Secure systems, software, and threat analysis.

Computer Science and Cybersecurity student focused on building, breaking, and explaining systems clearly.

Reverse EngineeringCS + CybersecurityMay 2027OS Teaching Assistant

ABOUT

Computer Science and Cybersecurity major focused on secure systems, networking, threat analysis, and clear technical communication.

candidate.profile

Who I Am

My work sits between software engineering, security operations, and offensive labs. I like understanding systems deeply enough to build them, defend them, and explain where they fail.

Teaching is part of that identity too. As an Operating Systems TA and STEM instructor, I practice breaking complex ideas into clear, useful explanations.

Degree

B.S. Computer Science & Cybersecurity

Expected

May 2027

GPA

3.30

Academic Role

Operating Systems TA

Location

Amityville, NY

Professional Lenses

SOC / SIEM Detection

Splunk SPL, KQL, authentication logs, web logs, detection logic, and triage notes.

Security Engineering

TLS, DNS, SSH, Linux hardening, identity, secure configuration, and network defense.

Offensive Security

Exploit reproduction, GDB, shellcode, command injection, and low-level debugging.

Software Engineering

Backend APIs, data models, testing, automation, and full-stack project work.

Relevant Coursework

Operating SystemsNetwork SecurityEthical HackingData Communications and NetworkingSoftware EngineeringDatabase ManagementData Structures and AlgorithmsIntro to Cryptography

EXPERIENCE

Teaching, mentoring, and technical work mapped to the internship paths I am pursuing.

leadership.timeline

Dr. Shan

Teaching Assistant, Operating Systems

Hofstra University • Hempstead, NY

Tutor students on processes, threads, scheduling, synchronization, memory management, file systems, and course assignments.

January 2024 - Present

STEM Teacher

Snapology • Westbury, NY

Lead robotics and engineering sessions for 100+ students through hands-on STEM activities.

March 2023 - November 2023

Coding Coach

The Coder School • Bellmore, NY

Taught Python and Scratch through project-based debugging and programming practice.

Internship lane

SOC / Detection

SIEM searches, failed-login logic, packet captures, triage, and investigation notes.

Splunk SPLKQLWiresharkLinux auth logsMITRE mappingAlert tuning

Internship lane

Security Engineering

Secure service setup, TLS, DNS, SSH, Linux, identity, and infrastructure controls.

TLS / X.509ApacheBind9LDAPNFSHashcat

Internship lane

Offensive Security

Exploit reproduction, shellcode analysis, GDB, protocol abuse, and reporting.

GDBMetasploitBurp SuiteNmapAssemblyExploit dev

Internship lane

Software / Backend

Secure APIs, telemetry pipelines, testing, data models, and CLI workflows.

Node.jsTypeScriptPythonPostgreSQLPrismaJest / Pytest

PROJECTS

A few representative builds across phishing analysis, detection engineering, and secure backend systems.

LABS

A condensed archive of hands-on security, systems, and C++ work. Open the full archive only if you want the deeper list.

all.labs.archive

Password Hashing and Hashcat Cracking

Used Hashcat in Kali to crack unsalted and salted hashes with dictionary, mask, and brute-force attacks; analyzed MD5, SHA256, salts, password policy design, rockyou.txt, and recovered weak passwords including password123, Apple12, hack, dr@ag0nf1re, bubbles, and hunter2.

Web Application Security: SQL Injection

Completed PortSwigger SQL injection labs using Burp Suite to inspect requests, alter vulnerable URL parameters, retrieve hidden product data, and bypass authentication into an administrator account.

Web Application Security: Cross-Site Scripting

Completed reflected, stored, attribute-based, and DOM XSS labs using Burp Proxy, HTTP history, and Repeater to test payload placement, output encoding gaps, and unsafe client-side sinks.

Lab Repositories

Public writeup archives for the security lab work below.

Password Hashing and Hashcat Cracking

Used Hashcat in Kali to crack unsalted and salted hashes with dictionary, mask, and brute-force attacks; analyzed MD5, SHA256, salts, password policy design, rockyou.txt, and recovered weak passwords including password123, Apple12, hack, dr@ag0nf1re, bubbles, and hunter2.

Web Application Security: SQL Injection

Completed PortSwigger SQL injection labs using Burp Suite to inspect requests, alter vulnerable URL parameters, retrieve hidden product data, and bypass authentication into an administrator account.

Web Application Security: Cross-Site Scripting

Completed reflected, stored, attribute-based, and DOM XSS labs using Burp Proxy, HTTP history, and Repeater to test payload placement, output encoding gaps, and unsafe client-side sinks.

Network Forensics with Wireshark

Investigated multi-PCAP evidence covering scanning, exposed credentials, DNS C2, ICMP fragmentation, credential harvesting, DoS traffic, geolocation, FTP exfiltration, SQL injection, web shells, Zerologon, and malware behavior.

Wireshark and Protocol Analysis

Captured and filtered ICMP, HTTP, and TCP traffic; inspected Ethernet II and IPv4 headers, followed HTTP streams, and identified TCP three-way handshake behavior for troubleshooting and protocol analysis.

Denial-of-Service Testing

Ran controlled SYN flood simulations with Scapy and Netwox against a Telnet service, monitored traffic in Wireshark, compared tool behavior, and analyzed TCP connection impact in an authorized virtual lab.

Splunk and KQL SOC Investigation Labs

Practiced SPL and KQL investigations across Linux authentication logs, web access logs, failed SSH attempts, brute-force logic, 404/scanning behavior, timelines, field extraction, joins, dashboards, false-positive tuning, and MITRE ATT&CK mapping.

