CYBERSECURITY • ETHICAL HACKING • WEB SECURITY

Security testing with a defensive mindset.

A practical portfolio of penetration-testing and web-security labs covering reconnaissance, vulnerability discovery, exploitation validation and remediation.

security-lab
$ nmap -sV target
$ gobuster dir -u target
$ wpscan --url target
$ identify vulnerability
$ document impact
$ recommend remediation

assessment complete

ABOUT

Hands-on cybersecurity work

This portfolio presents coursework-based security assessments performed in deliberately vulnerable, isolated lab environments. The work spans network reconnaissance, source-code review, web enumeration, command injection, SQL injection, XSS, Linux analysis and security hardening.

The emphasis is on understanding how vulnerabilities arise, demonstrating their impact safely, and translating findings into practical defensive recommendations.

SKILLS & TOOLS

Security toolkit

NmapGobusterNcatWPScan enum4linuxHashcatJohn the RipperLinux VirtualBoxWordPressDVWAWeb Security ReconnaissanceSource Code ReviewVulnerability AssessmentRemediation PythonJavaScriptFlaskReact Node.jsscikit-learnSQLAlchemyREST APIs MITRE ATT&CKIncident ResponseMachine LearningFull-Stack Development

PROJECTS

Security assessments

20 PROJECTS
01

Penetration Testing Lab

Built an isolated VirtualBox attacker/target environment and performed initial network reconnaissance.

NmapVirtualBoxLinux
View case study →
02

White-Box Command Injection

Reviewed DNS Lookup Utility source code and identified an unauthenticated OS command injection vulnerability.

PHPCWE-78Code Review
View case study →
03

Black-Box Testing

Performed reconnaissance, directory enumeration and controlled command-injection validation against a lab target.

NmapGobusterWeb
View case study →
04

Linux Environment Review

Used Linux shell commands to profile the target and locate sensitive WordPress configuration data.

BashLinuxForensics
View case study →
05

WordPress SQL Injection

Assessed a vulnerable WordPress plugin REST API and demonstrated SQL injection leading to credential recovery and admin access.

WPScanSQLiHashcat
View case study →
06

DVWA XSS Assessment

Demonstrated reflected and stored XSS and analyzed session-token security in a deliberately vulnerable application.

DVWAXSSSessions
View case study →
07

SOC Incident Response Simulator

Full-stack React + Node.js application with 30+ MITRE ATT&CK-tagged incident scenarios, scoring engine, and leaderboard for SOC analyst training.

ReactNode.jsMITRE ATT&CK
View project →
08

Phishing Detection Model

Scikit-learn supervised classifier trained on email features to detect phishing with high precision and explainable feature importance.

Pythonscikit-learnML
View project →
09

Network Enumeration Lab

Kali Linux reconnaissance against Metasploitable2 using Nmap, enum4linux, and SNMP to map network services and discover attack surface.

NmapKaliReconnaissance
View project →
10

Professional Port Scanner

Full-stack Flask + React network reconnaissance tool with parallel TCP scanning, service detection, CVE correlation, and real-time dashboard.

FlaskReactTooling
View project →
11

Hybrid File Encryption Tool

Production-grade cryptography application with AES-256-GCM and RSA encryption, HMAC integrity, and secure key management.

CryptographyAES-256RSA
View project →
12

ML-Based Intrusion Detection System

Machine learning-powered network anomaly detection using Random Forest and Gradient Boosting classifiers with 95%+ accuracy and ROC-AUC 0.97+.

Pythonscikit-learnML
View project →
13

Web Application Security Scanner

OWASP Top 10 vulnerability detection tool with SQL injection, XSS, CSRF, and security header analysis. Automated scanning with CVSS scoring.

FlaskReactSecurity
View project →
14

DNS & Certificate Intelligence Tool

Network reconnaissance tool for DNS enumeration, subdomain discovery, SSL/TLS certificate analysis, and domain infrastructure mapping.

FlaskdnspythonCryptography
View project →
15

Security Audit & Threat Intelligence Dashboard

Enterprise security compliance tool supporting GDPR, HIPAA, PCI-DSS, and ISO27001 audits with gap analysis and executive reporting.

FlaskReactCompliance
View project →
16

Keyless Memory Corruption Scanner

Advanced vulnerability detection for buffer overflows, use-after-free, memory leaks, format strings in C/C++, Python, JavaScript, and Java—fully offline with no API keys.

PythonFlaskVulnerability Scanning
View project →
17

Wazuh SIEM Dashboard

Enterprise-grade Security Information & Event Management system with real-time threat detection, log correlation, MITRE ATT&CK mapping, and compliance reporting (GDPR, HIPAA, PCI-DSS).

PythonFlaskSIEMThreat Detection
View project →
18

AWS Security Monitoring

Cloud security monitoring for AWS with CloudTrail event analysis, IAM anomaly detection, privilege escalation tracking, and AWS security compliance scoring.

PythonFlaskAWSCloud Security
View project →
19

Suricata IDS Alert System

Real-time network intrusion detection system with signature-based threat detection for SQL injection, XSS, command injection, port scans, DDoS, and malware patterns.

PythonFlaskIDSNetwork Security
View project →
20

Phishing Campaign Manager

Full-stack cybersecurity application (1550 LOC) demonstrating attack/defense thinking with Flask API, React dashboard, and scikit-learn ML detector (89-94% accuracy). Security awareness training tool with real-time email analysis.

FlaskReactscikit-learnFull-Stack
View project →

CONTACT

Let's connect

Open to professional connections and cybersecurity opportunities. Get in touch through email or connect with me online.