Hands-on DoS and DDoS attack fundamentals lab featuring Wireshark traffic analysis, Bash and Python automation, TCP/IP analysis, and defensive mitigation techniques.
-
Updated
Jul 3, 2026 - Python
Hands-on DoS and DDoS attack fundamentals lab featuring Wireshark traffic analysis, Bash and Python automation, TCP/IP analysis, and defensive mitigation techniques.
Full network/system penetration test of Metasploitable 2 — recon → root compromise (Samba RCE, ingreslock, MySQL/PostgreSQL default creds) → post-exploitation, with reports, per-finding write-ups, ATT&CK mapping, and blue-team Sigma detection rules.
Cracked 6 out of 7 user password hashes from an intentionally vulnerable open-source Linux system (Metasploitable 2) using real-world password cracking techniques with tools like John the Ripper and Hashcat. This project was executed during my cybersecurity internship to simulate real-world password auditing on a compromised system.
Vulnerability Risk Assessment lab using Nessus Essentials — 69 vulnerabilities discovered, 6 Criticals (CVSS 9.8–10.0), P1–P4 risk register produced with business impact analysis. Mapped to ISO 27001 Annex A & NIST CSF. GRC-focused documentation with audit-grade remediation report.
Vulnerability assessment of a legacy smart city server managing traffic monitoring and smart streetlights. Conducted using Nessus and Kali Linux, mapped to CIS Controls v8.1.
A hands-on internal penetration testing lab covering reconnaissance, vulnerability validation, exploitation, impact analysis, and remediation.
Step-by-step guide to scanning and exploiting Metasploitable2 ports with practical examples. – clear, professional, and searchable.
PenTest Lab 9 — OSINT, Recon & Exploitation of Metasploitable2 | Metasploit, Nmap, Censys | 4/4 Exploits Successful | ROOT Access via vsftpd & Samba CVEs
A documented penetration testing lab built on Kali Linux and Metasploitable2, walking through a full attack chain from network traffic analysis and service enumeration through to exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) and achieving root access. Includes blue team detection notes and MITRE ATT&CK mapping throughout.
Network reconnaissance project using Nmap against a Metasploitable 2 virtual machine in an isolated VMware Workstation lab.
End-to-end Metasploitable2 vulnerability management & hardening — scans, remediation, verification
End-to-End SOC Investigation Lab using Kali Linux, Metasploitable2, Nmap, Wireshark and VirtualBox for network verification, service enumeration, traffic analysis, evidence collection and security assessment.
VAPT lab implementing automated vulnerability scanning and exploitation workflows. Features network reconnaissance with Nmap, targeted CVE verification via Metasploit against a sandboxed target, and root-level privilege escalation mapping.
🛡️ Mise en place d'un laboratoire de Pentest (Sandbox VMware). Documentation complète du cycle d'attaque : de la Reconnaissance à l'Exploitation (Root) sur Metasploitable 2 via Kali Linux.
A comprehensive penetration testing report detailing 46 security vulnerabilities discovered during a full-scope assessment of a Metasploitable2 lab environment. Findings include Network Services, Web Applications, Privilege Escalation, and Enumeration vulnerabilities.
Penetration testing lab on Metasploitable2 — exploiting vsftpd backdoor, Samba, and MySQL vulnerabilities using Nmap, Nikto, and Metasploit on Kali Linux
VAPT project on Metasploitable 2 demonstrating exploitation, privilege escalation, and OWASP Top 10 vulnerabilities.
Vulnerability assessment of a legacy infrastructure system acquired by XYZ Financial Services. Conducted using Nessus and Kali Linux, mapped to CIS Controls v8.1.
Cyber Security Professional with 7 years of QA/QC engineering experience and 2+ years of hands-on Penetration Testing. I specialize in turning a rigorous quality-control mindset into aggressive offensive security testing. My repositories focus on automation scripts, network infrastructure exploitation, and security lab deployments.
Virtual machines full of intentional security vulnerabilities. Exploit at will! Metasploitable is essentially a penetration testing lab in a box created by the Rapid7 Metasploit team.
Add a description, image, and links to the metasploitable2 topic page so that developers can more easily learn about it.
To associate your repository with the metasploitable2 topic, visit your repo's landing page and select "manage topics."