Available for opportunities

Vency Khunt

Cyber Security Graduate, aspiring DFIR / SOC Analyst

I investigate, assess, and report on security problems, with hands-on experience across vulnerability assessment, incident response, and cyber risk. Across three live client engagements, I've worked technical assessments through to board-level reporting, and I'm comfortable moving between VAPT, GRC, and IR depending on where the problem sits.

Melbourne, VIC  ·  vencykhunt@gmail.com

01

About

I'm a Cyber Security graduate with hands-on project experience across incident response, vulnerability assessment, digital forensics, and OSINT-based risk analysis. Continuously improving my DFIR and SOC analysis capabilities through practical engagements, home lab simulations, and targeted security challenges.

What I bring beyond the technical toolkit: I'm comfortable working directly with clients, producing enterprise-grade reports, and pivoting quickly when something doesn't go to plan, including substituting tools mid-engagement when operational risk required it on a live assessment.

I run a multi-VM home lab across Kali Linux, Ubuntu, and Windows for scanning, forensics, and attack simulation practice.

DFIR SOC Analysis Incident Response Digital Forensics OSINT Vulnerability Assessment Home Lab
02

Skills

Tools

  • Wireshark
  • Nmap / Zenmap
  • Nessus Essentials & OpenVAS
  • OWASP ZAP
  • FTK Imager & Autopsy
  • CrowdStrike

Security Domains

  • Incident response & forensics
  • Vulnerability assessment
  • OSINT & external footprinting
  • PCAP / log analysis, C2 detection
  • Risk assessment & IR playbooks
  • Security policy drafting

Frameworks & Platforms

  • NIST Cybersecurity Framework
  • ASD Essential Eight
  • OWASP Top 10
  • Australian Privacy Act 1988
  • Kali Linux, Ubuntu, Windows
03

Write-ups & Projects

Three consecutive projects completed through Harness, an industry-mentored practicum program run alongside my degree, each delivered for a real external client under a named mentor.

CASE-001 · Apr to Jun 2026
Cyber Risk Assessment: Head Start Homes
Harness Project · Mentor: Antonio Deliseo
Risk Assessment OSINT Privacy Act Policy
+

Goal: Lead an end-to-end cyber risk assessment for an Australian not-for-profit helping vulnerable people access home ownership.

Approach:

  • Audited third-party risk and internal data exposure through SmartSheet integrations.
  • Conducted OSINT-based external footprinting to identify exposed assets.
  • Ran two structured stakeholder interviews to uncover data silos across the organisation.

Result: Delivered findings directly to the founder and board chair, producing a full Cyber Risk Assessment Report and an updated Information Security Policy.

Communicating a critical finding clearly to non-technical stakeholders, without either alarming or underselling it, is its own skill, separate from finding the risk in the first place.
CASE-002 · Jan to Mar 2026
Vulnerability Assessment: My1Health
Harness Project · Mentor: Simona Dimovski
Vulnerability Assessment OWASP Top 10 Web App Scanning
+

Goal: Assess My1Health's environment for exploitable vulnerabilities and deliver a prioritised remediation plan for the engineering team.

Approach:

  • OpenVAS introduced operational instability to the assessment environment, posing a risk to system availability. Substituted with Tenable Nessus Essentials and Nmap/Zenmap to maintain assessment continuity and protect client timelines.
  • Ran OWASP ZAP against the web application to test for common vulnerability classes.
  • Analysed findings against the OWASP Top 10, with attention to Insecure Design and Software & Data Integrity Failures.

Result: Identified SQL Injection, XSS, misconfigured permissions, and weak encryption. Delivered a structured Vulnerability Assessment Report with prioritised remediation steps.

A structured assessment methodology matters more than any single tool. When tooling introduces operational risk, the right call is to substitute and keep moving, your methodology keeps you on track regardless of what breaks.
CASE-003 · Oct 2025 to Jan 2026
Incident Response: Neutopia
Harness Project · Mentor: Michael Choeng
Incident Response Ransomware PCAP Analysis Forensics
+

Goal: Manage a simulated ransomware incident end-to-end and trace the initial point of compromise.

Approach:

  • Conducted PCAP analysis in Wireshark to trace the initial compromise back to a phishing email, filtering on SMTP and HTTP streams to recover the malicious payload delivery chain.
  • Filtered DNS query logs in Wireshark to isolate suspicious outbound queries and confirm malware beaconing patterns to an external C2 domain.
  • Preserved indicators of compromise (IoCs) using Autopsy and FTK Imager, maintaining chain of custody throughout.

Result: Identified "patient zero" via phishing indicators, authored a full IR and Forensic Analysis Report, and developed enterprise-ready playbooks for Ransomware, Phishing, and Insider Threat scenarios.

Understanding how attackers leverage DNS for stealthy C2 communication and data exfiltration is foundational for rapid containment. Tracing those patterns in network captures is where the investigation becomes a story you can actually act on.
04

Education & Certifications

🏅
In Progress
CompTIA Security+
Secure architecture, encryption, access control, governance & compliance frameworks.
🎓
Bachelor of Computer Science
RMIT University, Melbourne
July 2024 to July 2026
Relevant Coursework
Cyber Forensics (Jul to Oct 2025): disk imaging and Android mobile forensics using FTK Imager and Autopsy; chain-of-custody and legal reporting standards.
Cyberattack Analysis & Incident Response (Mar to Jun 2026): analysis of phishing, network attacks, and malware; full IR exercises from initial investigation through deep-dive technical analysis.
🎓
Bachelor of Technology, Computer Engineering
Marwadi University, Rajkot, India
2022 to 2024
05

Contact

Open to entry-level DFIR, SOC analyst, and cyber security graduate roles. Happy to walk through any of the engagements above in more detail.