TryHackMe Β· Hands-on Labs Β· 2025

Practical Cybersecurity
Labs & Training

Master's graduate in Informatics focused on cybersecurity, SOC operations, phishing simulation automation and practical hands-on labs through TryHackMe, PortSwigger and web security exercises.

6 Rooms Completed
2 Active Paths
SOC Primary Focus
2025 Active
TryHackMe /room/aithreatmodellingassessment
Completed
Medium AI Security Threat Modelling

AI Threat Modelling Assessment

What I practised
  • Identifying AI-specific attack surfaces and entry points
  • Prompt injection risks and mitigation strategies
  • Authentication & authorization in AI systems
  • Structured risk analysis for ML pipelines
STRIDE Prompt Injection AI Risk OWASP LLM
TryHackMe /soc-sim/public-summary/…
Completed
Medium SOC Log Analysis

SOC Simulator

What I practised
  • End-to-end SOC workflow and alert lifecycle management
  • Incident triage, prioritization and escalation decisions
  • Attacker behavior analysis and IOC identification
  • Log analysis fundamentals across multiple sources
SIEM Alert Triage IOC Analysis Incident Response
TryHackMe /room/picklerick
Completed
Easy CTF Linux

Pickle Rick

What I practised
  • Web enumeration and directory discovery techniques
  • Remote command execution via web vulnerabilities
  • Linux filesystem navigation and file inspection
  • Privilege escalation via sudo misconfiguration
Gobuster Nmap RCE sudo privesc
TryHackMe /room/dnsindetail
Completed
Easy Networking DNS

DNS in Detail

What I practised
  • DNS resolution process: recursive & iterative lookups
  • Record types: A, AAAA, CNAME, MX, TXT, NS, SOA
  • Domain infrastructure and hierarchy understanding
  • DNS enumeration for reconnaissance workflows
nslookup dig DNS Records Recon
TryHackMe /room/owasptopten2025one
Completed
Medium Web Security OWASP

OWASP Top 10 2025 β€” IAAA Failures

What I practised
  • Identification, authentication and authorization flaws
  • Session management weaknesses and token abuse
  • Logging, auditing and accountability failures
  • Practical exploitation of OWASP Top 10 entry #1
OWASP 2025 Auth Bypass Session Tokens Burp Suite
TryHackMe /room/owaspbrokenaccesscontrol
Completed
Medium Web Security Access Control

Broken Access Control

What I practised
  • IDOR (Insecure Direct Object Reference) exploitation
  • Horizontal and vertical privilege escalation attacks
  • Broken authorization β€” forcing URL and parameter access
  • Access control testing methodology
IDOR Privesc Burp Suite OWASP A01
Formal Credentials

Certificates & Courses

Click any diploma thumbnail to preview it directly in the browser.

Cybersecurity

2 in progress
Udemy

Mastering Kali Linux for Ethical Hackers

Hands-on ethical hacking course using Kali Linux β€” penetration testing methodology, network attacks, exploitation, post-exploitation, and reporting.

In progress Started
In Progress
Udemy

Complete Ethical Hacking Bootcamp: Zero to Mastery

Full-spectrum ethical hacking course covering reconnaissance, scanning, exploitation, web attacks, wireless security, and social engineering.

7 sections completed Β· Active

7 sections done 21%
21%
In Progress

AI & Automation

3 completed
UiPath Academy
2 certificates Β· academy.uipath.com
Full Preview

Introduction to Agentic Automation

Foundations of agentic AI β€” autonomous agents, orchestration, task delegation, and integrating AI agents into automated business workflows using UiPath.

Full Preview

Getting Started with Application Testing in UiPath Test Cloud

Introduction to automated application testing using UiPath Test Cloud β€” test design, execution, reporting, and integrating test automation into CI/CD pipelines.

Cisco Networking Academy
1 certificate Β· netacad.com
Full Preview

Introduction to Modern AI

Core concepts of modern AI β€” machine learning, neural networks, natural language processing, and real-world AI applications across business and IT.

Job Simulations

2 completed

Virtual work experience programs run by real companies via The Forage β€” hands-on tasks that mirror actual day-to-day work in professional roles.

Mastercard via The Forage
1 simulation Β· theforage.com
Full Preview

Cybersecurity Job Simulation

Practical simulation of real Mastercard security analyst work β€” designing a realistic phishing email simulation campaign and interpreting phishing awareness results to identify at-risk teams and recommend follow-up training.

Phishing Simulation Security Awareness Security Training Data Analysis Design Thinking Strategy
Deloitte via The Forage
1 simulation Β· theforage.com
Full Preview

Cyber Job Simulation

Practical simulation of Deloitte cybersecurity analyst work β€” covering network security, log analysis, Python scripting, data modeling, web security assessment, and formal client communication.

Log Analysis Python Web Security Data Modeling Networking Data Visualization Spreadsheet Skills

Business Systems

1 completed
Udemy

Microsoft Dynamics CRM β€” Introduction Course

Introduction to Microsoft Dynamics CRM β€” core modules (Sales, Service, Marketing), entity management, workflows, dashboards, and business process flows. Complements hands-on Dynamics 365 Business Central ERP experience.

Microsoft Dynamics CRM Sales Module Workflows Business Process
βœ“ Completed No diploma

Programming

1 in progress
Udemy

100 Days of Code β€” The Complete Python Pro Bootcamp

Daily Python programming challenges covering automation, web scraping, data science, Flask, APIs, and building real projects from scratch. Dr. Angela Yu.

~30 days completed Β· Active

Day ~30 / 100 30%
30%
In Progress

Planned

3 next
CompTIA

Security+

Industry gold standard for entry-level security. Validates threat analysis, network defense, and cryptography skills.

IBM / Coursera

Cybersecurity Analyst

Directly complements QRadar and SIEM experience from OTP banka. Covers threat intelligence and incident response.

Microsoft

PL-300 β€” Power BI

Data analytics cert covering Power BI, DAX, and report design. Complements existing Tableau and SQL experience.