub

Central offensive security repository containing documented Burp Suite methodologies, Kali Linux configurations, and vulnerability research.

BURP SUITE KALI LINUX METHODOLOGY
$ ./show_detailed_sources.sh --all
AUDIT TOOL PYTHON

Nmap Network Scanner

Python-based network scanner and port enumerator using raw socket programming to discover live hosts, open ports, and service banners.

PYTHON RAW SOCKETS NMAP CLI
AUTOMATION BASH / PY

Security Automation Scripts

Modular suite of scripts designed to automate repetitive security tasks: parsing authentication logs, calculating SHA256 hashes, and ping sweeps.

BASH AUTOMATION INCIDENT RESPONSE
SANDBOX LABS CTF NOTES

Web Security Labs & CTFs

Hands-on web security exercises completed across intentional vulnerable practice labs. Parameter tampering, SQLi payloads, and XSS defensive bypasses.

CTFS PORT SWIGGER THM ROOMS
$
CREDENTIALS & LABS

Verified Certifications & Training

Structured learning paths and practical platforms validating hands-on security capability.

root@sohan:~/pre-sec
VERIFIED

Pre-Security Path

TryHackMe Learning Credential

  • Network Fundamentals & TCP/IP
  • OSI Model & Packet Routing
  • Linux & Windows Hierarchy
  • Web Architecture & DNS
Verify Credential →
root@sohan:~/portswigger
PRACTITIONER

Web Security Academy

PortSwigger Hands-on Practice

  • SQL Injection Exploitation Labs
  • Stored & Reflected XSS Vectors
  • Broken Authentication Defenses
  • Burp Suite Professional Intercept
Academy Profile →
root@sohan:~/security+
IN TRAINING

Security+ (SY0-701)

CompTIA / Cisco NetAcad

  • Threats, Attacks & Vulnerabilities
  • Architecture & Defense-in-Depth
  • Identity, Access & Cryptography
  • Risk Management & Incident Audits
Certification Roadmap →
root@sohankharel:~/contact/connect.sh
status: online

Ready to connect or investigate?

Open to internships, defensive security collaborations, study groups, and bug bounty discussions.

$