From Theory to Live-Fire VAPT: A 60-Day Internship Journey in Simulated Enterprise Exploitation + Video Introduction: The transition from academic cybersecurity theory to practical offensive security operations represents a critical inflection point in any security professional's development. Moosa Adnan's recently completed 60-day internship at ApexPlanet Software Pvt Ltd exemplifies this transformation, moving from classroom concepts to executing full-scope Vulnerability Assessment and Penetration Testing (VAPT) within an isolated, enterprise-emulative environment. His engagement, spanning February 11 to April 11, 2026, highlights the indispensable role of hands-on simulated labs in cultivating the technical intuition required to identify, exploit, and remediate real-world vulnerabilities across networks and web applications....
60-Day VAPT Internship Journey at ApexPlanet Software Pvt Ltd
More Relevant Posts
-
Cyberster Blue Team Internship – Week 12 This week marked the completion of Phase Two of my DFIR capstone, a full-scale insider threat investigation built around the M57.biz case. Unlike earlier labs, I was given a primary disk image, a raw memory capture, and two USB drive images, and had to work through the investigation from evidence handling to the final forensic report without knowing upfront what had happened. Here's what I worked on: • Set up a multi-source Autopsy case, hashed the evidence with MD5 and SHA-256, and ran a full ingest across the disk and both USB images. • Established a system baseline from the SOFTWARE, SYSTEM, and SAM registry hives, including hostname, timezone, installed software, and user account activity. • Profiled the subject's normal role and working pattern using file system artefacts, LNK files, and Recent Items. • Installed and configured Volatility 3 to analyse the raw memory image for processes, process relationships, network connections, and command line activity. • Correlated memory findings with disk evidence to build a consistent picture of the system's state. • Examined both USB drives, recovered deleted files, and compared timestamps across disk and USB evidence to trace data movement. • Reviewed email and browser artefacts, including working around legacy file formats that Autopsy's automated parsers could not process. • Built a Master Event Sequence normalised to a single timezone to reconstruct the incident from start to finish. The biggest lesson from this capstone was how little any single piece of evidence tells you on its own. Disk, memory, USB, and email artefacts each answer a different part of the investigation. Correlating them is what allows a more complete and defensible picture to emerge. I also learned the importance of being honest about investigative limitations. Understanding what the evidence proves, what it suggests, and what remains an open gap is a core part of credible forensic analysis. Overall, Week 12 strengthened my practical experience with Autopsy, Volatility 3, Registry Explorer, memory forensics, USB and removable media analysis, and cross-artefact timeline correlation. With the completion of this capstone, I've officially completed my Internship with Cyberster. I'm grateful for the practical experience, challenges, and knowledge I've gained throughout the internship. A special thank you to my instructor, Sir Abdullah Zia, for his continued guidance and support throughout this internship. Cyberster #CyberSecurity #DigitalForensics #DFIR #BlueTeam #MemoryForensics #IncidentResponse #Autopsy #Volatility #RegistryForensics #CybersterInternship #InformationSecurity #DigitalInvestigation
To view or add a comment, sign in
-
From Intern to Innovator: Building Astra-Scan and Mastering Web Application VAPT + Video Introduction The cybersecurity industry faces a persistent shortage of skilled professionals capable of bridging the gap between theoretical knowledge and practical, offensive security execution. A recent internship completion announcement from a Top 1% TryHackMe player highlights a rigorous, hands-on journey through the Web Application Vulnerability Assessment and Penetration Testing (VAPT) lifecycle, culminating in the development of a custom AI-powered scanning tool....
