Hands-on cybersecurity work spanning web application penetration testing, malware and incident analysis, and risk-based security advisory. My focus is the bridge between technical findings and the controls, risk, and recommendations that security, audit, and advisory teams act on.
All assessments in this repository were performed in authorized, isolated lab environments for academic coursework. No production or third-party systems were involved.
| Project | Summary |
|---|---|
| Security Findings — Control & Risk Mapping | Findings from the projects below mapped to ISO/IEC 27001:2022, OWASP Top 10:2025, and NIST CSF 2.0, with business risk and control-level recommendations. |
| Stored XSS — Support Ticket System | Stored cross-site scripting exploited into an authenticated content-exfiltration chain that defeated HttpOnly cookies. (Critical, CVSS 8.6) |
| SQL Injection — SecureBank Portal | UNION-based SQL injection on an internal API achieving full database read access. (Critical, CVSS 9.8) |
| Ransomware Incident Analysis — CryptoLocker | Static analysis of a ransomware sample with indicators of compromise and containment/recovery recommendations. |
- Testing: web application penetration testing, vulnerability assessment & reporting, malware / static analysis, OSINT
- Frameworks: ISO/IEC 27001:2022, OWASP Top 10:2025 & ASVS, NIST CSF 2.0
- Tools: Burp Suite, Nmap, Wireshark, Metasploit, Kali Linux, VirusTotal, capa
- LinkedIn: linkedin.com/in/pasin-visuttipinate
- TryHackMe: tryhackme.com/p/AvonS10
- Email: pasin.visuttipinate@gmail.com