_ __ _ __ __ _ _ | |/ / / \ | \/ | / \ | | | ' / / _ \ | |\/| | / _ \ | | | . \ / ___ \| | | |/ ___ \| |___ |_|\_\/_/ \_\_| |_/_/ \_\_____|
HELLO, I'M KAMAL!
I'm a final-year Cybersecurity student at Vilnius University Kaunas Faculty. I focus on penetration testing, red teaming, digital forensics, and defensive security. I love breaking things ethically to understand how to build them stronger — whether it's a web app, a network, or an AI-driven IDS.
|
🎓 Education: Final-year BSc in Information Systems and Cyber Security, Vilnius University 📘 Additional Training: Cyber Security (Online) – 10 month course, Code Academy. Finished with High-Honour Diploma 📜 Certifications: CompTIA Security+, HTB CPTS, eJPT, CRTA, Sliver C2 🧪 Experience: Cybersecurity Intern @ Extramus EU; Student Intern @ UAB NOD BALTIC (ESET Antivirus Lietuva) |
🎯 Focus: Penetration testing, red teaming, digital forensics, malware analysis, network security, AI-driven IDS 🚀 Goal: Senior Red Team Operator 📚 Currently preparing for: CRTO (Certified Red Team Operator) exam 🛠️ Open Source: TornadoRevC2, XXERipper, CorsRipper, AI-based IDS, StaticSentinel, Libvirt/KVM migration tool 📌 Bachelor Thesis: AI-Powered Intrusion Detection System using ML, behavioral heuristics, and threat intelligence ⚡ Approach: Ethical hacking, build-to-defend, automate repetitive security work, document everything. |
|
[TornadoRevC2] Modular Post-Exploitation Framework Lightweight C2 framework in Python for Linux & Windows. Supports reverse/bind shells over TCP, TLS, mTLS, 63+ plugins, SOCKS5 pivoting, in-memory payload execution, and SHA-256 verified file transfers. |
[XXERipper] Black-Box XXE Scanner Open-source XXE scanner supporting 30+ attack techniques (in-band, blind/OOB, SSRF, cloud metadata, WAF bypass). Features differential parser fingerprinting, confidence scoring, and JSON/SARIF/HTML reporting. |
|
[CorsRipper] Advanced CORS Security Assessment Detects and correlates exploit chains: credentialed CORS, CSRF bypass, OAuth token exposure, WebSocket Origin trust, GraphQL introspection, CDN cache poisoning, postMessage abuse, and timing side channels. |
[Enterprise AI-based IDS] AI-Powered Intrusion Detection System Modular network security monitoring platform combining real-time packet capture, hybrid AI models, behavioral heuristics, and threat intelligence. Flask dashboard, Zeek integration, multi-process resilient architecture. |
|
[StaticSentinel] YARA-based Static Malware Analysis Assesses files without executing them using YARA rule matching, entropy analysis, SHA-256 hashing, and VirusTotal lookups. Heuristic scoring reduces false positives and provides human-readable verdicts. |
[Libvirt/KVM VM Migration Tool] Data-Integrity-First VM Export/Import Open-source utility for exporting and importing KVM virtual machines. Every file SHA-256 verified, qcow2 backing chains validated, authenticated encryption with GnuPG and OpenSSL, plus hardening against twelve classes of Bash failure modes. |
┌──[kamalx06@parrot]──[~] │ │ $ whoami │ pentester │ │ $ cat /etc/role │ red_teamer │ │ $ cat /etc/goal │ senior_red_teamer │ └──╼ $ |
kamalx06@github |
