- π IT Specialist at NAWY β Cairo, Egypt
- π± Building Penetration Testing & Network Security skills
- π― Goal: Network Security Engineer / Penetration Tester
- π Cisco CCNA courses completed + TryHackMe Platinum (30+ rooms)
- π Password Cracking β John the Ripper, Hashcat (rules + mask attacks), crunch
| Lab | Tools | Result |
|---|---|---|
| AD Dashboard β Auth & Session Security | PowerShell/Pode + JS | 12+ bugs found & fixed β |
| AD Security Hardening β 9 Critical findings | PowerShell + GPO | 13/14 Fixed β |
| Metasploitable2 β vsftpd 2.3.4 (CVE-2011-2523) | Metasploit | Root shell β |
| Metasploitable2 β Bindshell port 1524 | Netcat | Root shell β |
| Metasploitable2 β Samba (CVE-2007-2447) | Metasploit | Root shell β |
| Metasploitable2 β MySQL No Password | mysql CLI | DB access β |
| Metasploitable2 β UnrealIRCd (CVE-2010-2075) | Metasploit | Root shell β |
| TryHackMe β Blue (EternalBlue MS17-010) | Metasploit | SYSTEM β |
| Password Cracking β /etc/shadow, MD5, SHA-1 | John + Hashcat + crunch | 9 hashes cracked β |
- π vsftpd 2.3.4 Analysis β CVE-2011-2523
- π Networking Security Notes
- π‘ CCNA Security Notes
- π₯ fortigate-elastic-siem β FortiGate & DC logs integration with Elastic Stack for real-time SIEM
- π₯οΈ Glpi-Assest-Management β End-to-end IT Asset Management implementation
- π· powershell-scripts β 17 PowerShell scripts for AD security audit & hardening β 13/14 findings resolved with timestamped evidence
- π ad-operations-dashboard β [Latest] AD-integrated IT ops dashboard with authentication, RBAC, and audit logging. Diagnosed and fixed a cross-origin session cookie bug via reverse proxy architecture.
- π₯ fortigate-elastic-siem β FortiGate & DC logs integration with Elastic Stack for real-time SIEM
- π₯οΈ glpi-asset-management β End-to-end IT Asset Management implementation (1,500+ users, 2,700+ devices)
- π· powershell-scripts β AD security auditing and IT automation scripts (17 scripts, 13/14 findings resolved with evidence)
- π security-notes/password-cracking β Password cracking labs with John, Hashcat rules & mask attacks
- π python-tools β Python Recon & Pentesting Tools (port scanner, subdomain enum, hash identifier)
- π§ bash-scripts β Pentesting & Sysadmin Bash Tools
- π security-notes β Networking, Pentesting & CCNA Notes
- 30+ rooms completed
- Blue badge β EternalBlue (top 10%)
- 30+ day streak