CSE Student · Penetration Testing · Security Analysis

Rashu

Computer Science student focused on penetration testing, security analysis, and practical security research.

Degree
BSc in Computer Science & Engineering
Institution
Northern University Bangladesh

About

I'm a Computer Science & Engineering student at Northern University Bangladesh with a focused interest in offensive and defensive security. My work centres on penetration testing techniques, SOC workflows, and malware analysis — areas I develop through structured lab practice rather than simulated exercises.

Most of my learning happens hands-on: working through machines and challenges on Hack The Box, completing structured paths on TryHackMe, and building analysis tooling independently. I prefer evidence-based learning over passive study.

I'm currently developing practical skills across web application security, network enumeration, incident handling, and malware analysis. My goal is to build a consistent, documented body of work that reflects genuine technical progress.

Credentials

Professional certifications and training courses.

Certifications

Certified Red Team Analyst (CRTA)

[YEAR]

CyberWarFare Labs

Practical red team assessment certification covering Active Directory enumeration, lateral movement, and post-exploitation techniques in lab environments.

Credential link pendingID pending

Certified Defensive Security Analyst (CDSA)

[YEAR]

Hack The Box

Certification validating skills in SOC operations, incident handling, log analysis, and SIEM-based detection workflows.

Credential link pendingID pending

Training & Courses

  • Ethical Hacking for Professionals

    [YEAR]

    Byte Capsule

    Structured training covering penetration testing methodology, enumeration, and exploitation techniques.

  • Cybersecurity Fundamentals

    [YEAR]

    Hack To Live

    Foundational cybersecurity concepts including networking, security principles, and threat modelling. Contributed to course coordination activities.

  • [AWS SECURITY COURSE NAME — TO BE PROVIDED]

    [YEAR]

    AWS / [PROVIDER]

    Cloud security training covering AWS security services and configurations. Update with exact course name.

Security Labs & Practice

Hands-on practice through structured lab environments. Placeholder values will be updated as progress is documented.

Hack The Box

View Profile →
Rank
[RANK]
Machines Rooted
[COUNT]
Challenges Completed
[COUNT]

Primary practice platform for network enumeration, privilege escalation, and Active Directory attack paths.

Rank
[RANK]
Rooms Completed
[COUNT]

Structured learning paths covering SOC fundamentals, web application security, and Linux security.

CyberWarFare Labs

View Profile →
Labs Completed
[COUNT]

Red team lab environment used for CRTA preparation and Active Directory attack simulation.

* Bracketed values are placeholders. Update /data/portfolio.ts with actual statistics.

Projects

Security tools, analysis environments, and research work. Add projects by editing /data/portfolio.ts.

Malware Analysis Lab

In Progress

Malware Analysis

A local malware analysis environment with tooling for static analysis of PE binaries. Covers PE header parsing, section entropy analysis, imported API inspection, hash verification, and IOC extraction. Designed to support systematic triage of unknown samples.

PythonPE StudioGhidraCyberChefDetect-It-Easy

Security Reconnaissance Toolkit

Planned

Reconnaissance & Enumeration

[PROJECT DESCRIPTION — describe the scanning or reconnaissance functionality. Include tools integrated, scope, and intended use case.]

PythonNmapAmass[ADD TOOLS]
Repository pending

[PROJECT NAME]

Planned

[SECURITY DOMAIN]

[PROJECT DESCRIPTION — describe the project scope, security domain, and what was built or investigated.]

[TOOL][TOOL]
Repository pending

Writeups & Research Notes

Security research notes, machine writeups, and lab documentation.

Tools & Security Skills

Organised by security workflow. No percentage ratings — proficiency develops continuously through practice.

Reconnaissance & Enumeration

  • Nmap
  • Amass
  • Assetfinder
  • HTTP probing
  • Gobuster
  • FFUF

Web Application Security

  • Burp Suite
  • OWASP Top 10
  • PortSwigger Web Security Academy
  • OWASP Juice Shop
  • OWASP WebGoat

Network & Infrastructure

  • Wireshark
  • Nmap
  • SMB enumeration
  • SSH enumeration
  • Network traffic analysis

Defensive Security / SOC

  • Incident handling
  • Windows security
  • SIEM concepts
  • Log analysis
  • MITRE ATT&CK
  • Cyber Kill Chain

Malware Analysis

  • PE analysis
  • Static analysis
  • IOC extraction
  • Entropy analysis
  • Python-based analysis tooling

Scripting & Automation

  • Python
  • Bash
  • Linux shell scripting

Current Learning Focus

Active areas of study and practice — not claimed professional expertise.

Contact

Available for security internships, part-time roles, and collaborative projects.