whoami
Ho Vi Khanh
Information Security Graduate — Offensive Security
Recent Information Security graduate (University of Information Technology, VNU-HCM) focused on offensive security. Built and exploited OWASP Top 10 vulnerability labs (SQLi, XSS, SSRF) using Burp Suite against DVWA and PortSwigger Labs, and automated reconnaissance workflows with Python, Nmap, and the VirusTotal API. Cisco Ethical Hacker certified, with a published fileless-malware detection framework (Springer Nature) and a working olevba/YARA detection tool as further evidence of a long-term commitment to information security.
cat about.md
About
Recent Information Security graduate (University of Information Technology, VNU-HCM) focused on offensive security. Built and exploited OWASP Top 10 vulnerability labs (SQLi, XSS, SSRF) using Burp Suite against DVWA and PortSwigger Labs, and automated reconnaissance workflows with Python, Nmap, and the VirusTotal API. Cisco Ethical Hacker certified, with a published fileless-malware detection framework (Springer Nature) and a working olevba/YARA detection tool as further evidence of a long-term commitment to information security.
Web Application Penetration Testing
Hands-on exploitation of OWASP Top 10 vulnerabilities (SQLi, XSS, SSRF) using Burp Suite against DVWA and PortSwigger Labs; Cisco Ethical Hacker certified.
Reconnaissance & Automation
Python workflows for automated reconnaissance using Nmap and the VirusTotal API.
Security Research & Detection Engineering
Built a macro-malware detection tool from scratch (VBA extraction with olevba, obfuscation scoring, YARA rule authoring) and contributed to a published fileless-malware detection framework.
Machine Learning for Security
Python, Scikit-learn, Pandas, XGBoost, LLM integration; applied to phishing and malware detection.
Systems & Infrastructure
Kali Linux, Ubuntu, Windows; Windows Server, Active Directory, VMware, PfSense.
Education
Bachelor of Engineering in Information Security
University of Information Technology (UIT), VNU-HCM · 2022 – 2026
Topics: network security, ethical hacking, machine learning for security. Graduated with "Good" classification.
Certifications
- Ethical Hacker — Cisco Networking Academy, 01/2025
- Google AI Essentials (V1) — Google, 07/2026
Publications
- Ho, V.-K. et al. (2026). "G-FLEX: A Graph-Based and Fine-Tuned Transformer Framework with Explainable AI for Fileless Malware Detection." Springer Nature Singapore
cat experience.log
Experience
Sep 2025 – Jan 2026
Research Intern · Trung tam An ninh mang (InSecLab), UIT - VNU-HCM
Ho Chi Minh City, Vietnam
- Built and tested OWASP Top 10 vulnerability labs and automated reconnaissance workflows using Python, Nmap, and the VirusTotal API
- Contributed to G-FLEX, a graph-based fine-tuned transformer framework for fileless malware detection, published by Springer Nature Singapore
- Developed a phishing detection system combining Random Forest with LLMs over the PILWD-134K dataset
- Researched ML-based detection of malicious NPM and PyPI supply-chain packages
ls ./projects
Selected Projects
Web Pentest Labs
Practiced and documented OWASP Top 10 exploitation (SQLi, XSS, SSRF) against DVWA and PortSwigger Labs, simulating real-world attack scenarios and analysing server behaviour under attack.
Macro Malware Detection Tool
Detects malicious Office macros by extracting VBA code with olevba, scoring obfuscation patterns such as Chr() and XOR, and identifying VBA purging via YARA rules.
Phishing Website Detection System
Dec 2025Real-time phishing detection over hybrid URL and HTML features, designed client-side so it does not depend on third-party lookup services. Dataset of 134,000 sites (PILWD-134K).
Network Configuration & Domain System Administration
Mar 2026Designed a multi-branch internal network and centralised Active Directory domain for high availability and information security; automated GPO security policy deployment.
cat skills.json
Skills
Security Testing
Programming & ML
Detection Engineering
Systems & Infrastructure
tail -n 3 ./blog
Writing
August 14, 2026 · 6 min read
Multi-Agent Workflow: Cách Thiết Kế Hệ Thống AI Tự Vận Hành
August 13, 2026 · 4 min read
RAG: Bí Thuật Giúp AI Ngừng Nói Nhảm
RAG (Retrieval-Augmented Generation) - công nghệ nền tảng đằng sau các chatbot AI doanh nghiệp hiện đại như ChatGPT, Copilot.
August 10, 2026 · 5 min read
CVE-2025-33073-PoC
CVE-2025-33073 là một lỗ hổng kiểm soát truy cập không đúng cách trong Windows SMB cho phép kẻ tấn công được ủy quyền nâng cao đặc quyền qua mạng. Lỗ hổng này cho phép kẻ tấn công truy cập thông tin nhạy cảm trong bộ nhớ của một quy trình hợp lệ (NT AUTHORITY\SYSTEM)
./send-message.sh
Get in touch
Reach out at vikhanhho@gmail.com or use the form below.