🏆 2x CTF Champion • Hardware & Web Security

Subhechha Gautam.

Cybersecurity Researcher

Cybersecurity enthusiast specializing in web & API security, hardware hacking, reverse engineering, and embedded security. Winner of 1st place in Breaking Hardware CTF 2026 and PGS CTF.

subhechha@security-node:~
$ cat security_profile.json
{
  "name": "Subhechha Gautam",
  "location": "Kathmandu, Nepal",
  "focus": "Hardware Security & Web Exploitation",
  "teams": ["D3AD CA7", "GET the Flag"],
  "achievements": ["1st Place PGS Breaking Hardware CTF", "1st Place PGS CTF"]
}
$ status --verify
> VERIFIED CV // KATHMANDU, NEPAL
HARDWARE HACKING WEB APP SECURITY API SECURITY REVERSE ENGINEERING CRYPTOGRAPHY FIRMWARE ANALYSIS SDR & RFID BURP SUITE & WIRESHARK AWS & GOOGLE CLOUD
Victories & Honors

Achievements

Proven competitive performance in cybersecurity & hardware hacking CTFs.

🏆
1st Place Winner 2347 Points

Winner of PGS Breaking Hardware CTF

Member of Team D3AD CA7

Won 1st place in the Breaking Hardware 2026 Capture-the-Flag (CTF) competition as a member of team D3AD CA7. Demonstrated practical skills in hardware hacking, including UART and SPI analysis, firmware analysis, SDR, RFID/NFC attacks, and IoT security, achieving a team score of 2347 points.

UART Analysis SPI Analysis Firmware Analysis SDR RFID/NFC Attacks IoT Security
🏆
1st Place Winner Highest Scorer

PGS CTF Winner

Top Scorer on Team GET the Flag

Won first place in a Capture-the-Flag cybersecurity competition as the highest scorer on team GET the Flag. Demonstrated skills in reverse engineering, web exploitation, and cryptography under time pressure.

Reverse Engineering Web Exploitation Cryptography Time-Pressure Defense
🥉
3rd Place Podium Research Presentation

3rd Place – Research & Presentation Competition

Technical Presenter

Presented a technical research project before a judging panel, securing third place among participating teams.

Technical Research Presentation Security Analysis
Selected Work

Projects

Hardware security tools and IoT systems development.

Hardware Security ESP32-S3 BadUSB

Rubber Ducky

Developed an educational USB HID keystroke injection tool using the ESP32-S3 to demonstrate BadUSB attacks, automated payload execution, and endpoint security concepts using Arduino and TinyUSB (USB-OTG) for Presidential Innovista from Presidential Cybersecurity Club.

ESP32-S3 Arduino TinyUSB (USB-OTG) Keystroke Injection Presidential Cybersecurity Club
Award Winner IoT System JavaScript

IoT-Based Library Management System

Contributed to an award-winning project by designing a 3D model, implementing JavaScript, and integrating a QR scanner, improving system teamwork, reliability and efficiency.

JavaScript 3D Modeling QR Code Scanner IoT Integration Team Collaboration
Technical Stack

Skills

Cybersecurity domains, tools, languages, cloud, and networking.

subhechha@security-node:~
$ nmap -sV -p- subhechha-gautam.dev
Starting Nmap scan • 8 services discovered on scanned host
PORT STATE SERVICE VERSION
443/tcp open https Web Application Security
8080/tcp open http-proxy API Security
22/tcp open ssh Network Security
21/tcp open ftp Vulnerability Assessment
8443/tcp open https-alt Cryptography
1337/tcp open elite Capture The Flag (CTF)
502/tcp open modbus Hardware Hacking
5683/udp open coap IoT Security
> Nmap done: 1 IP address (1 host up) scanned in 0.34s
🛠️

Security Tools

  • Burp Suite
  • Wireshark
  • Nmap
  • Metasploit
  • Hydra
  • Kali Linux
💻

Programming & Development

  • Python
  • JavaScript
☁️

Cloud & Networking

  • AWS (Cloud Practitioner)
  • Google Cloud
  • Networking Fundamentals
  • Packet Analysis
  • TCP/IP Basics
💡

Soft Skills

  • Leadership
  • Planning & Research
  • Time Management
Academic Background

Education

Academic studies focusing on computing, software, and cybersecurity.

🎓

Bachelor of Science in Computer Science & IT

Presidential Graduate School

Focus: Cybersecurity, Software Systems, Hardware Security, Network Defense & Cryptography

Verified Credentials

Certifications

Official credentials in security, cloud, and networking.

ISC2

ISC2 Certified in Cybersecurity (CC)

ISC2 • Cybersecurity Domain Foundations

APISec

API Security Fundamentals

APISec University • REST API Security

AWS

AWS Cloud Quest: Cloud Practitioner

Amazon Web Services • Cloud Infrastructure

GCP

Google Cloud Essentials

Google Cloud • Cloud Computing

Cisco

Cisco Networking Basics

Cisco Networking Academy • TCP/IP & Networks

Get in Touch

Contact

Interested in security research, hardware hacking, CTF collaborations, or cybersecurity engineering opportunities? Feel free to reach out.

Location Kathmandu, Nepal
Profiles