Skip to main content

Who Am I?

I am M. Siddiq Baig, a certified Ethical Hacker (NED Academy) in Karachi, Pakistan building practical cybersecurity skills through hands-on labs and structured learning.


I focus on understanding networking fundamentals, web application security, defensive security, and ethical hacking techniques in legal and controlled environments.


My goal is to develop into a skilled penetration tester and contribute to improving real-world security through practical experience and continuous learning.


Ethical Hacker in Training

Cybersecurity Learner

Currently immersing in the world of cybersecurity with a focus on defensive security and ethical hacking fundamentals.

Diverse Skillset

Building a foundation in network basics, defensive security, and cyber risk awareness, while progressing through ethical hacking courses.

Continuous Learning

Completed various certifications to deepen understanding, with plans to acquire more credentials in the field of ethical hacking.


Cybersecurity Tools

I use a range of industry-standard tools to perform security testing, vulnerability assessment, and analysis.

Nmap network scanning tool
Recon

Nmap

Network scanning & service enumeration.

Used for host discovery & port analysis
Metasploit framework
Exploitation

Metasploit

Exploitation framework.

Automates penetration testing attacks
Burp Suite web security tool
Web Security

Burp Suite

Web application testing.

Intercepts & modifies HTTP traffic
OWASP ZAP scanner
Scanner

OWASP ZAP

Vulnerability scanning.

Open-source web app security testing
Wireshark network analyzer
Network

Wireshark

Traffic analysis.

Captures and inspects packets
Kali Linux OS
OS

Kali Linux

Penetration testing OS.

Security-focused Linux distribution
Nessus vulnerability scanner
Audit

Nessus

Vulnerability scanning tool.

Enterprise-grade security auditing

Security Labs | Tools & Technologies Hands-on Projects

Security Labs

Hands-on cybersecurity practice in controlled environments

Completed
Metasploitable penetration testing lab
Metasploitable2 Penetration Test
Target: Metasploitable2 VM
Finding: Samba vulnerability (RCE)
Impact: Remote shell access
Fix: Patch SMB service & disable SMBv1
Tools: Nmap, Metasploit
View Report
Web
Web application security scan
Web Application Security Scan
Target: Test Web App
Finding: Missing headers, XSS risk
Impact: Injection vulnerability
Fix: Input validation + CSP
Tools: OWASP ZAP, Burp Suite
Hardening
Content Security Policy implementation
Content Security Policy (CSP)
Target: Web Application
Finding: No CSP protection
Impact: Script injection risk
Fix: Strict CSP rules applied
Tools: Browser DevTools

Certifications

Industry-recognized certifications validating cybersecurity knowledge & skills

Cybersecurity Certifications | Ethical Hacker Portfolio
Cybersecurity certificate preview
NED Academy logo Ethical Hacker certification from NED Academy
Offense
Ethical Hacker
NED Academy
Feb 07, 2026
Penetration testing & exploitation
View
Cybrary logo Network Basics cybersecurity certificate from Cybrary
Recon
Network Basics
Cybrary
Jun 17, 2025
Host discovery & port scanning
View
Cybrary logo Careers in Cybersecurity certificate from Cybrary
Career
Careers in Cybersecurity
Cybrary
Jun 8, 2025
Industry roles & pathways
View
Cybrary logo Defensive Security and Cyber Risk certificate from Cybrary
Defense
Defensive Security
Cybrary
May 15, 2025
Threat detection & risk mitigation
View
Cybrary logo Cybrary Orientation course icon
Intro
Cybrary Orientation
Cybrary
May 15, 2025
Platform onboarding basics
View

Blog Articles

Insights, writeups & cybersecurity research

Blog
Zero-Day Microsoft Defender
Zero-Day in Microsoft Defender
A detailed write-up on a Zero-Day vulnerability discovered in Microsoft Defender, its potential impact, exploitation risks, and mitigation strategies.
Platform: BlueHammer
Read on BlueHammer

Disclaimer:

This website is for educational and portfolio purposes only.

All cybersecurity and ethical hacking activities mentioned here are performed in legal environments such as labs, training platforms, or systems where explicit permission has been granted.

I do not engage in or support illegal hacking, unauthorized access, or malicious cyber activity.


Get In Touch

I welcome inquiries and collaborations within the cybersecurity community. Whether you have questions, resources to share, or opportunities, let’s connect! Feel free to reach out via the contact form or email below. Your support is appreciated on my journey to becoming an ethical hacker!

Contact