About Skills Experience Projects Certifications Labs Contact
Available for opportunities

Nabin
Tiwari

|

Computer Science student with a sharp focus on network infrastructure and cybersecurity — building secure, resilient systems through hands-on labs, Cisco training, and real-world ISP experience.

Nabin Tiwari
Available · Kathmandu, Nepal
CERTIFICATION
CCNA Certified
EXPERIENCE
ISP Intern · 6mo
FOCUS AREA
Cyber Security
NETWORKING
Wireshark · Snort
SCROLL

Building secure networks,
one packet at a time

I learn networks and security the same way I'd learn a language — by using them until they break, then figuring out why.

I'm a Computer Science student specializing in Network Technology & Cybersecurity, currently completing a technical support internship at an ISP, where I troubleshoot Layer 1–3 connectivity issues for real customers using OSI-model diagnostics.

Outside of work, I build what I want to understand better. I've deployed and hardened a Windows Server 2022 Active Directory environment from scratch (DHCP, GPOs, OU-based access control), and designed a segmented enterprise network lab — Core/Distribution/Access layers, VLANs, ACLs — protected by a custom-tuned Snort IDS and UFW firewall. To test whether any of it actually holds up, I ran a full five-phase penetration test against my own lab: reconnaissance and enumeration with Nmap and enum4linux, vulnerability validation with Nessus and OpenVAS, exploitation with Metasploit, and web application testing with Burp Suite and SQLMap — then wrote it up as a formal report with CVSS-prioritized findings and remediation steps.

Tools I work with regularly: Wireshark, Nmap, Burp Suite, Metasploit, Snort, SQLMap, Nessus, OpenVAS, Linux, and Windows Server/Active Directory.

I'm also building Security Playground, a full-stack cybersecurity learning platform — live, interactive SQL Injection and XSS labs with a backend-verified CTF flag system, built the way I learn best: by doing, not just reading.

I'm looking for SOC Analyst, Network Security, or Penetration Testing internships — remote or on-site. If your team needs someone who documents thoroughly and actually enjoys the reconnaissance phase, let's talk.

Cisco Certified Fortinet Trained ISP Experience Open to Roles
0+
Certifications
0mo
ISP Internship
0+
Lab Projects
0+
Tech Skills

Tools of the trade

A focused, hands-on skill set built through certifications, virtual labs, and real-world ISP troubleshooting.

TCP/IP & OSI Model90%
Subnetting & DHCP85%
VLANs & Inter-VLAN Routing80%
OSPF Basics70%
Routers & Switches82%
Network Troubleshooting88%
Snort IDS78%
Access Control Lists (ACLs)80%
UFW Firewall75%
Network Segmentation78%
NAT & Port Security74%
Threat & Log Analysis72%
Windows Server 202282%
Active Directory (AD DS)80%
Group Policy Objects76%
Linux Administration74%
User & Access Management80%
Wireshark82%
Nmap80%
VirtualBox / VMware85%
Cisco Packet Tracer84%

Where theory meets real traffic

OCT 2025 — MAR 2026
Technical Support Intern
Himalayan Online Service Pvt. Ltd. · Kathmandu, Nepal
  • Applied OSI model-based troubleshooting to isolate and resolve Layer 1–3 network connectivity issues for live ISP customers.
  • Assisted in configuring and maintaining routers and network devices to sustain stable internet connectivity across the service area.
  • Monitored network performance using diagnostic tools to proactively detect faults and service disruptions before they escalated.
  • Collaborated with engineering teams to support ISP operations and ensure timely resolution of customer-reported network issues.

Built in the lab, proven in the packet

Hands-on virtual environments where every concept gets tested, broken, and fixed.

