Cybersecurity Practitioner

Abdul Rafay Sadiq

I build the detection that catches the intrusion — then run the intrusion to prove the detection holds.

BS Cyber Security / Air University Multan / Multan · Lahore, PK
>
projects · skills · credentials · contact
Abdul Rafay Sadiq
Abdul Rafay Sadiq

I defend infrastructure, and break into it
to make the defence stronger.

I'm Abdul Rafay Sadiq, a BS Cyber Security undergraduate at Air University Multan. I work both sides of the wire: building defences and then attacking them to find out exactly where they fail.

On the blue side, I build detection pipelines with SIEM, IDS/IPS and file-integrity monitoring, and handle the forensics when an alert fires. On the red side, I run enumeration, exploitation and privilege escalation inside isolated labs so the defenders know precisely what to watch for.

My focus is threat analysis, network monitoring, and security automation, applied to real-world infrastructure, not just theory.

08
Hands-on labs
70+
Vulns remediated
04
Security domains
03
Certifications

Defence

Monitoring, detection & response

  • Splunk
  • Wazuh
  • Suricata
  • Zeek
  • pfSense
  • IDS / IPS
  • SIEM
  • FIM

Offence

Enumeration, exploitation & escalation

  • Kali Linux
  • Metasploit
  • Nmap
  • Burp Suite
  • OWASP Top 10
  • Active Directory
  • Priv-Esc
  • HTB

Forensics & Intel

Analysis & threat intelligence

  • Wireshark
  • Ghidra
  • IoC Analysis
  • Memory Dumps
  • VirusTotal
  • MITRE ATT&CK
  • Kill Chain
  • LetsDefend

Build & Automate

Tooling & secure development

  • Python
  • C++
  • 8086 ASM
  • Sockets
  • Flask
  • n8n
  • SAST / DAST
  • DevSecOps
01
Defence

Enterprise Perimeter Defence & Deep Packet Inspection

Segmented a hardened lab perimeter and wired real-time intrusion detection into centralised monitoring.

Network Security Lab
  • Deployed and configured a pfSense firewall to segment network zones and harden the perimeter.
  • Integrated Suricata and Zeek for deep packet inspection, logging simulated intrusions in real time.
  • Forwarded telemetry to Splunk for centralised dashboards and threat-correlation alerts.
pfSense Suricata Zeek Splunk
+
02
Offence

Active Directory Exploitation & Privilege Escalation

Simulated APT behaviour in an isolated AD forest and escalated from foothold to domain administrator.

Penetration Testing Lab — HTB
  • Modelled APT tradecraft to surface misconfigurations and weak access controls.
  • Enumerated with Nmap, used Metasploit for lateral movement, escalated to domain admin.
  • Documented findings with remediation, including Zero Trust access policies.
Nmap Metasploit Active Directory HTB
+
03
Offence

Web Application Vulnerability Assessment

Intercepted and manipulated traffic to find and exploit critical OWASP Top 10 flaws, then wrote the fixes.

Application Security Lab
  • Used Burp Suite to analyse web traffic and identify SQL Injection and XSS.
  • Exploited each in a controlled environment and authored secure-coding remediations.
Burp Suite OWASP Top 10 SQLi XSS
+
04
Forensics

Digital Forensics & Malware Analysis

Hunted Indicators of Compromise across packet captures and memory, then contained the malicious channel.

Incident Response — LetsDefend
  • Analysed live captures and memory dumps for IoCs with Wireshark.
  • Correlated anomalies with VirusTotal intel to confirm malicious beacons; drafted a full IR report.
  • Implemented firewall blocking rules against the identified C2 methods.
Wireshark VirusTotal Memory Forensics IoC
+
05
Defence

Automated File Integrity Monitoring & Response

Detected unauthorised file changes in real time and automated the triage-to-response workflow.

Information Assurance
  • Built a File Integrity Monitoring system with Wazuh for critical-file change detection.
  • Designed automated detection-and-response workflows in n8n to cut manual triage.
Wazuh n8n FIM SOAR
+
06
DevSecOps

CTFd Security Assessment — SAST / SCA / DAST

Ran a full-lifecycle assessment on a 36k-line Flask app with 11 tools and remediated 70+ vulnerabilities.

Secure Software Design
  • Fixed two HIGH code risks (CWE-94, CWE-327) via CodeQL and Semgrep.
  • Patched 20 dependency CVEs using Trivy and pip-audit.
  • Simulated attacks with OWASP ZAP and Wapiti; added CSP and X-Frame-Options via Flask hooks.
CodeQL Semgrep Trivy OWASP ZAP pip-audit
+
07
Threat Intel

Cyber Threat Intelligence Fusion Center

Gathered OSINT, authored IOCs, and mapped adversary tradecraft to industry frameworks.

Cyber Threat Intelligence
  • Ran passive reconnaissance with Recon-ng, Sherlock, WHOIS and eMailTrackerPro.
  • Built malware IOCs in Mandiant IOC Editor; evaluated MISP, ThreatConnect and IBM X-Force.
  • Authored CTI reports mapping TTPs to MITRE ATT&CK and the Cyber Kill Chain.
Recon-ng Sherlock MISP MITRE ATT&CK
+
08
Cloud · Defence

Cloud-Based Network Intrusion Detection & Monitoring

Stood up a hardened AWS environment with cloud-native IDS and an automated alerting pipeline.

Network Security — AWS
  • Designed a secure AWS setup with VPCs, subnets and security groups, hardened with IAM and MFA.
  • Deployed Suricata IDS on EC2 for real-time DPI, detecting simulated Nmap probes.
  • Built a pipeline with Python, EventBridge and SNS for real-time email alerting.
  • Created a Flask dashboard for alerts, severity classification and telemetry.
AWS Suricata Python EventBridge / SNS Flask
+

Certifications

Cyber Threat Intelligence Analyst
Cybertraining365
Complete Cyber Security Course
Nathan House
LFD121 — Secure Software Development
The Linux Foundation
Urdu
Native
English
Professional

Education

BS Cyber Security
Air University Multan
Currently enrolled
Computer Networks · Network Security · Operating Systems · Information Assurance · Digital Forensics · DSA · Socket Programming · Cyber Threat Intelligence

Let's defend
something real.

location Multan · Lahore, Pakistan
Get in touch  →