Bhavya Malhotra — Cybersecurity Enthusiast & Backend Developer

bhavya@portfolio:~

$

scroll ↓
who is this guy

Cybersecurity & Backend Development.

I'm Bhavya, currently pursuing senior secondary education while focusing on cybersecurity and backend development.

I've built projects ranging from FastAPI web applications and Discord bots to desktop software, while continuing to develop my skills in security and software engineering.

My current areas of focus include web application security, digital forensics, network fundamentals, FastAPI backend development, and Kotlin for Android development.

4 projects shipped
2 certifications
17 years old
things left to learn
what i work with

Skills & Learning

Some I use confidently. Some I'm still figuring out. I'll be honest about both.

🔒

Security & Pentesting

Web App Security XSS SQLi CSRF / SSRF (learning) VAPT (learning) Burp Suite Nmap Wireshark Tenable Nessus (learning) Splunk (basics)

Backend Development

FastAPI Pydantic PyMongo MongoDB Atlas PyJWT JWT Auth Cookie Handling Discord.py SQLite
🖥️

Frontend & Desktop

JavaScript (basics) HTML / CSS PyWebView yt-dlp Multithreading PyInstaller (learning) Kotlin (learning) Android Dev (learning)
🌐

Networking & Forensics

Digital Forensics (basics) Network Fundamentals Wireshark More forensics (learning)
💻

Languages

Python JavaScript C (learning) Kotlin (learning)
comfortable actively learning
things i've actually built

Projects

Real projects with real backend logic. UIs were AI-assisted — the systems behind them weren't.

PyPI Package

NetraX

An asynchronous Python wrapper for Nmap with typed models, structured exceptions, and built-in scan profiles.

Built to make Nmap easier to integrate into modern Python applications. Instead of dealing with subprocess management, XML parsing, and raw command output, NetraX provides an async API that returns structured dataclass models. It includes built-in scan profiles, configurable timeouts, permission checks, automatic Nmap validation, JSON/dictionary export, and detailed exception handling while remaining dependency-free.

what i learned: Async subprocess management, XML parsing, package architecture, dataclass modelling, exception design, PyPI publishing, semantic versioning, and project documentation
next steps: AI-powered report generation, additional scan profiles, richer reporting utilities, and continued expansion of supported Nmap data fields
Python asyncio Nmap XML Dataclasses PyPI
Discord Bot

VoiceForge

Temporary voice channels that create and delete themselves — no manual cleanup needed.

Started as a single-server bot, grew into a proper multi-server architecture with a control panel. The hard part wasn't making channels — it was carefully handling Discord API rate limiting so the bot doesn't get banned. Users create a voice channel, everyone joins, it disappears when empty. Clean, no clutter.

what i learned: Rate limiting strategies, multi-guild bot architecture, SQLite for persistent guild configs, Pydantic for config validation
still working on: Better control panel UI, more customization per guild
discord.py Pydantic SQLite Python
Web App

Fukray

Community website for a Discord server — with a real backend, not just static HTML.

The UI was AI-generated, but the backend is entirely mine — FastAPI with MongoDB Atlas, proper JWT auth with short-lived tokens (security over convenience), cookie handling, login and access management. Includes a quotes system where users can add and delete quotes using BSON ObjectID lookups and proper JSON/BSON type conversion. Security was the focus throughout.

what i learned: JWT expiry and refresh logic, BSON/JSON type handling, PyMongo aggregations, cookie security flags, FastAPI dependency injection
still working on: More features, maybe a refresh token flow
FastAPI PyMongo MongoDB Atlas PyJWT Python
Desktop App

RaagaX

A music player for Windows and Linux that streams directly from YouTube — no middle server.

UI and PyInstaller spec file were AI-assisted, but everything else is mine — FastAPI backend embedded in the app, yt-dlp for direct stream URLs (no buffering through a server), PyWebView for the native window. Multithreading to keep the UI from freezing on big playlists. Handles frozen vs non-frozen state paths, Linux dependency scripts, and Discord rich presence. Ships as a zip with a single exe.

what i learned: PyInstaller frozen paths, Linux build scripts, yt-dlp stream URL extraction, multithreading for audio, Discord IPC for rich presence
still working on: Speed and efficiency on large playlists — it's a known issue, actively fixing
FastAPI PyWebView yt-dlp Multithreading PyInstaller Python
verified learning

Certifications

🛡️
Tutedude

Cybersecurity

Foundational cybersecurity concepts — threat landscape, defensive principles, attack vectors, and security practices.

view certificate ↗
⚔️
Tutedude

Ethical Hacking

Ethical hacking methodology — reconnaissance, scanning, exploitation techniques, and responsible disclosure.

view certificate ↗
📚
In Progress

More coming soon

Currently working through TryHackMe rooms and diving deeper into Android development with Kotlin. More certifications on the way.

tryhackme profile ↗
where i've been

Education

Apr 2014 – Mar 2023

Air Force School, Jammu

UKG through Class 8 — foundational years. School activities, building curiosity, figuring out what actually interests me.

Jul 2024 – Jun 2025

NIOS — Class 10 (Secondary)

National Institute of Open Schooling. Completed secondary education — the flexibility helped me spend more time actually building things.

May 2026 – Jun 2027 current

NIOS — Class 12 (Senior Secondary)

Currently in senior secondary. Parallel to this: building projects, studying security, learning Kotlin, and finding out what kind of developer I want to be.

let's connect

Let's Connect

I'm 17, still in school, and building stuff in my free time. If you have feedback on my projects, want to collaborate on something, or just want to talk about security — I'm genuinely happy to hear from you.