🖥️
Windows Server Active Directory GPO VirtualBox
Windows Server 2022 AD Infrastructure
Deployed a full enterprise-grade Active Directory environment in a virtual sandbox. Structured role-based access with OUs, security groups, and least-privilege policies. Provisioned DHCP and enforced security baselines via custom GPOs.
🛡️
Snort IDS UFW Linux Attack Simulation
Network Security Monitoring Lab
Deployed Snort IDS to detect scanning attempts and attack patterns in real time. Authored custom detection rules, configured UFW to manage inbound/outbound traffic, and ran attack simulations to study system response and alert behavior.
🐧
Linux Ubuntu SSH Syslog
Linux System Administration & Security Lab
Managed Linux users and groups with useradd/usermod/passwd. Enforced file permissions and ownership via chmod and chown. Monitored auth.log and syslog for login attempts and user activity. Configured Ubuntu VM with SSH for remote administration.
🎯
Nmap Metasploit Burp Suite SQLMap Snort
Enterprise Network Security Assessment
Executed an end-to-end penetration test against a simulated Windows/Linux enterprise network — reconnaissance, vulnerability assessment, exploitation, web application testing, and detection/evasion. Mapped the attack surface with Nmap, enum4linux, SNMP, and WhatWeb; validated findings from Nessus, OpenVAS, and Nikto against CVE/CVSS scores; gained initial access and escalated privileges with Metasploit and Linux privesc techniques; exploited SQL injection, IDOR, and session flaws with Burp Suite and SQLMap; then wrote custom Snort IDS rules, evaluated firewall evasion, deployed a honeypot, and delivered a professional pentest report with remediation guidance.
🔬
Wireshark Nmap VLANs ACLs
Network Design & Analysis Lab
Designed a layered topology (Core/Distribution/Access) with VLAN segmentation and ACL enforcement. Used Wireshark to capture and dissect packets, and Nmap to surface vulnerabilities and validate security posture across the virtual network.
🕹️
Node.js Express.js SQLi / XSS CTF Engine
Security Playground — Cybersecurity Learning & CTF Platform
May 2026 – Present · Lincoln University College
A full-stack cybersecurity learning platform offering interactive web security labs and CTF challenges with backend-verified flag validation. Includes real vulnerable web apps for SQL Injection and XSS practice, a flag system that blocks source-code cheating by storing and checking flags server-side, and session-based progress tracking with an XP system. Built and deployed using an AI-assisted development workflow, pairing security knowledge with modern tooling to ship a working platform quickly.

Credentials that carry weight

🔗
CCNA: Switching, Routing & Wireless Essentials
Cisco Networking Academy
01 Jan 2026
View Certificate
🌐
CCNA: Introduction to Networks
Cisco Networking Academy
24 Jun 2025
View Certificate
🛡️
Introduction to the Threat Landscape 3.0
Fortinet
2026
🔐
Introduction to Cyber Security
Simplilearn
11 Jan 2026
View Certificate
☁️
Trust and Security with Google Cloud
Simplilearn SkillUp
21 Feb 2026
IAM Encryption GCP Security
View Certificate
🛡️
Digital Security Fundamentals
Simplilearn
21 Feb 2026
Risk Mgmt Data Protection
View Certificate

Where skills get battle-tested

Real-world hacking labs, CTF challenges, and security research platforms — learning by doing, not just reading.

🎯
TryHackMe
tryhackme.com
Active
Completed guided CTF rooms including Vulnversity (file upload exploitation), Nmap scanning, SQL Injection basics, and Burp Suite web interception — each room building practical offensive and defensive awareness.
Vulnversity Nmap SQL Injection Burp Suite
Open Platform →
🕷️
PortSwigger Web Security Academy
portswigger.net/web-security
Active
Practicing structured web application security labs covering OWASP Top 10 vulnerabilities — XSS, SQLi, SSRF, IDOR, authentication bypass — using Burp Suite as the primary testing proxy.
XSS SQLi SSRF Auth Bypass
Open Platform →
⚔️
Hackviser
hackviser.com
Exploring
Exploring guided hacking simulations and security challenges focused on penetration testing workflows, network exploitation, and vulnerability assessment techniques.
Pen Testing Vuln Assessment
Open Platform →
📖
HackTricks Wiki
hacktricks.wiki
Reference
Using HackTricks as a primary pentesting knowledge base — covering privilege escalation, Active Directory attacks, network pivoting, and CTF methodologies for structured, real-world attack research.
Priv Escalation AD Attacks Pivoting CTF Reference
Open Wiki →
🧃
OWASP Juice Shop
juice-shop.herokuapp.com
Active
Practicing against OWASP's intentionally vulnerable web application — hunting for hidden flags across XSS, broken auth, insecure deserialization, and improper input validation vulnerabilities in a safe sandbox.
OWASP Top 10 Web Security CTF Flags
Open Lab →

The foundation

Bachelor's in Computer Science
Cyber Security & Networking Technology
Texas College of Management & IT
Kathmandu, Nepal · Expected 2028
Higher Secondary Education (+2)
Science
Texas International College
Kathmandu, Nepal · Mar 2022 – Jun 2024
Secondary Education (SEE)
General
Samata Shiksha Niketan
Kathmandu, Nepal · May 2015 – Apr 2021

Let's build something secure

Whether you're looking for a network intern, a lab partner, or just want to talk shop about Cisco, Snort, or packet analysis — I'm always up for a conversation.