Skip to content
View majidoussama's full-sized avatar

Block or report majidoussama

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
majidoussama/README.md

Hi, I'm Oussama 👋

Cybersecurity Engineering Student · Cloud Security · SOC / SIEM · Network Security

LinkedIn Email Location


About

4th-year Cybersecurity Engineering student at ENSIASD Taroudant (Sécurité IT et Confiance Numérique). I design, build and attack my own infrastructure to really understand how it breaks — three self-driven lab projects below cover cloud security, SOC/SIEM operations, and enterprise network security end to end: architecture, hardening, detection, and a real offensive test against each one.

Currently looking for a 2-month internship to apply these skills in a structured professional environment.


🛠️ Featured Projects

A virtualized enterprise network — 4 security zones, a DMZ security chain (WAF → reverse proxy → app), a Windows Active Directory domain, and a Wazuh SIEM — tested against a 23-attack red-team campaign (recon, brute force, privilege escalation, DoS, web exploitation), with detection validated and a countermeasure documented for every attack executed.

pfSense Wazuh Active Directory ModSecurity MITRE ATT&CK Blue Team / Red Team

Enterprise network infrastructure secured with a FortiGate NGFW, Active Directory with GPO-based access control, and DMZ segmentation — validated through offensive testing (DDoS simulation, SQLi/XSS pentests, segmentation checks).

FortiGate NGFW Active Directory GPO DMZ Defense in Depth

Secured a real AWS VPC with a custom Linux firewall (iptables/nftables) and inline Suricata IDS/IPS, deployed a Wazuh SIEM from scratch, hardened every instance against the CIS AWS Foundations Benchmark, then pentested my own infrastructure (Nmap, Burp Suite SQLi/XSS) and closed a real detection gap with a self-deployed ModSecurity WAF — all for ~$2.79 of AWS credit.

AWS Wazuh Suricata iptables/nftables CIS Benchmark ModSecurity CloudTrail


🧰 Skills

Network Security: pfSense · FortiGate NGFW · ModSecurity WAF · Wazuh SIEM · Wireshark · Nmap · IDS/IPS

Systems & Infrastructure: Active Directory · GPO · Windows Server · Ubuntu Server · Kali Linux · Bastion Host

Offensive Security: Burp Suite · Metasploit · SQLi · XSS · DDoS (k6) · CTF (TryHackMe)

Cloud: AWS (VPC, EC2, IAM, CloudTrail, EBS)

Languages & Tools: Python · Bash · Git · VirtualBox / VMware


📜 Certifications

TryHackMe — Cyber Security 101 · Pre Security · Web Fundamentals · Jr Penetration Tester · Advent of Cyber 2025


📫 Get in touch

Open to internship opportunities — feel free to reach out on LinkedIn or by email.

Pinned Loading

  1. aws-cloud-security-lab aws-cloud-security-lab Public

    Secured a real AWS VPC with a custom Linux firewall (iptables/nftables), inline Suricata IDS/IPS and a Wazuh SIEM — CIS-hardened, pentested with Nmap/Burp Suite.. , remediated with a ModSecurity WAF.

    Shell

  2. secure-network-fortigate-lab secure-network-fortigate-lab Public

    Secured an enterprise network with a FortiGate NGFW, Active Directory with GPO-based access control, and DMZ segmentation — validated through offensive testing (DDoS simulation, SQLi/XSS pentests, …

    PowerShell

  3. soc-pentest-siem-lab soc-pentest-siem-lab Public

    Built a virtualized enterprise network (4 security zones, Active Directory, DMZ WAF/reverse-proxy chain) with a Wazuh SIEM, then ran a 23-attack red-team campaign against it — detection validated a…

    Shell