Skip to content
View kamalx06's full-sized avatar

Block or report kamalx06

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kamalx06/README.md
  _  __    _    __  __    _    _     
 | |/ /   / \  |  \/  |  / \  | |    
 | ' /   / _ \ | |\/| | / _ \ | |    
 | . \  / ___ \| |  | |/ ___ \| |___ 
 |_|\_\/_/   \_\_|  |_/_/   \_\_____|
Terminal Init Roles

HELLO, I'M KAMAL!

I'm a final-year Cybersecurity student at Vilnius University Kaunas Faculty. I focus on penetration testing, red teaming, digital forensics, and defensive security. I love breaking things ethically to understand how to build them stronger — whether it's a web app, a network, or an AI-driven IDS.


GitHub LinkedIn CompTIA Security+ HTB CPTS Views



Professional Snapshot

🎓 Education: Final-year BSc in Information Systems and Cyber Security, Vilnius University

📘 Additional Training: Cyber Security (Online) – 10 month course, Code Academy. Finished with High-Honour Diploma

📜 Certifications: CompTIA Security+, HTB CPTS, eJPT, CRTA, Sliver C2

🧪 Experience: Cybersecurity Intern @ Extramus EU; Student Intern @ UAB NOD BALTIC (ESET Antivirus Lietuva)

🎯 Focus: Penetration testing, red teaming, digital forensics, malware analysis, network security, AI-driven IDS

🚀 Goal: Senior Red Team Operator

📚 Currently preparing for: CRTO (Certified Red Team Operator) exam

🛠️ Open Source: TornadoRevC2, XXERipper, CorsRipper, AI-based IDS, StaticSentinel, Libvirt/KVM migration tool

📌 Bachelor Thesis: AI-Powered Intrusion Detection System using ML, behavioral heuristics, and threat intelligence

⚡ Approach: Ethical hacking, build-to-defend, automate repetitive security work, document everything.


Core Focus

Offensive Security: Penetration testing (web, OS, network, infrastructure), Active Directory enumeration & attack-path analysis, vulnerability assessment, exploit development.

Digital Forensics & Malware Analysis: Evidence analysis, incident investigation, reverse engineering of malicious code, threat detection, data recovery.

Defensive Security: SIEM/IDS/IPS/WAF deployment (Wazuh, Suricata, ModSecurity, SafeLine), NGFW configuration (Palo Alto VM-Series), network segmentation, hardening.

AI & Automation: AI-driven intrusion detection using machine learning, behavioral analysis, Python/Bash scripting for security automation, tool development.

Technology Stack

Languages & Scripting

OS & Infrastructure

Reconnaissance & OSINT

Web Application Security

Active Directory & Internal

Command & Control / Exploitation

Credential Access & Cracking

Pivoting & Tunneling

Cloud & Container Security

Forensics, RE & Malware Analysis

Wireless & Hardware

Defensive Stack


Recent Projects

[TornadoRevC2]
Modular Post-Exploitation Framework

Lightweight C2 framework in Python for Linux & Windows. Supports reverse/bind shells over TCP, TLS, mTLS, 63+ plugins, SOCKS5 pivoting, in-memory payload execution, and SHA-256 verified file transfers.
[XXERipper]
Black-Box XXE Scanner

Open-source XXE scanner supporting 30+ attack techniques (in-band, blind/OOB, SSRF, cloud metadata, WAF bypass). Features differential parser fingerprinting, confidence scoring, and JSON/SARIF/HTML reporting.
[CorsRipper]
Advanced CORS Security Assessment

Detects and correlates exploit chains: credentialed CORS, CSRF bypass, OAuth token exposure, WebSocket Origin trust, GraphQL introspection, CDN cache poisoning, postMessage abuse, and timing side channels.
[Enterprise AI-based IDS]
AI-Powered Intrusion Detection System

Modular network security monitoring platform combining real-time packet capture, hybrid AI models, behavioral heuristics, and threat intelligence. Flask dashboard, Zeek integration, multi-process resilient architecture.
[StaticSentinel]
YARA-based Static Malware Analysis

Assesses files without executing them using YARA rule matching, entropy analysis, SHA-256 hashing, and VirusTotal lookups. Heuristic scoring reduces false positives and provides human-readable verdicts.
[Libvirt/KVM VM Migration Tool]
Data-Integrity-First VM Export/Import

Open-source utility for exporting and importing KVM virtual machines. Every file SHA-256 verified, qcow2 backing chains validated, authenticated encryption with GnuPG and OpenSSL, plus hardening against twelve classes of Bash failure modes.



Developer Card

  ┌──[kamalx06@parrot]──[~]
  │
  │ $ whoami
  │ pentester
  │
  │ $ cat /etc/role
  │ red_teamer
  │
  │ $ cat /etc/goal
  │ senior_red_teamer
  │
  └──╼ $

kamalx06@github
-------------------------
Name: Kamal
Focus: Penetration Testing / Red Teaming / AI Security
Education: Vilnius University, Cybersecurity (final year)
Certifications: CompTIA Security+, HTB CPTS
Current Stack: Python, Bash, Linux, Windows, Security Tooling
Currently Preparing: CRTO (Certified Red Team Operator)
Goal: Senior Red Team Operator
Status: Building, breaking, and learning.


GitHub Streak

Pinned Loading

  1. TornadoRevC2 TornadoRevC2 Public

    A lightweight, modular post-exploitation framework for Linux and Windows. Manages interactive reverse/bind shell sessions over TCP/TLS/mTLS and provides plugins for enumeration, execution, pivoting…

    Python 34 7

  2. XXERipper XXERipper Public

    Production-grade XXE scanner that combines statistical baselining, differential parser fingerprinting, and OOB confirmation to find what naive scanners miss. 30+ attack techniques, credential extra…

    Python 6

  3. CorsRipper CorsRipper Public

    CORS exploitation and impact analysis engine focused on CSRF, OAuth abuse, cache poisoning, and cross-origin trust failures.

    Python 3

  4. ids-bachelor-thesis ids-bachelor-thesis Public

    AI based IDS Project for Bachelor Thesis

    Python

  5. StaticSentinel StaticSentinel Public

    YARA based static malware analysis tool that performs rule matching, entropy analysis, and VirusTotal hash lookups to assess files and avoid false positives

    Python

  6. libvirt-vm-migration libvirt-vm-migration Public

    Safety-first Bash utility for exporting and importing libvirt/KVM VMs. Preserves QCOW2 backing chains and snapshot metadata, verifies with SHA-256 before and after restore, refuses to produce incom…

    Shell