Cyber Security Engineer
Securing digital environments through penetration testing, network analysis, and vulnerability assessment.
Who I am
Hi, I'm Mohammed Amaan — a passionate Cyber Security Engineer with a deep interest in ethical hacking, penetration testing, and network defence.
I stay sharp by solving Capture The Flag challenges and tracking newly discovered vulnerabilities. Outside of security, I enjoy gaming, podcasts, and music.
My goal is simple: contribute to a safer digital world for everyone, one vulnerability at a time.
My work
Acunetix
Automated web vulnerability scanning to identify security flaws and inform remediation strategies for website owners.
Burp Suite
Web application security testing via SQL injection, SSRF, and redirect manipulation techniques.
Nmap
Network mapping and port scanning to identify exposed services and potential entry points on servers.
Wireshark
Packet capture and live traffic analysis including handshake inspection and network anomaly detection.
SQLMap
Automated SQL injection to extract database information and locate admin panel access points.
What I offer
Network attacks
Airmon-ng, Evil Twin, MITM, Wireshark — identifying vulnerabilities and entry points across networks.
Password attacks
Cryptography analysis, Pass-the-Hash, brute force, and phishing simulation techniques.
Website attacks
SQL/XSS injections, SSRF, web shells — exposing database and admin panel weaknesses.
Server attacks
DNS floods, TCP/UDP attacks, FTP/SSH exploitation, and firewall bypass techniques.
Expertise
Background
Cyber Security Intern
Placeholder Company
Researched network security, Active Directory, ISO 27001 compliance, GDPR, VPN technologies, and TCP/UDP port management.
BSc Computer Science
Placeholder University
Focused on networking, security principles, and systems programming.
Cyber Security Course
Placeholder Academy
Penetration testing, network analysis, Linux VMs, cloud computing, and server services.
DDoS & Network Attacks
Placeholder Academy
DNS Flood, SYN-ACK Flood, and practical DDoS simulation techniques.
Hall of shame
Every exhibit here is something I attempted, broke, misunderstood, or gave up on. Displayed with pride. Entry is free. Exit is through the gift shop of hard-won lessons.
My first CTF attempt
Spent 6 hours on a challenge rated "Easy". Turned out I was solving the wrong challenge entirely.
Reading the brief is, apparently, step one.
Home lab firewall setup
Configured what I thought was an airtight firewall. Locked myself out of my own machine within 4 minutes.
Always keep a physical console cable nearby. Always.
Learning Python for automation
Wrote a script to automate a 5-minute task. Spent 3 days on the script. It now takes 8 minutes and occasionally crashes.
Automation is a spectrum. I live at the wrong end of it.
SQL injection on my own test site
Successfully injected my own database. Then forgot the backup was also on the same machine. Gone.
Backups exist. Use them. Before, not after.
Understanding cryptography properly
Started studying cryptography in 2022. Still not sure what I'm doing. The maths laughs at me daily.
Humility: the only thing I've mastered so far.
Your next exhibit
Replace this card with something you tried, broke, or regret. The museum is always accepting donations.
To be determined. Probably soon.
// 5 exhibits on display · more being produced in real time
Writing
Let's talk