Security Projects

Practical demonstrations of security assessment skills on intentionally vulnerable applications and platforms.

API Security Medium

crAPI

OWASP

API security assessment of the Completely Ridiculous API (crAPI) vulnerable application. Explored REST API vulnerabilities including broken authentication, excessive data exposure, mass assignment, and security misconfiguration.

Burp SuitePostmancURLOWASP ZAP
View Project
Penetration Testing Medium

Hack The Box Labs

Hack The Box

Active penetration testing practice on Hack The Box platform machines. Each machine involves systematic reconnaissance, service enumeration, vulnerability identification, exploitation, and privilege escalation in controlled environments.

NmapMetasploitBurp SuiteGobusterLinPEAS +1
View Project
Web Application Security Medium

OWASP Juice Shop

OWASP

Systematic security testing of the OWASP Juice Shop vulnerable application. Focused on authentication bypass, injection attacks, client-side security, and business logic vulnerabilities using both manual and automated techniques.

Burp SuiteBrowser DevToolsOWASP ZAPSQLMap
View Project
Web Application Security Hard

VulnBank

Custom Lab

A comprehensive security assessment of an intentionally vulnerable banking web application. Conducted full reconnaissance, vulnerability identification, exploitation, and documented findings with remediation guidance.

Burp SuiteNmapNiktoGobusterSQLMap +1
View Project
Cybersecurity Labs Easy

TryHackMe Learning Paths

TryHackMe

Structured learning paths and practical labs on TryHackMe covering web security, network security, enumeration, privilege escalation, and vulnerability assessment. Completed multiple rooms and learning paths to build foundational and intermediate skills.

NmapMetasploitBurp SuiteWiresharkGobuster
View Project