Ahmed Abdalrhman

alzeaty

I break lab machines on my own time and write down the exact request that worked.

I am a junior penetration tester. I work through self-directed lab machines — TryHackMe rooms, PortSwigger Academy — and write up what I find step by step so I can reread it later.

My focus is web application and network work: authentication and access control flaws, injection, exposed cloud credentials, and traffic analysis.

  • 01 NTI / NTRA Cybersecurity Academy

    National Telecom Institute, Ministry of Communications.

  • 02 TryHackMe Advent of Cyber 2025

    24 challenges completed. Certificate ID THM-I1Q2HMQIIO.

  • 03 PortSwigger Web Security Academy

    All Access Control and Authentication labs.

Al Nour Tech, 2019–2021 — IT and network engineering.

Freelance web development, 2021–2023. The security work came out of that.

All 9 writeups, plus 1 appendix

ctf-crypto-analysis-tool — github.com/alzeaty1/ctf-crypto-analysis-tool. A modular crypto analysis CLI with a plugin registry, a pytest suite, MIT licensed. It covers XOR analysis (known-key, single-byte brute force, and repeating-key recovery via column scoring with beam search), entropy and English-language scoring, and ECB repeated-block detection. One cipher family is implemented so far; the rest of the registry is scaffolding.

A separate set of reading notes on other people’s published bug bounty writeups — what they did, what I would try differently. These are notes on other authors’ findings, not my own.