Penetration Testing Lab
Built an isolated VirtualBox attacker/target environment and performed initial network reconnaissance.
View case study →CYBERSECURITY • ETHICAL HACKING • WEB SECURITY
A practical portfolio of penetration-testing and web-security labs covering reconnaissance, vulnerability discovery, exploitation validation and remediation.
$ nmap -sV target
$ gobuster dir -u target
$ wpscan --url target
$ identify vulnerability
$ document impact
$ recommend remediation
assessment complete
ABOUT
This portfolio presents coursework-based security assessments performed in deliberately vulnerable, isolated lab environments. The work spans network reconnaissance, source-code review, web enumeration, command injection, SQL injection, XSS, Linux analysis and security hardening.
The emphasis is on understanding how vulnerabilities arise, demonstrating their impact safely, and translating findings into practical defensive recommendations.
SKILLS & TOOLS
PROJECTS
Built an isolated VirtualBox attacker/target environment and performed initial network reconnaissance.
View case study →Reviewed DNS Lookup Utility source code and identified an unauthenticated OS command injection vulnerability.
View case study →Performed reconnaissance, directory enumeration and controlled command-injection validation against a lab target.
View case study →Used Linux shell commands to profile the target and locate sensitive WordPress configuration data.
View case study →Assessed a vulnerable WordPress plugin REST API and demonstrated SQL injection leading to credential recovery and admin access.
View case study →Demonstrated reflected and stored XSS and analyzed session-token security in a deliberately vulnerable application.
View case study →Full-stack React + Node.js application with 30+ MITRE ATT&CK-tagged incident scenarios, scoring engine, and leaderboard for SOC analyst training.
View project →Scikit-learn supervised classifier trained on email features to detect phishing with high precision and explainable feature importance.
View project →Kali Linux reconnaissance against Metasploitable2 using Nmap, enum4linux, and SNMP to map network services and discover attack surface.
View project →Full-stack Flask + React network reconnaissance tool with parallel TCP scanning, service detection, CVE correlation, and real-time dashboard.
View project →Production-grade cryptography application with AES-256-GCM and RSA encryption, HMAC integrity, and secure key management.
View project →Machine learning-powered network anomaly detection using Random Forest and Gradient Boosting classifiers with 95%+ accuracy and ROC-AUC 0.97+.
View project →OWASP Top 10 vulnerability detection tool with SQL injection, XSS, CSRF, and security header analysis. Automated scanning with CVSS scoring.
View project →Network reconnaissance tool for DNS enumeration, subdomain discovery, SSL/TLS certificate analysis, and domain infrastructure mapping.
View project →Enterprise security compliance tool supporting GDPR, HIPAA, PCI-DSS, and ISO27001 audits with gap analysis and executive reporting.
View project →Advanced vulnerability detection for buffer overflows, use-after-free, memory leaks, format strings in C/C++, Python, JavaScript, and Java—fully offline with no API keys.
View project →Enterprise-grade Security Information & Event Management system with real-time threat detection, log correlation, MITRE ATT&CK mapping, and compliance reporting (GDPR, HIPAA, PCI-DSS).
View project →Cloud security monitoring for AWS with CloudTrail event analysis, IAM anomaly detection, privilege escalation tracking, and AWS security compliance scoring.
View project →Real-time network intrusion detection system with signature-based threat detection for SQL injection, XSS, command injection, port scans, DDoS, and malware patterns.
View project →Full-stack cybersecurity application (1550 LOC) demonstrating attack/defense thinking with Flask API, React dashboard, and scikit-learn ML detector (89-94% accuracy). Security awareness training tool with real-time email analysis.
View project →CONTACT
Open to professional connections and cybersecurity opportunities. Get in touch through email or connect with me online.