Skip to content
View AymanAhmedAli's full-sized avatar

Block or report AymanAhmedAli

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AymanAhmedAli/README.md

Hi, I'm Ayman Ahmed πŸ‘‹

IT Specialist | Pentesting Learner | Network Security


πŸ§‘β€πŸ’» About Me

  • πŸ”­ IT Specialist at NAWY β€” Cairo, Egypt
  • 🌱 Building Penetration Testing & Network Security skills
  • 🎯 Goal: Network Security Engineer / Penetration Tester
  • πŸ“š Cisco CCNA courses completed + TryHackMe Platinum (30+ rooms)
  • πŸ” Password Cracking β€” John the Ripper, Hashcat (rules + mask attacks), crunch

πŸ› οΈ Tech Stack

Linux Bash Kali Nmap Metasploit Windows Cisco FortiGate Python Wireshark PowerShell Elastic Hashcat John


πŸ”΄ Pentesting Labs

Lab Tools Result
AD Dashboard β€” Auth & Session Security PowerShell/Pode + JS 12+ bugs found & fixed βœ…
AD Security Hardening β€” 9 Critical findings PowerShell + GPO 13/14 Fixed βœ…
Metasploitable2 β€” vsftpd 2.3.4 (CVE-2011-2523) Metasploit Root shell βœ…
Metasploitable2 β€” Bindshell port 1524 Netcat Root shell βœ…
Metasploitable2 β€” Samba (CVE-2007-2447) Metasploit Root shell βœ…
Metasploitable2 β€” MySQL No Password mysql CLI DB access βœ…
Metasploitable2 β€” UnrealIRCd (CVE-2010-2075) Metasploit Root shell βœ…
TryHackMe β€” Blue (EternalBlue MS17-010) Metasploit SYSTEM βœ…
Password Cracking β€” /etc/shadow, MD5, SHA-1 John + Hashcat + crunch 9 hashes cracked βœ…

πŸ“ Security Writeups


πŸ“‚ Projects

  • πŸ” ad-operations-dashboard β€” [Latest] AD-integrated IT ops dashboard with authentication, RBAC, and audit logging. Diagnosed and fixed a cross-origin session cookie bug via reverse proxy architecture.
  • πŸ”₯ fortigate-elastic-siem β€” FortiGate & DC logs integration with Elastic Stack for real-time SIEM
  • πŸ–₯️ glpi-asset-management β€” End-to-end IT Asset Management implementation (1,500+ users, 2,700+ devices)
  • πŸ”· powershell-scripts β€” AD security auditing and IT automation scripts (17 scripts, 13/14 findings resolved with evidence)
  • πŸ”‘ security-notes/password-cracking β€” Password cracking labs with John, Hashcat rules & mask attacks
  • 🐍 python-tools β€” Python Recon & Pentesting Tools (port scanner, subdomain enum, hash identifier)
  • πŸ”§ bash-scripts β€” Pentesting & Sysadmin Bash Tools
  • πŸ“’ security-notes β€” Networking, Pentesting & CCNA Notes


πŸ“Š TryHackMe β€” Platinum Rank πŸ†

  • 30+ rooms completed
  • Blue badge β€” EternalBlue (top 10%)
  • 30+ day streak

πŸ“« Contact

LinkedIn

Pinned Loading

  1. fortigate-elastic-siem fortigate-elastic-siem Public

    Real-time SIEM integrating FortiGate firewall, Active Directory, and Windows endpoints with Elastic Stack (Elasticsearch + Kibana + Logstash)

    1

  2. glpi-asset-management glpi-asset-management Public

    GLPI IT Asset Management deployment with Python REST API automation scripts for user lifecycle management, asset tracking, and bulk operations across enterprise environments.

    Python 1

  3. ad-operations-dashboard ad-operations-dashboard Public

    A PowerShell/Pode backend + vanilla JS dashboard integrated with Active Directory β€” featuring AD-based authentication, audit logging, and session security. Built as a hands-on security engineering …

    JavaScript 1

  4. powershell-scripts powershell-scripts Public

    PowerShell scripts for Active Directory security auditing and IT automation β€” built from real-world penetration test findings.

    PowerShell 2

  5. bash-scripts bash-scripts Public

    Bash scripts for penetration testing and system administration β€” network scanner, recon tool, ping sweep, and system audit scripts.

    Shell 1

  6. python-tools python-tools Public

    Python recon tool integrating Nmap scanning, ping check, and web enumeration using subprocess module.

    Python 1