Skip to main content

Available for security roles & freelance work

Asad Ali

Currently working as:

Cybersecurity Analyst | SOC Analyst | Web & Network Security

I detect, investigate and document threats — then write about how it was done.

  • SC-200
  • ISC2 CC
  • TryHackMe top 3% (@pylus)
  • Lahore, Pakistan

About

Security work, documented end to end

Computer Science graduate and cybersecurity analyst working across the blue and red side of the fence.

I'm a Computer Science graduate and cybersecurity analyst with hands-on experience in threat detection, vulnerability assessment and network analysis. I hold the Microsoft SC-200 and ISC2 Certified in Cybersecurity credentials, and I rank in the top 3% globally on TryHackMe.

Day to day I work with Nmap, Wireshark, Burp Suite, Snort, Zeek, Tshark and the MITRE ATT&CK framework. I've built custom scanning tools in Python, completed a Red Team internship, and I actively publish detailed CTF walkthroughs and case studies on Medium.

Alongside security I freelance in WordPress development and SEO — handling complete website setups, hardening, performance tuning and on-page/off-page strategy for clients.

Education

  • BS Computer Science

    University of Engineering and Technology (UET)

    Lahore, Pakistan · 2021 — 2025

TryHackMe rooms
0+TryHackMe rooms
Globally ranked
Top 0%Globally ranked
Years freelancing
0+Years freelancing
Certifications
0+Certifications

Experience

Where I've been working

Security operations, infrastructure support and client delivery — most of it running in parallel.

  1. IT Project Manager

    May 2026 — Present

    SoftsincsPart-time · Hybrid · Lahore

    • Coordinating delivery across IT projects, aligning technical scope with client requirements and timelines.
  2. IT Support Engineer

    Oct 2025 — Present

    FinMin SolutionsFull-time · On-site

    • Configured and maintained networks and servers across the organisation.
    • Managed ERP systems and resolved customer issues and production bugs.
    • Tested new releases across Android, desktop and web applications.
  3. Cybersecurity Intern — Red Team

    Apr 2025 — May 2025

    Hack SecureInternship · Remote

    • Performed SQL injection, XSS and directory enumeration using Burp Suite and Gobuster.
    • Mapped networks and captured traffic with Nmap and Wireshark.
    • Built a Python TCP port scanner used during engagements.
    • Documented findings in structured penetration testing reports.
  4. Security Research Writer

    2025 — Present

    MediumSelf-directed

    • Detected brute-force and reverse-shell attempts with Snort in live IPS mode.
    • Identified Log4j exploitation and phishing activity using Zeek.
    • Published detailed walkthroughs and network forensics case studies.
  5. SEO & WordPress Freelancer

    Oct 2021 — Present

    FreelanceSelf-employed · Remote

    • End-to-end delivery from lead generation to website development, security and performance.
    • Managed hosting, backups, permissions, caching, CDNs and update cycles for client sites.

Skills

Tooling and frameworks I work with

Grouped by where they sit in the workflow — from fundamentals through offensive tooling to detection engineering.

Cybersecurity Fundamentals

  • CIA Triad
  • Security Controls
  • Risk Management
  • GRC Concepts

VAPT & Red Team

  • Kali Linux
  • Burp Suite
  • Nmap
  • Metasploit
  • Gobuster
  • SQL Injection
  • XSS

Blue Team & Detection

  • Snort
  • Zeek
  • Wireshark
  • Tshark
  • YARA
  • Loki
  • MISP
  • Microsoft Sentinel
  • KQL
  • Log Analysis

Frameworks

  • OWASP Top 10
  • MITRE ATT&CK
  • Pyramid of Pain
  • Cyber Defense Framework

Networking

  • OSI & TCP/IP
  • IP Addressing & Subnetting
  • LAN / WAN

OS & Programming

  • Windows (Active Directory)
  • Linux (Kali, Ubuntu, ParrotOS)
  • macOS
  • Python
  • JavaScript / React.js
  • C++

Web & Freelance

  • WordPress
  • SEO
  • Next.js

Soft Skills

  • Communication
  • Problem-Solving
  • Critical Thinking
  • Team Collaboration

Projects

Selected work

Labs, tooling and investigations — each one written up so the methodology is reproducible.

