Portfolio

To keep you safe from the storm, I must become the storm first.

Davud Qasimov — cybersecurity enthusiast focused on red teaming and penetration testing.

This portfolio tracks my practical training in penetration testing and red teaming — certifications, a project I built, and the skills I'm developing along the way.

6certifications earned
3in progress
7core skills

About

Building toward a career in cybersecurity, with a focus on red teaming and practical penetration testing — working through certification programs and hands-on labs.

This is a personal portfolio to track progress and share what I'm building.

Quick facts

  • Focus: red teaming & penetration testing
  • Hands-on training: CyberWarFare Labs, INE Security
  • Currently building: ASRX, an Active Directory security tool

Skills

Core areas I'm focused on and actively practicing.

Penetration Testing Red Teaming Vulnerability Assessment Web Security Active Directory Security Linux MITRE ATT&CK

Projects

A tool I built for Active Directory security auditing.

github.com/DavudQasimov/ASRX

Active Directory security auditing tool

ASRX

Automates the AS-REP Roasting attack: finds Active Directory accounts with Kerberos pre-authentication disabled, harvests tickets from the domain controller, and exports hashes ready for Hashcat and John the Ripper.

  • Automatic discovery of vulnerable accounts
  • Automated TGT ticket harvesting — no manual request crafting
  • Clean hash export for offline cracking tools

Requires: Impacket, pyasn1

Certifications

Earned and in progress — updated as I complete new programs.

In Progress

AD-RTS eCPPT eWPT

Planned

OSWA eWPTX CRTO OSCP OSEP OSCE

Writeups

Articles, certification reviews, and CTF walkthroughs published on Medium.

TryHackMe / Walkthrough

Blue CTF — TryHackMe

A step-by-step room walkthrough covering the exploitation of EternalBlue (MS17-010) and privilege escalation.

Read on Medium →
Certification Review

API-RTA Certificate — CyberWarFare Labs

Insights, exam preparation strategies, and my experience earning the Certified API Red Team Analyst certification.

Read on Medium →
TryHackMe / Walkthrough

Internal CTF — TryHackMe

Detailed walkthrough covering web enumeration, initial access, internal network pivoting, and acquiring root access.

Read on Medium →
TryHackMe / Walkthrough

Soupedecode 01 CTF - TryHackMe

Comprehensive walkthrough covering the entire Active Directory attack chain.

Read on Medium →

Interactive Terminal

Type commands below to interact with the system. Try help to start.

davud@portfolio:~

Welcome to Davud Qasimov's interactive shell v1.0.0

Type help to see available commands.


davud@portfolio:~$

Let's connect

Feel free to reach out about my projects, certifications, or anything cybersecurity-related.

[email protected]