To view or add a comment, sign in
-
Week 9 down in the Cyberster Blue Team Internship! 🕵️♂️💻 This week shifted focus to Browser Forensics, LNK File Analysis & Unified Timeline Correlation — piecing together how users actually interact with a system beyond just OS-level artifacts. 🔍 What I worked on: ✅ Browser Forensics (Chrome/Edge) — acquiring & hashing SQLite databases, analyzing history, downloads, cookies & cache ✅ LNK File Analysis — parsing Windows shortcut artifacts to reconstruct recent file access, USB usage & network shares ✅ Unified Timeline Building — normalizing timestamps to UTC and merging browser, Prefetch, LNK & event log data into one master timeline ✅ Cross-Artifact Correlation — connecting browser activity → LNK access → tool output review to build a defensible investigative narrative 💡 Biggest takeaway: A single artifact tells you what happened. A unified, correlated timeline tells you the story — sequence, intent & context. Grateful for the continued mentorship from my instructor, Abdullah Zia, as I keep sharpening my Blue Team & DFIR skills! 🛡️ #CyberSecurity #DigitalForensics #DFIR #BlueTeam #Internship #BrowserForensics #TimelineAnalysis #CyberSter
To view or add a comment, sign in
-
Week 5 of my Blue Team Internship at Cyberster — done. 🍀 Spent this week on the full malware-analysis lifecycle — sample acquisition through detonation to a working detection layer and formal IR plan: ♦ Sourced two live samples from theZoo, following the connect → download → verify → airgap → analyse order strictly, hashing (SHA256/MD5) each sample the moment it was extracted ♦ Ran static analysis with file, exiftool, binwalk, and strings (ASCII + -el Unicode passes) — caught a JS dropper hiding behind a String.fromCharCode decoder, and a PE/.NET sample masquerading as a "PDF Previewer" under a fake publisher name ♦ Detonated both samples interactively inside ANY.RUN with FakeNet live, manually driving execution rather than trusting an automated report, and watching the process tree, network, registry, and file-system panels in real time ♦ Almost logged Windows' own WerFault.exe crash telemetry as C2 traffic — caught the misattribution before it made it into the IOC list ♦ Replayed the session PCAP through Suricata in offline mode and wrote custom detection rules, plus MITRE-mapped Wazuh rules in local_rules.xml, each one tied to a specific observed behaviour rather than a generic template ♦ Wrote the Incident Response Plan across all four NIST SP 800-61 phases scoped honestly to what the evidence actually supported, not the clean narrative a template would assume The biggest lesson this week? A detection rule is only as trustworthy as the evidence behind it an invented IOC to paper over a gap is worse than leaving the gap marked open. Another big thanks to Abdullah Zia and Cyberster for a curriculum that keeps forcing real judgment instead of a checklist. Full breakdown (labs, troubleshooting, screenshots) attached below. 📎 Excited for Week 6. 🚀 #CyberSecurity #SOC #MalwareAnalysis #ANYRUN #Suricata #Wazuh #IncidentResponse #InfoSec #Internship #Cyberster #BlueTeam
To view or add a comment, sign in
-
Our Network & Cybersecurity interns joined our technical team from day one, putting their knowledge into practice in a real-world environment. They worked through real incident scenarios, explored complex network architectures, and received continuous mentorship, turning technical challenges into valuable learning experiences. Here’s a look back at their journey, key takeaways, and what hands-on career growth looks like in practice. Ready to launch your cybersecurity career? Stay tuned for our upcoming internship opportunities!
To view or add a comment, sign in
-
🔐 Week 5 - VAPT Practical Learning | Cybersecurity Internship I’m Pleased to share my Week 5 Practical work as part of the Cybersecurity Internship at DG Interns Hub. 🛠️ Tools & Activities: 🔎 Nmap — Network scanning, port discovery, service & version detection 🛡️ Nikto — Web server security assessment and configuration analysis 🌐 Burp Suite — HTTP request interception and web traffic analysis 🖥️ Apache/Ubuntu Lab — Target service verification and security assessment 📊 Documented technical findings and security recommendations 💡 Key Learning: Network discovery → service enumeration → web-server assessment → HTTP traffic inspection → security findings and recommendations. #CyberSecurity #VAPT #PenetrationTesting #Nmap #Nikto #BurpSuite #EthicalHacking #NetworkSecurity #WebSecurity #CybersecurityInternship #DGInternsHub #Internship #InformationSecurity
To view or add a comment, sign in
-
