SCHIZOSCHIZOSCHIZO
  • WORK
  • ABOUT
  • BRAIN DUMP
  • TOOLS
  • CONTACT

Suhesh Kasti

Exploring application security, network infrastructure and application delivery. Here documented are braindumps of all my learnings, exploration and mistakes as well.

Explore WorkBrain Dump
Download CV
Scroll

About Me

Suhesh Kasti — application security engineer working with F5 BIG-IP and web application firewalls

Suhesh Kasti

Application Security Engineer & Offensive Security

I'm an application security engineer. I secure applications from notorious hacker people. Right now, I'm learning offensive security and pentesting. You either die a defender or live long enough to become an attacker.

This site is my brain dump — raw, unfiltered research notes, project writeups, and weird experiments.

Download CV [PDF]

Certifications

CAPT

Hackviser↗— verify the CAPT certification

CWSE

Hackviser↗— verify the CWSE certification

F5 CTS

F5 Networks↗— verify the F5 CTS certification

F5 CA

F5 Networks↗— verify the F5 CA certification
View All Certifications →

Education & Qualifications

Bachelors

Computer Science & Information Technology — Nepalaya College

Higher Education

Gyankunj HSS & College

Experience Timeline

2024–Present
Application Security Engineer

Digital Network Solutions

Protect client web applications against layer 7 attacks using WAF. Strengthen security posture through vulnerability assessments, configuration audits, and WAF tuning.

  • Protect client's web applications against various layer 7 attacks
  • Help clients strengthen their security posture
  • Configure and maintain Web Application Firewalls
2023–2024
Associate Security Research Analyst

SecurityPal Inc.

Enhanced clients' digital security through handling security questionnaires and knowledge base enrichment. Analyzed compliance requirements.

  • Enhance the client's knowledge repository
  • Respond to prospect's security questionnaires
  • Analyze and document security compliance requirements
2022–2023
Technical Support Representative

Subisu Cablenet Ltd.

Transformed digital challenges into seamless connectivity. Managed network setup, remote diagnostics, and customer technical support at a major ISP.

  • Assist with network setup and configuration
  • Conduct remote diagnostics, support, and configurations
  • Manage end-user connectivity and technical issues

Skills

next: BIG-IP & Delivery
  • Web Exploitationlabs + CAPT / CWSE
  • Burp Suitemy main testing tool
  • API SecurityREST, auth, Postman
  • PortSwigger Academy95 written up, more pending
  • Network Testingnmap, metasploit, labs
  • Recon & OSINTtooling I built myself
  • Security Research3 months · SecurityPal
  • HTB CPTSstudying now
  • Mobile Pentestinglearning on the side
BIG-IP & Delivery
  • F5 ASM / AWAF — 2.5 yrs · production
  • WAF Policy Tuning — daily, false positives included
  • LTM Load Balancing — pools and virtual servers
  • F5 DNS / GTM — working knowledge
  • SSL/TLS — offload, profiles, certs
  • Traffic Analysis — logs, tcpdump, Wireshark
  • Health Monitors — tuning, not just adding
  • Troubleshooting — SSL, DNS, routing, pressure
  • Log Analysis — from noise to root cause
IT & Network Admin
  • Linux — 3 yrs · RHEL, Debian, Arch
  • Networking — TCP/IP, NAT, VLANs
  • DNS & BIND — zones, records, DNSSEC
  • Windows / WSL — daily at work
  • Packet Capture — Wireshark, tcpdump
  • Remote Diagnostics — customer CPE and routers
  • Hardware — modems, switches, cabling
  • Connectivity — line faults and link issues
  • VPNs — remote access and tunnels
DevOps & Automation
  • Docker — daily · comfortable, not an expert
  • Git & GitHub — daily
  • Bash — daily shell work
  • Python — scripts and automation
  • REST APIs — curl, Postman, JSON
  • Virtualization — VMware, KVM, Proxmox
  • NGINX — config and troubleshooting
  • ELK Stack — deployed it for logs
  • Deployment — built and shipped this site
Clients & Communication
  • Customer Support — 3+ yrs · ISP to enterprise
  • De-escalation — annoyed callers, kept calm
  • Ticket Triage — SLAs, priorities, escalations
  • Plain-English Security — explaining a blocked request
  • Cross-Team Work — app teams and clients
  • Documentation — runbooks and clean notes
  • Remote Sessions — talking people through fixes
  • Training — built an app to train recruits
  • Questionnaires — vendor and compliance work
3+ yrs
Customer-facing
2.5 yrs
Production WAF
5
Certifications
95+
Lab writeups

