Skip to content
View i1zco's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report i1zco

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
i1zco/README.md

Rawad Raool

Cybersecurity Student | Aspiring Security Engineer

LinkedIn Email


Professional Overview

As a Cybersecurity student at the University of Aden (Expected 2028), my objective is to architect resilient security infrastructures and develop robust vulnerability intelligence tools. My core focus lies in application security, defensive SecOps, network hardening, and bridging the gap between offensive research and automated incident response. I am actively building a foundation in securing enterprise environments, analyzing source code for critical vulnerabilities, and implementing comprehensive defense-in-depth strategies.

Core Focus Areas:

  • Application Security & White-Box Source Code Review
  • Enterprise Network Security & Routing Protocols
  • Security Operations (SIEM, SOAR, EDR, IDS/IPS integration)
  • Host-Based & Edge Defense Architectures (WAF, Firewall Filtering)

Key Projects & Vulnerability Research

  • Secra — Vulnerability Intelligence Tool Engineered an automated Python-based tool that integrates with public vulnerability databases to map known CVEs against detected software products. Features an active network-scanning module designed to reduce manual asset-vulnerability correlation time.

  • Wishlist Member Security Assessment — White-Box Analysis Conducted deep white-box source code analysis of a PHP-based platform utilizing OWASP testing methodologies. Discovered and validated two distinct software vulnerabilities prior to public CVE issuance through proof-of-concept development.

  • Zomeye Recon — OSINT Reconnaissance Framework Developed a Python-based intelligence tool leveraging third-party APIs to bypass Cloudflare protections and uncover hidden origin infrastructure and backend IP addresses tied to target domains.

  • Automated SecOps Pipeline (Home SOC) — End-to-End Environment Architected a Security Operations Center environment. Deployed Splunk SIEM for centralized log aggregation, integrated Shuffle and n8n SOAR platforms to automate incident-response workflows, and configured Wazuh EDR for host-based threat visibility.


Advanced Infrastructure & Defense Engineering

I implement robust defense-in-depth and routing security controls across enterprise architectures:

  • Web Application Firewall & Core Rule Sets: Deployed host-based WAF solutions using ModSecurity integrated with Apache/Nginx, backed by the OWASP Core Rule Set (CRS) to mitigate application layer attacks (SQLi, XSS, LFI). Leveraged Cloudflare CDN for edge security, DDoS mitigation, and origin IP concealment.
  • Network Routing & Switching Security: Configured secure enterprise routing and switching environments utilizing Cisco and MikroTik hardware/virtual environments. Implemented dynamic routing protocols (OSPF), loop prevention mechanisms (STP), and interface-level Port Security to mitigate unauthorized device access and MAC spoofing.
  • Firewall Filtering & Packet Inspection: Designed custom packet filtering rules utilizing nftables and pfSense firewalls. Enforced strict network segmentation via VLANs, NAT policies, and secure VPN tunnels.
  • Threat Detection & Name Resolution Security: Fine-tuned signature rules on Suricata/Snort IDS/IPS engines for real-time traffic inspection. Explored mechanisms to secure infrastructure integrity including DNSSEC implementation concepts.
  • System Hardening: Secured production-style PostgreSQL environments by enforcing the Principle of Least Privilege (PoLP), disabling passwordless local authentication, and mandating encrypted network traffic.

Certifications & Achievements

  • 5th Place Winner — 4th Student Research & Innovation Conference (Developed a Smart Employee Attendance Management System using Python/OpenCV).
  • Practical Training — TryHackMe: Advent of Cyber 24.

Technical Competencies

Development & Scripting

Backend

Security & Infrastructure

Security

pfSense
Splunk
Cisco
MikroTik

Systems & Operations

Linux

Tools

GitHub Analytics

Rawad stats

Pinned Loading

  1. Secra Secra Public

    Secra is a lightweight Python-based CVE vulnerability scanner that performs CPE-to-CVE mapping, software version risk analysis, and security intelligence reporting for cybersecurity researchers and…

    Python 4 1

  2. zoomeye-recon zoomeye-recon Public

    ZoomEye Recon is a passive reconnaissance tool that uses ZoomEye API to discover domain assets, subdomains, and related IP addresses. The tool is designed for OSINT research and educational securit…

    Python 2

  3. wishlist-member-vuln-analysis wishlist-member-vuln-analysis Public

    Analysis of an Unauthenticated Arbitrary File Write vulnerability in Wishlist Member plugin (<=3.25.1) with potential RCE. Educational and responsible disclosure report.

    2

  4. wishlist-poc wishlist-poc Public

    Wishlist Member Arbitrary File Read via Directory Travesal <= 3.25.1

    Python 2