4th-year Cybersecurity Engineering student at ENSIASD Taroudant (Sécurité IT et Confiance Numérique). I design, build and attack my own infrastructure to really understand how it breaks — three self-driven lab projects below cover cloud security, SOC/SIEM operations, and enterprise network security end to end: architecture, hardening, detection, and a real offensive test against each one.
Currently looking for a 2-month internship to apply these skills in a structured professional environment.
A virtualized enterprise network — 4 security zones, a DMZ security chain (WAF → reverse proxy → app), a Windows Active Directory domain, and a Wazuh SIEM — tested against a 23-attack red-team campaign (recon, brute force, privilege escalation, DoS, web exploitation), with detection validated and a countermeasure documented for every attack executed.
pfSense Wazuh Active Directory ModSecurity MITRE ATT&CK Blue Team / Red Team
Enterprise network infrastructure secured with a FortiGate NGFW, Active Directory with GPO-based access control, and DMZ segmentation — validated through offensive testing (DDoS simulation, SQLi/XSS pentests, segmentation checks).
FortiGate NGFW Active Directory GPO DMZ Defense in Depth
Secured a real AWS VPC with a custom Linux firewall (iptables/nftables) and inline Suricata IDS/IPS, deployed a Wazuh SIEM from scratch, hardened every instance against the CIS AWS Foundations Benchmark, then pentested my own infrastructure (Nmap, Burp Suite SQLi/XSS) and closed a real detection gap with a self-deployed ModSecurity WAF — all for ~$2.79 of AWS credit.
AWS Wazuh Suricata iptables/nftables CIS Benchmark ModSecurity CloudTrail
Network Security: pfSense · FortiGate NGFW · ModSecurity WAF · Wazuh SIEM · Wireshark · Nmap · IDS/IPS
Systems & Infrastructure: Active Directory · GPO · Windows Server · Ubuntu Server · Kali Linux · Bastion Host
Offensive Security: Burp Suite · Metasploit · SQLi · XSS · DDoS (k6) · CTF (TryHackMe)
Cloud: AWS (VPC, EC2, IAM, CloudTrail, EBS)
Languages & Tools: Python · Bash · Git · VirtualBox / VMware
TryHackMe — Cyber Security 101 · Pre Security · Web Fundamentals · Jr Penetration Tester · Advent of Cyber 2025
Open to internship opportunities — feel free to reach out on LinkedIn or by email.