Aayush Shrestha / Paincakes
Offensive Security Consultant | Penetration Tester
Kathmandu, Nepal · Remote
Aayush Shrestha
Penetration tester. I find the way into web apps, APIs, networks and cloud accounts, then write down exactly how to close it.
Open to freelance pentests and research collaborations.
- Years in offensive security
- 5+
- Organizations assessed
- 40+
Rooted, with writeups
01 — Executive summary
I break into web apps, APIs, AD and network infrastructure, and cloud environments for a living. With permission, which apparently makes it a career, not a crime. Five years, 40+ organizations, and I’ve yet to meet a system that was actually secure by default. You build it, I break it, then I help you fix it.
I’ve spent five years testing web apps, APIs, networks and cloud infrastructure. I started at CryptoGen Nepal as an Offensive Security Analyst, moved to F1Soft International as a Security Testing Engineer, and now work remotely as an Offensive Security Consultant at StickmanCyber.
Most of the job is what happens after the exploit: clear reports, practical fixes, and working with development and operations teams so security becomes part of how they already work.
- Based in
- Kathmandu, Nepal
- Focus
- Web, API, AD and network infrastructure, cloud environments
- Peak rank
- #1 on Hack The Box, Nepal
- Off the clock
- Security research, rooting boxes and writing up how
02 — Scope
What I test
01 Web & API From the OWASP Top 10 to the business-logic flaws scanners walk past.
Approach
Finding and exploiting vulnerabilities in web applications and APIs, from the OWASP Top 10 to complex business-logic flaws.
Earned
- eCPPTv2
Toolkit
- Burp Suite
- OWASP ZAP
- Postman
- SQLMap
- Nmap
- ffuf
Field notes
- Found critical RCE in production banking infrastructure.
- Tested the APIs behind major fintech products.
02 Active Directory & network Attack chains from first foothold to Domain Admin.
Approach
Simulating real-world attacks on corporate networks to find and exploit misconfigurations in Active Directory and other network services.
Earned
- eCPPTv2
- Fortinet NSE 1–3
Toolkit
- Metasploit
- Nmap
- BloodHound
- Mimikatz
- Responder
- NetExec
Field notes
- Reached #1 on the Hack The Box Nepal leaderboard.
- Took full Domain Admin in hardened enterprise environments.
- Chained attacks across multiple systems to reach Domain Admin.
03 Cloud: AWS & Azure Misconfigurations, IAM and exposed storage, across regions.
Approach
Assessing cloud environments for misconfigurations and checking them against best practice.
Earned
- AWS Cloud Foundations
- AWS Cloud Security Foundations
Toolkit
- AWS CLI
- Azure CLI
- ScoutSuite
- Prowler
- Pacu
Field notes
- Researched and performed AWS cloud security testing.
- Automated S3 bucket enumeration.
- Audited multi-region AWS infrastructure for compliance.
04 Auditing & ISO 27001 Audits against ISO 27001 controls, by a certified Lead Auditor.
Approach
Running security audits and checking compliance with industry standards, as a certified ISO 27001 Lead Auditor.
Earned
- ISO/IEC 27001:2022 Lead Auditor
Toolkit
- Nessus
- ISMS.online
- CIS Benchmarks
Field notes
- Verified ISO 27001 compliance for fintech applications and servers.
- Built risk scoring models from ISO 27001 controls.
- Ran internal audits against security policy.
05 DevSecOps & automation SAST, DAST and security checks inside the pipeline, not after release.
Approach
Integrating security into the development lifecycle and automating security processes to cut effort and risk.
Toolkit
- GitLab CI/CD
- Jenkins
- SonarQube
- SAST/DAST tooling
- Python
- Rancher
Field notes
- Integrated SAST and DAST tools into CI/CD pipelines.
- Introduced security-as-code practices.
- Trained development teams on security awareness.
03 — Engagement history
Where I’ve worked
-
Sep 2026 – Present 1 mo
Offensive Security Consultant
StickmanCyber Remote
- Run manual-first penetration tests on internal and external networks, including on-prem and hybrid Active Directory.
- Assess web applications, APIs and desktop applications, including source code review.
- Research new vulnerabilities in software products and track newly disclosed issues across web, network and cloud.
- Test against the OWASP Top 10, API Top 10, ASVS, WSTG and MSTG, and NIST methodology.
- Write assessment reports with clear remediation steps, and walk clients and internal teams through the findings.
-
Jul 2025 – Sep 2026 1 yr 2 mos
Security Testing Engineer
F1Soft International
- Ran vulnerability assessments and penetration tests across web and API platforms, following industry-standard guidelines.
- Ran static (SAST) and dynamic (DAST) application security testing throughout the development lifecycle.
- Built automated security checks into CI/CD pipelines, moving teams toward security-as-code.
- Delivered internal training and security awareness sessions on secure practices and threat mitigation.
- Kept up with emerging threats, vulnerabilities and technologies through ongoing research.
-
Feb 2022 – Jul 2025 3 yrs 5 mos
Offensive Security Analyst
CryptoGen Nepal
- Performed vulnerability assessments and penetration tests on network infrastructure, web applications and AWS cloud environments.
- Wrote reports covering findings, exploitation steps and prioritized remediation.
- Contributed to security research and built custom tools and scripts that made assessments faster and more effective.
- Worked with teams to implement the recommended fixes and supported them afterwards.
04 — Credentials
Certifications I hold
| Certification | Issuer | Year | Verification |
|---|---|---|---|
| eCPPTv2 Certified Professional Penetration Tester | INE Security | 2023 | Verify |
| ISO/IEC 27001:2022 Lead Auditor | Mastermind | 2023 | |
| AWS Cloud Foundations | AWS Academy | 2023 | |
| AWS Cloud Security Foundations | AWS Academy | 2023 | |
| Fortinet NSE 1–3 Network Security Expert | Fortinet | 2023 |
06 — Next steps
Need something tested?
Freelance pentests, research collaborations, or a question about a writeup. Email works best.
Click to copy