Hamzah Zuhrah profile photo

Hamzah Zuhrah

Cybersecurity Student | Kali Linux | CompTIA Security+ in Progress

Interested in cybersecurity, Linux-based system security, and practical security projects that strengthen real-world technical skills.

Cybersecurity student at Old Dominion University with hands-on experience in Kali Linux, Linux administration, networking, access control, and technical lab documentation. Focused on building practical security skills through system configuration, command-line work, and security engineering projects, including a fully rebuilt Secure File Transfer System and four public-interest cybersecurity web applications focused on scam prevention, survivor safety, nonprofit incident response, and community cyber resilience.

About Me

I am a cybersecurity student focused on building real technical skills in Linux, networking, system security, and cybersecurity fundamentals. My portfolio highlights coursework, hands-on labs, and practical projects that demonstrate my ability to work with command-line tools, user and permission management, and system configuration in lab environments.

Skills

Kali Linux Linux Command Line User & Group Management File Permissions Shell Scripting Task Automation System Administration Virtual Machine Labs Networking Fundamentals Network Security Security Concepts Technical Documentation Python Client-Server Networking scrypt Password Hashing AES-256-GCM TLS Secure Protocol Design Security Testing Incident Response Threat Modeling NIST CSF 2.0 Accessible Web Applications

Currently Learning

  • CompTIA Security+ (SY0-701)
  • Linux system administration and file permissions
  • Secure file transfer and authentication concepts
  • Networking protocols and security fundamentals

Projects

Five completed projects that pair defensible security engineering with clear documentation, tested behavior, and—where applicable—live tools designed to help real communities.

Public-interest app 01

ScamShield Community

Live

A privacy-first message triage tool that explains scam pressure tactics, credential requests, risky payment methods, impersonation, and suspicious link structures without uploading user content.

Explainableweighted rule engine On-deviceno text transmission URL analysis7 warning classes Safer UXno false “safe” verdict

Public-interest app 02

SafeSteps Digital Safety

Live

A survivor-centered, session-only technology safety planner covering account access, device monitoring, location sharing, phone plans, smart-home systems, communications, and evidence preservation.

Session-onlyzero stored answers Quick exitbutton + keyboard Risk-awareescalation pause points 8 domainsprioritized planning

Public-interest app 03

BreachCoach

Live

A branching incident-response tabletop simulator for nonprofits, with ransomware, business-email compromise, and donor-account takeover exercises built around real operational tradeoffs.

3 scenarios9 escalating injects 27 choicesscored outcomes 4 dimensionsresilience model Debriefprintable review

Public-interest app 04

MissionReady Cyber

Live

A cybersecurity readiness planner for community organizations that converts twelve maturity questions across all six NIST CSF 2.0 Functions into a prioritized 30–60–90 day action roadmap.

6 functionsindependent scores 12 questions4 maturity states 90-day plandeterministic ranking Privateno organization data

Hands-On Labs

Networking and Infrastructure Labs

  • Configured networking settings on a Windows device in a live virtual machine environment
  • Studied networking topologies and architecture
  • Worked with network protocols and router-based communication
  • Practiced IP addressing and physical star topology design
  • Examined packet contents and network reference models and standards

Network Security Labs

  • Explored foundational network security concepts
  • Analyzed general network attacks in lab environments
  • Applied network hardening techniques to improve system security

Kali Linux Assignments

  • Working with Command Line
  • Working with vi Editor
  • Group and User Management
  • Password Cracking
  • File Permissions
  • Storage Management
  • Shell Script
  • Task Automation
  • Networking Basics
  • Basic Network Configuration

Technical Evidence

Kali Linux & Command Line Usage

  • Used commands such as grep, ls, cd, and pwd to navigate and inspect Linux systems
  • Managed users with commands such as useradd and passwd
  • Modified permissions using chmod and verified results through terminal output
  • Worked with disk and partition-related commands in lab environments

Security Concepts Applied

  • Practiced account and permission management in controlled environments
  • Applied system hardening concepts through file and directory permission changes
  • Documented technical lab steps and validated outcomes with screenshots and command output
  • Built familiarity with Linux-based administrative workflows relevant to cybersecurity

CYSE 301 Password Cracking Lab Report

An evidence-based report documenting a controlled password-cracking lab across Linux and Windows systems. The assignment covers user and group configuration, password hash extraction, dictionary attacks, numeric brute force, and defensive lessons learned from the results.

Assignment 5: Password Cracking

  • Created controlled Linux accounts and evaluated yescrypt password hashes with John the Ripper
  • Extracted and tested Windows NTLM records in an isolated virtual lab
  • Compared dictionary and numeric brute-force techniques, including a raw-MD5 extra-credit exercise
  • Documented findings, evidence, and practical password-defense recommendations

Academic Papers

A Reverse Digital Divide: Information Security Behaviors

Analyzes how Generations Y and Z differ in cybersecurity behavior, focusing on risk perception, awareness, and decision-making in security practices.

The Social Impact of Predictive Cybersecurity Systems

Explores the advantages and limitations of AI-driven cybersecurity systems, including concerns about bias, privacy, and reliance on automation.

Designing a Security Policy for a Corporate Information System

Covers critical security policy areas including access control, encryption, network segmentation, monitoring, and system maintenance.

Security Risks and Social Impact of SCADA Systems

Examines vulnerabilities in SCADA systems used in critical infrastructure, including risks from network exposure and insecure protocols. Also highlights the role of human behavior, organizational culture, and the social impact of cyberattacks on vulnerable communities.

Certifications

CompTIA Security+ (SY0-701) — In Progress

Contact

Email: hzuhr001@odu.edu

GitHub: github.com/ThisIsHamzah99

LinkedIn: linkedin.com/in/hamzah-z-15b55317b