Skip to content
View aminulislamfahim's full-sized avatar

Block or report aminulislamfahim

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
aminulislamfahim/README.md

Md Aminul Islam Fahim

Cybersecurity Professional | Penetration Tester | Incident Response Analyst

🎯 Hands-on experience in penetration testing, vulnerability assessment, and incident response.
πŸ” Authored a real-world ransomware attack case study for a healthcare facility, resulting in permanent data loss due to RSA encryption and backup failure.
πŸ’‘ Skilled in translating technical findings into executive-level remediation plans (offline backup, EDR, SIEM, network segmentation).
πŸ“„ Public case study: Healthcare Ransomware IR Report
πŸ“„ Public case study: cPanel Security Audit Framework/ Scanner


πŸ› οΈ Technical Skills

πŸ” Offensive Security
Burp Suite, Metasploit, Nmap, OWASP ZAP, OpenVAS, Nessus

πŸ›‘οΈ Incident Response & Forensics
Ransomware Analysis (RSA encryption), Forensic Evidence Collection (Event Logs, memory artifacts), Malware Binary Handling, Backup Policy Review (3-2-1-1 rule)

πŸ“Š Security Operations
SIEM (Splunk, Wazuh concepts), EDR (Endpoint Detection & Response), Network Segmentation, MITRE ATT&CK (T1486 – Data Encrypted for Impact)

πŸ’» Programming & Scripting
Python, Bash, PowerShell, SQL

πŸ“š Frameworks & Standards
OWASP, NIST SP 800-61 (Incident Response), ISO 27001


🌟 Key Projects

πŸ“„ Healthcare Ransomware Incident Response Case Study

Repo: github.com/aminulislamfahim/ransomware-ir-case-study-healthcare

  • Authored a complete IR report for a 200+ endpoint hospital facing a bear26.exe ransomware attack that caused permanent data loss across 7 core clinical systems.
  • Identified architectural failures: Windows Server 2012 (EOL), no antivirus, no network segmentation, Windows trusted authentication alone, and overwrite-only backup that destroyed the last clean copy.
  • Provided 3-tier remediation roadmap (Immediate / 3–6 months / Long-term) including offline immutable backups (3-2-1-1), EDR deployment, SIEM (Splunk/Wazuh), and vendor-side software changes (separate app login, versioned backups).
  • Demonstrated forensic evidence collection from compromised host (Event Logs, Task Manager snapshots, malware binary preservation).

βš™οΈ cPanel Security Audit Framework/ Scanner

Repo: https://github.com/aminulislamfahim/cpanel-malware-scanner.git

-Developed a Bash-based security toolkit to assist administrators in auditing WordPress hosting environments and identifying suspicious filesystem artifacts cross WHM/cPanel servers.

  • Automated large-scale WordPress inventory and audit workflows across WHM/cPanel servers, reducing manual audit time by 40–50% and improving consistency of security reviews.

  • Designed a configurable architecture with signature and whitelist support, enabling scalable security assessments and streamlined incident response workflows

πŸ† Capture the Flag (CTF) Achievements

  • Solved over 100 challenges on PicoCTF, Hack The Box, and TryHackMe.
  • Specialized in reverse engineering, cryptography, and web exploitation.
  • Improved team rankings and contributed to community-based CTF learning initiatives.

πŸŽ“ Education

Bachelor of Science in Computer Science and Engineering
Bangladesh University of Business and Technology (BUBT)
Feb 2018 to Dec 2024


πŸ† Certifications

  • Penetration Testing: Advanced Penetration Testing, Offensive Penetration Testing, Mobile App Security (Cybrary)
  • Systems Security: SSCP, Cisco IT Security Makeover, End User VPN Security (Cybrary)
  • Other Technical Skills: Computer Hacking and Forensics, Intermediate SQL (Cybrary)

πŸš€ Leadership & Activities

  • President, BUBT IT Club (Nov 2022–Aug 2023):
    Managed a team of 80+ members, organized 20+ technical events, and grew membership by 50%.

  • Volunteer Mentor:
    Guided 20+ students in penetration testing and career development, increasing community CTF rankings by 20%.


πŸ“« Connect with Me


Pinned Loading

  1. aminulislamfahim aminulislamfahim Public

    Config files for my GitHub profile.