  • TryHackMe Labs & CTF Simulations

    Over 100 rooms completed, ranked in the top 3% globally — covering offensive and defensive tradecraft end to end.

    • Web application enumeration and login brute forcing
    • Log analysis and network forensics investigations
    • CTF
    • Enumeration
    • Forensics
    • Blue Team
    View profile — TryHackMe Labs & CTF Simulations
  • Python TCP Port Scanner

    A custom CLI scanner built for reconnaissance during Red Team engagements.

    • Scans 1,000+ ports per minute with socket timeout logic
    • CLI input sanitization to prevent malformed target parsing
    • Python
    • Sockets
    • Recon
    • Tooling
    View on GitHub — Python TCP Port Scanner
  • E-HospitCare System

    Final Year Project — a hospital care platform built with a security-first frontend architecture.

    • Responsive React interfaces with input sanitization
    • Role-based access control across patient and staff views
    • React
    • RBAC
    • Secure SDLC
    • FYP

    Write-up available on request

  • Network Traffic Analysis Case Studies

    A series of Wireshark, Nmap and Zeek investigations documented as full case studies.

    • 81,000+ packets analysed across multiple captures
    • DNS latency detection and TCP checksum anomaly triage
    • C2 channel port profiling, Log4j and phishing detection
    • Wireshark
    • Zeek
    • Nmap
    • Threat Hunting
    Read the case studies — Network Traffic Analysis Case Studies
  • Snort IPS Live Attack Defense

    Live intrusion prevention against simulated attacks, with custom rule authoring.

    • Detected SSH brute-force attempts on port 22
    • Caught Metasploit reverse shells on port 4444
    • Wrote custom reject rules running in live IPS mode
    • Snort
    • IPS
    • Detection Engineering

    Write-up available on request

  • Web Shell Detection with YARA & Loki

    Built and validated detection signatures for web shells across a compromised file set.

    • Generated custom YARA rules with yarGen
    • Scanned hosts with Loki for indicators of compromise
    • Validated findings against Valhalla and VirusTotal threat intel
    • YARA
    • Loki
    • Threat Intel
    • IOC

    Write-up available on request

Certifications

Credentials

Vendor and vendor-neutral certifications across security operations, governance and networking.

  • SC-200: Security Operations Analyst

    Microsoft

    Issued
    Jun 2026
    ID
    44B591BE3A886560

    Verified credential

  • Certified in Cybersecurity (CC)

    ISC2

    Issued
    Jul 2025
    Expires
    Jul 2028

    Verified credential

  • Certified Fundamentals in Cybersecurity

    Fortinet

    Issued
    Jul 2025

    Verified credential

  • ISO/IEC 27001 Information Security Associate

    SkillFront

    Issued
    Jun 2025

    Verified credential

  • Introduction to CIP

    OPSWAT Academy

    Issued
    Sep 2025

    Verified credential

  • Advent of Cyber 2025

    TryHackMe

    Issued
    2025

    Verified credential

  • OWASP Top 10

    Infosec

    Issued
    2025

    Verified credential

  • AWS Educate: Introduction to Generative AI

    Amazon Web Services

    Issued
    Jun 2025

    Verified credential

  • AWS Educate: Introduction to Cloud 101

    Amazon Web Services

    Issued
    Jun 2025

    Verified credential

  • Networking Basics

    Cisco

    Issued
    Jul 2024

    Verified credential

  • Introduction to Cybersecurity

    Cisco

    Issued
    Oct 2022

    Verified credential

  • Complete B2B Sales Course: Lead Generation to Closing

    Udemy

    Issued
    2023

    Verified credential

Latest Writing

Walkthroughs and case studies

Long-form write-ups on detection engineering, network forensics and certification prep.

All articles

Contact

Let's talk

Open to SOC and security analyst roles, freelance security reviews, and WordPress or SEO engagements.

Location
Lahore, Punjab, Pakistan

At least 20 characters.

Or email contact@asadali.tech