Skip to content
Syed Muhammad
Open to junior roles & small business projects

Hi, I'm Syed Muhammad Abbas Ali

Junior Cybersecurity Specialist

I help individuals and small businesses identify security weaknesses, improve security posture, and build safer digital systems while continuously expanding my cybersecurity skills through practical projects and hands-on labs.

About

Early career. Real practice.

Curious by default

I dig into how things break before I try to fix them.

Practice over talk

Labs, write-ups, and small tools instead of buzzwords.

Honest about the gaps

Still learning — and comfortable saying so.

I'm early in my cybersecurity journey, and I'd rather be upfront about that than pretend otherwise. What I bring is genuine curiosity, consistent hands-on practice, and a habit of documenting what I learn as I learn it.

Most days involve a home lab, a stack of write-ups, or a small tool I'm building to understand a concept better — networking fundamentals, Linux administration, web application security, and the early stages of ethical hacking are where I currently spend most of my time.

I'm not claiming to be an expert. I'm claiming to be someone who shows up, tests things carefully, reads the documentation, and gets a little better every week — and who would rather under-promise and over-deliver on a small project than the reverse.

Skills

What I'm building, honestly labeled

Every skill is marked by where I actually am with it right now — not a fabricated expertise score.

Practicing

Networking

Practicing

Linux

Comfortable

Windows

Practicing

Python

Practicing

Bash

Comfortable

HTML

Comfortable

CSS

Practicing

JavaScript

Comfortable

Git

Comfortable

GitHub

Practicing

Nmap

Learning

Wireshark

Learning

Burp Suite

Practicing

OWASP Top 10

Learning

SQL Injection Basics

Learning

XSS Testing

Practicing

Directory Enumeration

Learning

Subdomain Enumeration

Learning

Basic API Testing

Learning

Risk Assessment

Services

Beginner-friendly, clearly scoped

Priced and scoped for small businesses — every engagement states exactly who it's for, what's included, and which tools I use.

Website Security Assessment

Small business owners with a live website or landing page

  • Manual review against the OWASP Top 10
  • Plain-language report of what was checked
  • Prioritized list of findings with suggested fixes
Burp SuiteOWASP ZAPNmap
Ask about this

Basic Vulnerability Assessment

Small teams who want a first-pass health check

  • Surface-level scan of exposed services and endpoints
  • Screenshot-backed evidence for every finding
  • No exploitation of production systems without written consent
NmapOWASP ZAP
Ask about this

OWASP Top 10 Security Review

Developers who want a second pair of eyes before launch

  • Checklist-driven review mapped to each OWASP category
  • Notes on what's already handled well
  • Clear, non-alarmist write-up of gaps
Burp SuiteManual testing
Ask about this

Website Security Recommendations

Anyone who wants practical next steps, not just a scan

  • Review of headers, cookies, and basic configuration
  • Concrete, ranked recommendations
  • Follow-up call to walk through the report
Browser dev toolsManual testing
Ask about this

Security Awareness Consultation

Small teams without a dedicated security contact

  • One session covering common attack patterns
  • Simple habits that reduce risk day-to-day
  • A short reference document to keep on hand
No tools — conversation-based
Ask about this

Linux Server Basic Hardening

Small businesses running a single Linux server

  • Review of users, permissions, and open services
  • SSH and firewall configuration check
  • Written summary of changes made or recommended
Linux CLIufw / iptables
Ask about this

Network Security Review

Small offices with a simple local network

  • Inventory of visible devices and open ports
  • Identification of obviously risky configurations
  • Straightforward remediation checklist
NmapWireshark
Ask about this

Basic API Security Review

Teams shipping a small internal or public API

  • Review of authentication and authorization basics
  • Check for common misconfigurations
  • Notes on rate limiting and input validation
Burp SuitePostman
Ask about this

Security Best Practices Report

Anyone who wants a baseline to work from

  • A written, prioritized checklist tailored to your setup
  • Explained in plain language, not jargon
  • Free of upsell — just the recommendations
Manual review
Ask about this

Projects

Things I've actually built

Small, real, and mine — each one solving a specific problem I ran into while learning.