Replay Attack

Captured and modified HTTP traffic with tcpdump and netcat, then wrote savepasswd.py to restore critical system files and complete the workflow end to end.

DNS Setup and Port Scan

Performed authorized DNS enumeration, added records, hardened Bind9, mapped services with nmap and lsof, and completed OS fingerprinting analysis.

Metasploit Penetration Testing

Exploited MS08-067 for remote shell access, uploaded files with Meterpreter, tested Armitage automation, and proposed layered defenses.

Command Injection Exploit & Mitigation

Reproduced automated mass-account creation through command injection, then implemented and verified input sanitization in C.

Metasploit Exploit Development & Session Analysis

Developed and debugged custom Metasploit exploits and analyzed session behavior using Wireshark and Ruby debugging.

ICTF’07: Ruby & Metasploit

Deployed and extended the grader, re-IP’d cloned VMs, mapped PHP flag flow, and built a one-command Ruby exfiltration and submission pipeline.

Sound of Music: Penetration Test

Built a durable one-command exploit with programmatic login, cookie handling, server-side include abuse, and proxied submission for consistent scoring.

C Pointers & GDB

Built an 8-digit zero-padded hex printer, fixed setvar for n=200, reasoned through addresses precisely, and stepped bubble_sort instruction by instruction in GDB.

Assembly & GDB

Implemented cat.cc with execve, analyzed static-linked ls assembly, and extracted main() machine code into a shellcode-style character array for inspection.

Stack Exploitation

Mapped a full fib stack frame and crafted Perl payloads to crash execution at 0x41414141 and redirect control flow to greeting().

Buffer Overflow & Shellcode

Recovered setuid and execve parameters from shellcode, explained JMP/CALL position independence, and built a working exploit payload using GDB-derived offsets.

Remote Buffer Overflow & Metasploit

Reproduced the peercast3 exploit, analyzed linux/x86/shell_bind_tcp, traced execution at JMP ESP, and wrote a syscall-level bind shell report.

Heap Spray / Browser Exploits

Reproduced crashes, proved shellcode control in Immunity Debugger, installed mangleme, and built a Unicode-safe heap spray that triggered calc.exe.

Format String Exploitation

Leaked main() return addresses with crafted %p payloads, used format-string writes to set a global Canary, and proposed a hardened post-compile PatchMe rewriter.

Game Hacking with OpenRA

Modified OpenRA source to reduce soldier cost to $1, patched the Makefile with sed, automated fixes, and debugged C# syntax errors to simulate exploit-style manipulation.

Linux Command-Line Challenge

Completed a timed Linux training bot covering file navigation, permissions, scripting, and fast CLI execution inside a scored environment.

Linux File Forensics

Solved timed Linux analysis tasks using md5sum, chmod, xxd, sed, and grep for checksums, permissions, nested search, and precise file editing.

Encrypted Messaging & Access Control

Configured Linux mail with ygm, applied Base64 and AES encryption, managed users, set file permissions, and deployed SUID programs for controlled access.

SSL Certificate Configuration & HTTPS Deployment

Generated and signed CSRs with OpenSSL, deployed HTTPS certs to Apache, and handled private/public key use, X.509 certs, and secure transfers.

Linux Process & Log Analysis

Used ps, strace, grep, kill, and crontab to identify malicious processes, interpret outputs, terminate threats, and automate parts of system hardening.

Secure Network Configuration & SSH Setup

Configured OpenSSH, troubleshot routing issues, fixed Netplan interfaces, secured SFTP transfers, and configured DNS using Bind9.

LDAP-Based Single Sign-On

Configured LDAP for centralized authentication, resolved service discovery issues with DNS and strace, and created secure user group models.

NFS Deployment & Authentication

Built an NFS server for distributed file sharing, maintained file ownership and permissions, and integrated LDAP-based authentication.

String Patterning & BMI Calculation

Wrote nameDiamond() using substring logic and nested loops, plus a BMI calculator with modular functions and classification logic.

Vector Filtering & Element Removal

Implemented countInRange() and removeAll() with reverse iteration to safely modify vectors in place.

Nearest Smaller Value via Stack

Implemented nearest_smaller_to_right() with a stack and careful edge-case handling.

Vote Counting via HashMap

Built tallyVote() to track character frequencies and answer queries efficiently with hashmap-based lookup.

Recursive Power & Decimal Printing

Wrote myPow() with negative-power handling and printDecimal() for fixed-length base-10 formatting via recursion.

Unique Vector Permutations

Implemented permute() using recursion and sets to generate only unique permutations.

Word Search in 2D Grid

Built exist() using DFS-style backtracking with visited-state handling so each cell is used at most once.

Merge Two Sorted Linked Lists

Created a non-recursive merge routine without auxiliary memory, focusing on pointer manipulation and edge cases.

Template List Concatenation

Extended a custom linked-list template by overloading the + operator for list concatenation.

Remove Duplicates in Sorted List

Implemented deleteDuplicates() to remove all duplicate values from a sorted linked list in a single traversal.

Second Minimum in Special Binary Tree

Implemented findSecondMinimumValue() with recursion and tree traversal logic to detect the second smallest unique value.

CONTACT

Open to remote, hybrid, on-site, and relocation-friendly internships in security or software engineering.

contact.compose

Send a Message

Use the form if you want to talk internships, projects, labs, or collaboration. The form opens your default mail client with the message prefilled.