Brain Dump

All Posts →MAP
Building a Local AI-Powered Security Research Agent from Scratch
Deep Dives2026-05-21

Building a Local AI-Powered Security Research Agent from Scratch

A full honest build log of setting up a completely local, private AI agent stack for authorized security research and bug bounty — llama.cpp, Goose, Qdrant RAG, model routing, Telegram integration — everything that went wrong and how it got fixed.

LLMllama.cppGooseQdrant
Locking Down Ports on F5 BIG-IP
Byte-Sized2026-06-25

Locking Down Ports on F5 BIG-IP

Port lockdown on a self IP decides which management ports answer on that interface — the switch between reaching the BIG-IP and leaving it exposed.

f5bigipSSHfirewall
Configuring DNSSEC on F5 BIG-IP DNS
Checklists2026-06-17

Configuring DNSSEC on F5 BIG-IP DNS

A step-through for signing a zone with DNSSEC on BIG-IP DNS — generating the ZSK and KSK, creating the zone, and building the chain of trust.

f5bigipDNSSECDNS
Wireshark Basics
Cheatsheets2026-06-28

Wireshark Basics

Conversation filters, profiles, custom time columns and colouring rules — the Wireshark setup tweaks that make packet analysis less painful.

Wiresharkpacket analysisnetworkSecurity
TryHackMe — Basic Pentesting
Labs2026-09-08

TryHackMe — Basic Pentesting

A TryHackMe Basic Pentesting room: SMB enumeration exposes a staff list, a private key cracks under john, and a backup file hands over the root password.

lab/thmwalkthroughEnumerationnmap

Featured Work

6 Projects
Local AI Security Agent
AI Security

Local AI Security Agent

Two local models, a RAG index I keep fed with live CVE data, MCP tools for nmap and search, and a Telegram bot so I can ask it things from my phone. Nothing leaves the GPU.

Pythonllama.cppQdrantFastAPIDocker
Details→
Security Writeups
Writeups

Security Writeups

Every lab and box I have worked through, written up the way I wish someone had explained them to me. The payloads, the dead ends, and the parts I got wrong first.

PortSwiggerHTBCTFWalkthrough
Details→
RemarkEnks
Automation

RemarkEnks

A browser extension that writes TSC remarks for Subisu operators. One click instead of the usual copy-paste routine, and it saved the team a serious number of hours.

JavaScriptChromeFirefoxAutomation
Details→
Re-Earth Waste Management
Web Design

Re-Earth Waste Management

Frontend work on a waste management platform in Nepal. I built the interface while the rest of the team handled the backend.

HTMLCSSJavaScriptCollaboration
Details→
Browser 11
Web Experiment

Browser 11

A Windows 11 clone that runs in a browser tab. The start menu opens, the notification centre works, and it exists mostly because I wanted to know if I could.

HTMLCSSJavaScriptUI/UX
Details→
Subisu TSC Desktop App
Desktop App

Subisu TSC Desktop App

A Tkinter app that trains new Subisu technicians. Lessons with diagrams, a quiz bank, progress tracking, and it works with no internet at all.

PythonTkinterDesktopTraining
Details→
View All Projects →

Connect

GitHub
@Suhesh-Kasti
↗
LinkedIn
suheshkasti
↗
Twitter
@kastisuhesh
↗
YouTube
@suheshkasti
↗
Telegram
@suheshkasti
↗
WhatsApp
+977 9861084025
↗
Email
kastisuhesh1@gmail.com
↗
Phone
+977 9861084025
↗

Send a Message

SCHIZO

Suhesh Kasti — AppSec & Offensive Security

Navigate

  • ▸ Projects
  • ▸ Brain Dump
  • ▸ Cyber Tools
  • ▸ About
  • ▸ Contact
  • Download CV

Connect

  • ◆ GitHub
  • ◆ LinkedIn
  • ◆ Twitter
  • ◆ YouTube
  • ◆ Telegram
© 2026 SCHIZO

Press / to search