Hi, I'm Muhammad Ehtisham

Cybersecurity Professional | Freelancer | Student

Securing digital assets and exploring the evolving landscape of cybersecurity with expertise and innovation.

Muhammad Ehtisham

About Me

About Muhammad Ehtisham

Cybersecurity Professional

I'm Final year Cybersecurity student and freelancer passionate about protecting digital infrastructures and solving security challenges. My journey in this field has been driven by curiosity and a commitment to making the enhancing the security and resilience of digital infrastructures.

I am committed to expanding my skills in penetration testing, threat detection, and system hardening while adapting to emerging technologies. With a strong focus on industry-oriented solutions, my goal is to build a solid foundation in cybersecurity and grow into a productive security professional.

Name:

Muhammad Ehtisham

Education:

Bachelor's in Cybersecurity Air University 2022-Present

Experience:

Entry Level

Freelance:

Available

My Skills

Technical Skills

Network Security

Vulnerability Assessment

Penetration Testing

Intrusion Detection

Defensive Security & Threat Monitoring

Cloud Security

Tools & Technologies

Kali Linux Wireshark Metasploit Burp Suite Nmap Wazuh-SIEM Bash OWASP ZAP Snort Nessus Docker AWS Azure

My Projects

Troubleshooting and Implementing Wazuh SIEM Solution at Power Plant

Troubleshooting and Implementing Wazuh SIEM Solution at Power Plant.

Resolved SIEM misconfigurations, deployed Wazuh SIEM, and restored SCADA-Servers and Pfsence Firewall communication, enhancing security and monitoring.

SOC Risk Assessment
Wazuh SIEM Solution on Microsoft Azure

Deployed Cloud-Based Wazuh SIEM Solution on Microsoft Azure.

This project involved deploying and configuring a Wazuh SIEM solution on Microsoft Azure to enhance security monitoring and threat detection. The implementation included log collection, rule customization, and integration with cloud resources for real-time analysis.

Cloud Security Logs Analysis
Cloud Security Audit

Cloud Security Audit & Misconfiguration Assessment

This project focused on identifying and mitigating critical cloud security misconfigurations that could lead to data breaches and unauthorized access. During the assessment of a cloud-hosted environment, several vulnerabilities were uncovered, including open directory listings, exposed AWS credentials, unauthenticated Kubernetes API endpoints, and leaked system files. Each of these misconfigurations posed significant security risks, such as privilege escalation and system compromise. flag{AI_Security_and_Cloud_are_Million$_Skills}

Security Assessment Exploitation
Exploring IBM QRadar SIEM

Exploring IBM QRadar SIEM

This project showcases my hands-on experience with IBM QRadar SIEM, where I learned how it collects, normalizes, and correlates logs from various sources to detect security threats effectively. I explored offense investigation techniques, created custom detection rules, and worked with the powerful dashboard interface for real-time threat monitoring.

Network Security QRadar SIEM
DVWA Web Server Penetration Testing

DVWA Web Server Penetration Testing

This project focuses on penetration testing of the Damn Vulnerable Web Application (DVWA), a deliberately insecure web application designed for security professionals and ethical hackers to practice vulnerability assessment. The testing includes SQL Injection, Cross-Site Scripting (XSS), Command Injection, CSRF, and authentication bypass techniques. The goal is to identify and exploit security weaknesses while implementing best practices for web application security hardening.

DVWA PenetrationTesting
Honeypot Deployment on DigitalOcean with IDS Monitoring

Honeypot Deployment on DigitalOcean with IDS Monitoring

Deployed a custom Honeypot Server on Ubuntu within DigitalOcean Cloud, integrating Suricata and Wazuh for real-time threat detection. Captured SSH brute-force attempts and OWASP Top 10 attack activities, visualized through Wazuh Dashboard for security analysis.

Honeypot OWASP

Certifications

(ISC)² Certified in Cybersecurity (CC)

ISC2

Dec 2023

Verify

AWS Academy Graduate - AWS Academy Cloud Security Foundations

AWS

Nov 2024

Verify

SIEM Basics, Installation and Configuration

LetsDefend.io

Jan 2024

Verify

Cybersecurity Operations Fundamentals Specialization

Cisco

Sep 2023

Verify

SOC & Security Assessment Bootcamp

VaporVM Ltd

May 2024

Verify

Google Cybersecurity Specialization

Google

Aug 2023

Verify

Get in Touch

Contact Information

Feel free to reach out for collaborations, freelance work, or just to say hello!

Email

connectsham95@gmail.com

Phone

+923329979242

Location

Islamabad, Pakistan

Connect with me