Featured
Home LabNetworking

Personal Home Lab

A self-hosted lab environment used to practice networking, Linux administration, and safe, contained security testing.

Problem solved: Gives me a controlled space to break things and learn without touching production systems.

VirtualBoxKali LinuxpfSense
Featured
PythonWeb Security

Web Vulnerability Scanner

A lightweight scanner that checks a target URL for common misconfigurations and OWASP Top 10 indicators.

Problem solved: Automates the repetitive first pass of a manual review so I can spend more time on analysis.

PythonRequestsBeautifulSoup
JavaScriptWeb App

Password Strength Checker

A small web tool that scores password strength against entropy and common-pattern rules, entirely client-side.

Problem solved: Teaches users why a password is weak instead of just saying it is.

JavaScriptHTMLCSS
PythonNetworking

Port Scanner

A command-line TCP port scanner built from scratch to understand how tools like Nmap work under the hood.

Problem solved: Built to understand socket-level scanning mechanics, not to replace existing tools.

PythonSockets
PythonNetworking

Network Scanner

A local-network discovery tool that identifies live hosts, open ports, and basic service banners.

Problem solved: Helps map a small network before doing any deeper review.

PythonScapy
Web AppTypeScript

Security Checklist Generator

A small app that generates a tailored security checklist based on a few questions about a website or server.

Problem solved: Turns a vague 'am I secure?' question into a concrete, actionable list.

Next.jsTypeScript
SIEMDashboard

Simple SIEM Dashboard

A minimal log-ingestion dashboard that surfaces suspicious patterns from sample log data in near real time.

Problem solved: Built to understand the basic mechanics of log correlation and alerting.

PythonFlaskSQLite
PythonLog Analysis

Log Analyzer

A CLI tool that parses server logs and flags patterns associated with brute-force attempts and scanning activity.

Problem solved: Practice project for pattern recognition in raw log data.

PythonRegex
Featured
Web SecurityCase Study

Website Security Audit Demo

A walkthrough project demonstrating a full, non-destructive security audit on a purposefully vulnerable test site.

Problem solved: Shows my assessment process end-to-end using a legal, intended-for-testing target.

Burp SuiteOWASP ZAP
LinuxDocumentation

Linux Hardening Guide

A written, step-by-step guide documenting the hardening steps I apply to a fresh Linux server install.

Problem solved: Turns personal notes into a reusable reference — for myself and for anyone else learning the same thing.

LinuxBash

Learning Journey

Growth, shown honestly

No fabricated job history — just the real sequence of how I got from zero to here, and where I'm headed next.

Started Learning Networking

Began with the fundamentals — TCP/IP, subnetting, and how traffic actually moves.

Built Linux Lab

Set up a virtualized environment to practice administration and hardening safely.

Learned Burp Suite

Started working through intercepting requests and understanding web traffic manipulation.

Built First Security Tool

Wrote a simple Python script to solve a real problem I kept running into manually.

Completed OWASP Practice

Worked through OWASP Top 10 categories against intentionally vulnerable test applications.

Built This Portfolio

Brought the projects, tools, and progress together into one honest, organized place.

Working Toward Professional Certification

Currently studying toward a recognized certification — details to be added once complete.

In progress

Toolbox

What I work with day to day

Nmap

Burp Suite

Wireshark

OWASP ZAP

Kali Linux

VirtualBox

VMware

Git

VS Code

Linux

Windows

Python

Docker

Learning

Why work with me

What you can expect

Affordable

Rates that reflect where I am in my career — fair for a small business budget.

Dedicated

I treat every project, no matter how small, as worth doing properly.

Always Learning

Every engagement feeds back into my own practice — I stay current on purpose.

Attention to Detail

I'd rather flag ten small things than miss one important one.

Transparent Communication

You'll always know what I checked, what I found, and what I didn't get to.

Focused on Practical Results

Findings come with plain-language fixes, not just a wall of jargon.

Contact

Let's talk about your security

Whether you're a recruiter or a small business owner, I read every message myself and reply personally.