About

About

๐Ÿ‘‹ Hello!

Iโ€™m Nguyแป…n Giรกp Anh Khoa, a third-year Information Security student at Ho Chi Minh City University of Industry and Trade (HUIT), expected to graduate in 2027.

My primary interest is Offensive Security, especially Web Application Penetration Testing. I enjoy learning by solving real-world security labs, participating in CTF competitions, and building home labs to understand both attack techniques and defensive mechanisms.

My goal is to become a professional Penetration Tester capable of identifying vulnerabilities and helping organizations improve their security posture.


๐ŸŽฏ Areas of Interest

  • Web Application Penetration Testing
  • Network Penetration Testing
  • Active Directory Security

๐Ÿ›  Technical Skills

Programming

  • C/C++
  • C#
  • Basic Python

Security

  • Burp Suite
  • Nmap
  • Wireshark
  • Metasploit
  • Gobuster
  • SQLMap
  • FFUF
  • John the Ripper
  • Hashcat

Operating Systems

  • Kali Linux
  • Ubuntu
  • Windows

Knowledge

  • TCP/IP & Networking
  • Linux Fundamentals
  • OWASP Top 10 (2021)
  • Web Security
  • Basic Active Directory

๐Ÿšฉ Practical Experience

I continuously improve my practical skills through security labs and Capture The Flag (CTF) competitions.

Some of the topics I have worked on include:

  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Authentication & Authorization flaws
  • Local File Inclusion
  • File Upload vulnerabilities
  • Reconnaissance & Enumeration
  • Privilege Escalation (Linux)
  • Basic Active Directory attacks

I have also participated in CTF competitions such as BKISC CTF 2026 and THCon CTF 2026, where I solved beginner Web and OSINT challenges.


๐Ÿ“š Learning Platforms

Iโ€™m learning, and developed my self by involve in these learing platfoms

  • Hack The Box Academy
  • TryHackMe
  • PortSwigger Web Security Academy
  • picoCTF
  • Cisco Ethical Hacker

๐Ÿ”น Phishing Simulation Lab

Built a phishing laboratory using:

  • OWASP Juice Shop
  • Nginx Reverse Proxy
  • Evilginx2
  • GoPhish

Studied phishing techniques including Browser-in-the-Browser, Clickjacking, Homograph attacks, and Proxy Phishing.


๐Ÿ”น DoS / DDoS Home Lab

Built a virtual lab consisting of Kali Linux, Ubuntu and Windows machines to simulate DoS/DDoS attacks.

Used Wireshark to analyze attack traffic and evaluated mitigation techniques including firewall rules, monitoring and IP blocking.


๐Ÿ“ˆ Current Learning

Currently focusing on:

  • Hack The Box Academy Penetration Tester Path
  • Web Application Security
  • Active Directory Exploitation
  • Privilege Escalation
  • Malware Analysis
  • Report Writing

๐ŸŒ Profiles

  • Blog: https://melodickat.github.io
  • Hack The Box: https://profile.hackthebox.com/profile/019dd773-0480-72a9-918b-6f84c2e96be1
  • TryHackMe: https://tryhackme.com/p/GekkoGecko
  • OSINT Industries: https://ctf.osint.industries/users/4244

๐Ÿ“ซ Contact

  • ๐Ÿ“ง favcolbun@gmail.com
  • ๐Ÿ“ Bien Hoa, Dong Nai, Vietnam