Cybersecurity experience doesn't always require an #internship at a major tech company. Rommel Christ, a computer science student spent his summer as an IT intern through our Academic Internship Program. He built more than 20 web pages for the American Public Transportation Association website, worked hands-on with SIEM software and penetration testing results and was trusted with administrative access to nearly every tool he touched. He also connected directly with #cybersecurity leaders at the Washington Metropolitan Area Transit Authority (WMATA) and the Regional Transportation District, relationships that grew out of doing the work well. "A few experiences will stay with me. Visiting the Metro Integrated Command Center. Seeing firsthand what it takes to protect public transportation, both physically and digitally, through their cybersecurity team and viewing all the real-time transit camera feeds was incredible." Read the full story: https://lnkd.in/g86wva-D #Internship #Cybersecurity #ComputerScience
To view or add a comment, sign in
-
-
ReliaQuest is committed to investing in future generations by raising awareness of cybersecurity and cyber careers through our partnership with Junior Achievement. Through this partnership with Junior Achievement, we connect classroom learning with real-world problems, bridge the gap between education and hands-on experiences, and prepare students for successful careers in cybersecurity. #ReliaQuest #MakeSecurityPossible #Internship #Careers
To view or add a comment, sign in
-
-
🎓 Wrapping up the Cyberster Blue Team Internship — Week 12 Twelve weeks ago I started this internship not knowing exactly where it would take me. Twelve weeks and two full domains later, I can say it took me further than I expected. The internship was split across two core pillars of Blue Team defense: 🔹 SOC Operations — log analysis, alert triage, detection engineering, and building the muscle memory to tell real signal from noise 🔹 Digital Forensics & Incident Response — disk, memory, and USB forensics; building an evidentiary case from raw artifacts instead of assumptions Week 12 was the capstone: a full four-part insider threat investigation — from system triage and memory analysis with Volatility, through USB and deleted-file recovery, to a final forensic report answering the three questions every investigation comes down to: what happened, who did it, and how do you prove it. The biggest lesson from this internship wasn't a tool or a command — it was learning to let the evidence lead the conclusion, not the other way around. Every finding in this report is cited back to a specific artifact, because in this field, "I think" doesn't hold up — "here's the hash, here's the timestamp, here's the match" does. Huge thanks to Abdullah Zia for the mentorship throughout this program — for pushing me to document rigorously, question my own assumptions, and treat every finding as something that has to survive scrutiny. And thanks to Cyberster for building an internship that didn't just teach tools, but taught how to think like an analyst. Full final report attached below. 📄 #CyberSecurity #BlueTeam #DigitalForensics #SOC #DFIR #Cyberster #Internship #IncidentResponse #ThreatHunting #InfoSec
To view or add a comment, sign in
-
Excited to share Project Winnie 🍯, one of the projects I worked on during my internship at KAUST (King Abdullah University of Science and Technology) The project focused on building and testing a honeypot-based security monitoring system using OpenCanary. As part of the project, we: • Built an isolated honeypot lab using Proxmox • Configured Ubuntu Server as the honeypot and Kali Linux as the attacker • Deployed multiple OpenCanary services, including SSH, FTP, HTTP/S, SMB, and Telnet • Simulated attacks such as network scanning, login attempts, and FTP brute-forcing • Analyzed the security events and logs generated by OpenCanary • Implemented real-time Microsoft Teams alerts for detected activity A big thank you to my fellow interns Layan Mashraie and Deema Alnasser for all the work we put into this project together. This project was a great opportunity to turn cybersecurity concepts into something practical and gain hands-on experience with honeypots, network security, Linux, attack simulation, security monitoring, and automation. We also had the opportunity to present Project Winnie at the WISER Expo, where interns from the WISER program across different departments came together to showcase the projects they worked on throughout their internships. It was a great way to wrap up the experience, share what we built, and see the work of other interns across the organization. #Cybersecurity #Honeypot #OpenCanary #NetworkSecurity #CybersecurityInternship #WISER #Proxmox #KaliLinux #InformationSecurity #InfoSec #CyberDefense #SecurityMonitoring #ThreatDetection #NetworkMonitoring #UbuntuServer #Linux #MicrosoftTeams #SecurityEngineering #BlueTeam #SOC #CybersecurityProjects #Internship #WISERProgram #WISERExpo #LearningByDoing #ProfessionalDevelopment #KAUST
To view or add a comment, sign in
-
Explore related topics
- Offensive Security Tools and Techniques
- How to Analyze Malware and Identify Vulnerabilities
- Transitioning from Web Developer to Cybersecurity Analyst
- How Cybercriminals Exploit Security Vulnerabilities
- Penetration Testing Methodologies
- Cybersecurity Lab Skills for Job Seekers
- Top Pentesting Techniques for Cybersecurity
- Ethical Hacking and Penetration Testing Guides
- Penetration Testing Services
- Email attack simulation study results