ACCESS GRANTED
OPEN TO WORK · --:--:-- IST
X 0.000 · Y 0.000
SCAN 000% · MODE: IDENTITY
⚠ INTRUSION DETECTED

NISHANTVERMA

The anatomy of a cybersecurity expert
>
SUBJECTN. VERMA
CLASSCYBERSECURITY EXPERT
BACKGROUND8+ YRS WEB DEV
CURRENT OP█████████
LOCATIONNEW DELHI, IN
COORDS28.61°N 77.21°E
THREAT LEVELFRIENDLY
SCROLL TO SCAN
A study in five layers

The Anatomy of a
Cybersecurity Expert

scroll to assemble ↓
01 · The Foundation

Built on eight
years of code

100+ production websites taught me how the web is put together, and exactly where it comes apart.

Frontend · 2016 → now
02 · The Recon Layer

Sees what
others miss

Passive and active reconnaissance, OSINT and enumeration: mapping the attack surface before touching a single port.

Shodan · Maltego · Nmap
03 · The Armor

Hardened from
the inside

Vulnerability assessment and web application security, applied with a developer's instinct for what actually ships.

BIA certified · 2025
04 · The Arsenal

Tools of
the trade

Nmap, Metasploit, Wireshark, Shodan, Maltego and Nessus/OpenVAS, used hands-on rather than just listed.

Six tools · one method
05 · The Detail

Every byte,
inspected

The difference lives in the last quarter-inch: a header, a config, the one forgotten endpoint.

Attention to detail
The Anatomy00 / 05
OPEN TO WORK✦PENETRATION TESTING✦WEB APP SECURITY✦OSINT & RECON✦CYBERSECURITY✦SOMETHING IS BEING BUILT✦
02 — whoami

I built the web. Now I secure it.

bash — 80×24
0years building the web
0production sites shipped
0security tools in my kit
2016Web dev intern
2016–17Frontend · Adaan
2017 →Frontend · Lebro
2025Cybersecurity · BIA
2026████████
03 — methodology

How I work

01 phase/recon

Map it before you touch it

Passive recon and OSINT first: what's already public about a target, from domains and tech stack to people and exposed services. The quietest phase is often the most revealing.

$ shodan host lab.target
  ports    22, 80, 443, 3306
  server   nginx · php
  [!] database port reachable from the internet
// Shodan · Maltego · OSINT
02 phase/scan

Find every open door

Network scanning to map live hosts, open ports and running services, so nothing in scope is left unknown.

$ nmap -sV 10.0.0.0/24
  22/tcp   open  ssh     OpenSSH
  80/tcp   open  http    nginx
  8080/tcp open  http    admin panel  ← why is this exposed?
// Nmap · Zenmap
03 phase/enumerate

Read it like the developer who built it

Service enumeration and vulnerability scanning, plus the part most testers skip: reading client-side code, configs and headers with 8+ years of builder's instinct.

[!] outdated component in bundle
[!] missing security headers
[!] stack traces on error pages
// Nessus · OpenVAS · DevTools
04 phase/exploit

Prove it, carefully

Validate findings inside scope, with evidence and without collateral damage, and watch the traffic while doing it.

msf6 > check
[+] target appears vulnerable
[*] proof captured · no damage done
// Metasploit · Wireshark
05 phase/report

Make it fixable

Clear findings, real impact and fixes developers can actually ship. I've been the developer on the receiving end of a report, so I write the one I'd want to get.

$ cat report.md | head -3
  critical  2   fixes included
  medium    5   fixes included
  status    ready for the dev team
// clear writing · developer empathy
04 — selected work

Proof, not promises

WORK #01STATUS: COMPLETE
RECON

Reconnaissance engagement

Capstone project · Boston Institute of Analytics · 2025
  • End-to-end recon study covering passive and active recon, OSINT, scanning, service enumeration and packet analysis
  • Tool chain: Nmap/Zenmap, Shodan, Maltego, Wireshark, Nessus/OpenVAS, Metasploit
  • Also covered post-exploitation, and the ethics of doing this for real
// full write-up available on request
WORK #02STATUS: SHIPPING
100+

Production websites

Lebro Learning · Adaan Digital · 2016 → now
  • Designed, built and maintained 100+ responsive sites for real clients
  • Led a development team and owned quality and secure coding standards
  • Years of debugging live sites gave me a map of exactly where web apps break
★ Best Employee of the Month
WORK #03STATUS: LIVE
THIS

This website

Three.js · hand-written GLSL · GSAP
  • An illustrated portrait given real depth by an AI depth map: it turns to follow your cursor, blinks, then dissolves into 30k particles that morph as you scroll
  • Hand-written relief, blink and dissolve shaders, cursor-reactive type and a real shell. Click my face, by the way.
  • There's a flag hidden somewhere in here. Recon skills welcome.
// view-source: encouraged
CLASSIFIED
WORK #04STATUS: IN DEVELOPMENT
2026

Project ████████

Security tooling · ██████████
  • I'm building a security tool of my own. That's all I can say for now.
  • Clearance level required: ███████
// declassification pending
WORK #05STATUS: PENDING
NEXT

Your team?

Penetration testing · web app security · security-minded frontend
  • I'm looking for my first dedicated security role, where a builder's instincts help find what others miss.
01 / 05DRAG ↓ SCROLL
NMAP✦METASPLOIT✦WIRESHARK✦SHODAN✦MALTEGO✦NESSUS✦
05 — arsenal

Tools on radar

// Security skills

Network ScanningVulnerability AssessmentPenetration TestingWeb App SecuritySecurity ToolingOSINT & ReconService EnumerationPacket Analysis

// Languages & web

JavaScriptJavaC / C++HTML5CSS3BootstrapWordPressDudaCamilyo
06 — interactive shell

Don't take my word for it

This is a working shell. Type help to start, or go looking for the flag hidden somewhere on this site.

visitor@nishant.verma — zsh
07 — establish connection

Let's build something secure

ssh — secure channel
awaiting input_