root@nikhil:~$ _

root@nikhil:~$

Nikhil Sankhla

I'm a |

Software developer turned security practitioner with 2.5+ years of industry experience. Pursuing a Master's in Cyber Security at UNSW, specialising in offensive security, binary exploitation, and web application pentesting.

nikhil@kali — bash — 80x24
##############################################
# Nikhil Sankhla — Interactive Shell #
# Type 'help' for available commands #
##############################################
Try: help · whoami · skills · projects · theme light
0+ Years Experience
0+ Security Projects
0+ Tools Mastered

Latest Posts

Case studies, concepts, and field notes from security research.

Case Study

Evil Twin Attacks: A Practical Wireless Security Case Study

Hands-on walkthrough of setting up an Evil Twin attack lab using Raspberry Pi and Kali Linux — WPA2 handshake capture, deauth flooding, and full traffic interception.

15 min 2026-06-15
Concepts

Understanding Heap Use-After-Free Vulnerabilities

A deep dive into heap UAF vulnerabilities — how allocators manage memory, how UAF arises, and how to chain it into reliable code execution.

12 min 2026-05-20
Learning

Building a DevSecOps Pipeline: Lessons from Production

Real-world lessons from embedding SAST and dependency scanning into GitLab CI/CD pipelines at scale — what worked, what didn't, and why.

10 min 2026-04-10
Learning

AWS Core Services Explained: What They Do and How They Fit Into a Deployment

EC2, ECS, ECR, ALB, IAM, VPC, CloudWatch — what each AWS service actually does and how they connect together when you deploy a real application.

13 min 2026-07-01
Concepts

Top 20 System Design Concepts Every Developer Should Know

From CAP theorem to consistent hashing — the 20 system design concepts that come up repeatedly in interviews and real-world architecture decisions, with practical explanations for each.

16 min 2026-07-01
Learning

Linux Commands Every Cyber Security Student Actually Needs

Not a list of 200 commands you'll forget. These are the commands I reach for every single day — for CTFs, pentesting, debugging, and general Linux work — with practical examples for each.

12 min 2026-07-01
Concepts

pwndbg: The GDB Plugin That Actually Makes Exploitation Bearable

Stock GDB is painful for binary exploitation. pwndbg fixes that — here's how to set it up, what it shows you, and the commands I actually use during CTF and fuzzer debugging sessions.

11 min 2026-06-28
Concepts

CVEs in Web Security: What They Are and How to Actually Use Them

CVEs show up everywhere in security — job descriptions, advisories, CVSSv3 scores on dashboards. Here's what they actually mean, how the system works, and how to use CVE data in real web security work.

10 min 2026-06-20
Learning

Why Every Cyber Security Student Should Be Running Kali Linux

Not because it makes you look cool. Because the tooling, the environment, and the mindset shift that comes with running Kali are genuinely useful — and most students wait way too long to switch.

9 min 2026-07-01
Interview

Cracking the Cybersecurity Interview: What They Actually Ask

From behavioural questions to live CTF-style challenges — a breakdown of every stage of the cybersecurity interview process and how to prepare for each round.

9 min 2026-02-14
Concepts

Zero Trust Architecture: Beyond the Buzzword

Zero Trust is everywhere in job descriptions. But what does it actually mean to implement it? A technical breakdown of identity-centric security models and what real Zero Trust looks like in practice.

11 min 2026-01-20

Software Developer
turned Security Researcher

I transitioned from building software systems at Dell Technologies to pursuing offensive security at UNSW Sydney. I bridge the developer mindset with the attacker's perspective — understanding how systems are built helps me find where they break.

My focus areas include binary exploitation, wireless attack simulation, web application pentesting, and embedding security into DevOps pipelines.

Learn More

Offensive Security

Binary exploitation, fuzzing, wireless attacks, and web pentesting.

Secure Development

DevSecOps pipelines, microservices security, and authentication systems.

Hardware Security

Wireless lab builds, IoT security research, and embedded system attack surfaces.

UNSW Cyber Security

Master's student specialising in offensive security and exploitation.

Core Skills

Web Pentesting Binary Exploitation Python Burp Suite ELF Fuzzing Docker Wireless Security pwndbg GitLab CI/CD OWASP Top 10 Kali Linux Kubernetes Aircrack-ng C / Assembly Raspberry Pi Wireshark Scapy IoT Security

Digital Footprint Scanner

See exactly what every website knows about you the moment you visit — using only standard browser APIs.

Ready to scan your browser

Click below to run a reconnaissance sweep on your own browser. No data leaves your device — your public IP is resolved client-side via a free HTTPS API.

This tool only collects data that any website can already access. Nothing is sent to a server or stored. Results are for educational purposes only.

Scan progress
0%
recon — browser-intelligence — bash
Reconnaissance Completed Successfully
22 data points collected via browser APIs
Network Intelligence
Public IP Address
Country
Region / State
City
ISP / Organization
Timezone
Browser
Browser
Version
Language
System
Operating System
Platform
Device Type
Display & Hardware
Screen Resolution
Color Depth
CPU Threads
Device Memory
Touch Support
GPU Renderer (WebGL)
Session
Cookies
Network Type
Local Time
Browser Fingerprint (DJB2 hash)

Have a project or opportunity?

I'm open to security consulting, research collaborations, CTF teams, and full-time roles in offensive security or DevSecOps.