Skip to content
View usmanfarazz's full-sized avatar

Block or report usmanfarazz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
usmanfarazz/README.md
Typing SVG

LinkedIn TryHackMe Email Open to Internships

Profile Views Followers

About Me

I'm Usman Faraz, a Cybersecurity student at PAF-IAST, Pakistan, focused on offensive security and red teaming. I build my skills through hands-on labs, CTF challenges and small security tools, and I document what I learn along the way.

  • πŸŽ“ Education: BS Cybersecurity, PAF-IAST
  • βš”οΈ Focus: Red Teaming, Web App Pentesting, Network Security
  • πŸ“š Currently learning: Active Directory attacks, exploit development, malware analysis
  • 🐧 Daily driver: Kali Linux / Ubuntu
  • 🀝 Open to: Internships, CTF teams and security collaborations
β”Œβ”€β”€(usmanfarazzγ‰Ώkali)-[~]
└─$ whoami --verbose

  name      : Usman Faraz
  role      : Cybersecurity Student | Aspiring Red Teamer
  location  : Pakistan πŸ‡΅πŸ‡°
  focus     : [ "Offensive Security", "Web App Pentesting", "Network Security" ]
  learning  : [ "Active Directory Attacks", "Exploit Development", "Malware Analysis" ]
  mindset   : "Think like an attacker, defend like an engineer."
  status    : Open to internships & collaborations βœ…

Tech Stack

Programming & Scripting

Languages

Operating Systems

Operating Systems Parrot OS BlackArch Commando VM

Security Toolkit

Core tools β€” labs & CTFs

Nmap Burp Suite Metasploit Hydra John the Ripper Hashcat SQLmap Gobuster ffuf Netcat

Currently learning β€” Active Directory, red teaming & reverse engineering

Cobalt Strike Sliver C2 Havoc C2 BloodHound Mimikatz Rubeus Impacket CrackMapExec Responder Evil-WinRM Ghidra


Areas of Focus

🌐
Web App Pentesting
OWASP Top 10, Burp Suite
πŸ–§
Network Security
Recon, Scanning, Traffic Analysis
βš”οΈ
Red Teaming
Exploitation, Privilege Escalation
πŸ€–
AI + Security
LLM Apps, Automation

Featured Work

Project Description Stack
πŸ” Port Scanner Multi-threaded TCP port scanner with service detection & banner grabbing
πŸ” Password Analyzer Local password strength checker with entropy & crack-time estimation
πŸ›‘οΈ Password Strength Checker (Web) Client-side password strength checker, no network calls Β· Live demo
πŸ“’ Cybersec Notes Personal knowledge base for cybersecurity and penetration testing
πŸ€– OBA Core – Horquva AI Workforce Intelligence Engine (MVP) Β· Live demo

2026 Roadmap

  • Linux fundamentals & Bash scripting
  • Networking basics (TCP/IP, OSI, Wireshark)
  • Complete TryHackMe Jr Penetration Tester path
  • Solve 50+ CTF challenges on PicoCTF
  • Earn eJPT certification
  • Start preparing for OSCP

Practice Platforms

TryHackMe Hack The Box PicoCTF OverTheWire PortSwigger Academy VulnHub Root-Me CTFtime HackerOne Bugcrowd Hacker101 HTB Academy OffSec Proving Grounds Vulnlab PentesterLab pwn.college Exploit Education OWASP Juice Shop DVWA HackThisSite


GitHub Stats

GitHub Stats Top Languages
GitHub Streak
Contribution snake

Connect With Me

GmailΒ Β  LinkedInΒ Β  TryHackMeΒ Β  GitHub


"The quieter you become, the more you are able to hear."

Pinned Loading

  1. cybersec-notes cybersec-notes Public

    My personal notes for Cybersecurity and Penetration Testing

  2. OBA-Core-Horquva OBA-Core-Horquva Public

    Forked from JawadZaheer365/OBA-Core-Horquva-OCOS-DEVELOPE

    AI Workforce Intelligence Engine β€” Horquva MVP

    TypeScript

  3. password-analyzer password-analyzer Public

    πŸ” Local password strength analyzer with entropy & crack-time estimation (Python + Bash)

    Python

  4. password-strength-checker-web password-strength-checker-web Public

    πŸ” Client-side password strength checker β€” pure HTML, CSS & JavaScript, no network calls

    JavaScript

  5. port-scanner port-scanner Public

    ⚑ Fast multi-threaded TCP port scanner with service detection (Python)

    Python

  6. Ilm-o-Amal/ilm-o-amal.github.io Ilm-o-Amal/ilm-o-amal.github.io Public

    Ilm o Amal β€” Knowledge & Action. Articles in English, Urdu and Roman Urdu by Usman Faraz.

    HTML 1