Web Application Security
VAPT-focused testing of modern web applications, HTTP flows, authentication, authorization and common OWASP vulnerability classes.
I'm Kushal Khatri — a recently +2 completed student, trained in Cybersecurity & Ethical Hacking at Saarathi Academy and continuously building practical skills through self-learning, labs, websites, documentation and videos.

I am a recently +2 completed student focused on starting my journey in cybersecurity. I completed Cybersecurity & Ethical Hacking training from Saarathi Academy and have continued developing my skills independently through online resources, technical websites, documentation, labs and video-based learning.
I like to learn by doing: understand the concept, build or use a controlled lab, test the behavior, troubleshoot what breaks, document the result and then repeat it. Remote/self-directed learning has strengthened my research and problem-solving ability.
My main interests are Web/API VAPT, security testing, network reconnaissance, Linux security and security automation. I want to keep building real evidence-based projects and grow toward professional cybersecurity roles.

Cybersecurity is more than tools and commands. I'm building a practical identity around curiosity, disciplined testing and a habit of turning what I learn into visible work.
A practical stack built around vulnerability assessment, penetration testing, network analysis, Linux security and automation.
VAPT-focused testing of modern web applications, HTTP flows, authentication, authorization and common OWASP vulnerability classes.
REST API assessment, endpoint enumeration, authorization testing, JWT analysis and business-logic security.
Disciplined reconnaissance, service enumeration, attack-surface mapping and packet-level validation.
Linux logs, audit evidence, persistence review, SSH exposure, file-integrity concepts and security hardening.
Manual validation first, evidence capture, false-positive triage, severity assessment and responsible reporting.
Small Python and Bash utilities for reconnaissance, API probing, log triage and repetitive security workflows.
These are the project directions designed for my portfolio. Each one can grow into a full write-up with scope, methodology, evidence, impact and remediation.
A portfolio-ready assessment covering reconnaissance, Burp Suite testing, authentication, access control, injection classes, security headers, evidence and remediation.
Structured API testing covering endpoint discovery, OpenAPI review, authorization, BOLA/BFLA, JWT behavior, rate limiting and Python-assisted testing.
A controlled lab project using Nmap and Wireshark to enumerate services, validate traffic, inspect TLS/SSH exposure and document findings.
Host-review workflow using logs, audit evidence, persistence checks, integrity baselines and security-hardening recommendations.
Recently completed +2 and now focusing on building a technical career in cybersecurity.
Training focused on networking, reconnaissance, Linux and host foundations, web/API VAPT, security tooling, reporting and career readiness.
Continuing to learn through cybersecurity websites, documentation, videos, labs, technical articles and hands-on practice. This is where I expand beyond the structured classroom path and keep improving independently.
Understand the target, authorization and rules before testing.
Map the attack surface and identify useful entry points.
Reproduce findings and separate real issues from noise.
Explain evidence, impact, severity and practical remediation.
All security testing presented here is intended for authorized labs, owned systems or explicitly approved scopes.