Available — Summer 2026 Kuwait & remote

Mohammad
Alqattan.

Cybersecurity Analyst
01about

A graduate specialized in forensics, analytics, and incident response.

Cybersecurity graduate from Penn State University holding a B.S. in Cybersecurity Analytics & Operations, a minor in Security & Risk Analysis, and Penn State's NSA IST Certificate. Coursework spans digital forensics, malware analysis, incident response, network defense, and packet-level traffic analysis.

Areas of focus include Python-based security tooling, machine-learning classifiers for threat detection, static and dynamic malware analysis in Ghidra, and incident reconstruction from packet captures. Recent research work developed deterministic per-student PCAP generation for a network security teaching lab.

Emphasizes rigorous technical writing — incident reports, lab documentation, and analytical write-ups — as a first-class deliverable alongside technical work.

Education B.S. CybersecurityPenn State '26 · GPA 3.25
Based in Kuwait + remote
Focus Digital forensicsmalware, SIEM
Languages Arabic native
English fluent · IELTS 6.5
02selected work

Research, coursework, & things I'm proud of.

Personalized Wireshark network analysis lab system.

Undergraduate Research Assistant · Advisor: Prof. Nicklaus Giacobe · Penn State, May – Jul 2026

A Python/Scapy system that derives per-student PCAPs deterministically from SHA-256 hashes — rewriting TCP/IP, HTTP, and DNS fields, embedding secrets in HTTP payloads with Content-Length recalculation, and preserving stream integrity via checksum + sequence/ACK cascade repair.

Deployed as a CherryPy web service serving personalized labs, backed by 16 base traffic captures produced in a controlled Linux (Ubuntu) / VMware environment with tuned TCP congestion control (CUBIC + tc netem).

Python Scapy SHA-256 PCAP TCP/IP HTTP DNS CherryPy Linux
student ID — input abc123
SHA-256
256-bit digest 3f9a8e2c41bd76f0a91e d2b5af89cd12be4ff63a2104c
map → network
src.ip
10.42.17.9
dst.mac
00:1b:2c:f4:9a:e1
tcp.port
49874 → 80
proto
HTTP / TCP
output
lab.pcap · 0 packets · 0.0 MB
CYBER 440
Capstone
Team of 6 Jan – May 2026

Ransomware incident investigation across ~12M packets.

Six-person team investigation of a simulated municipal network compromise. Traced a multi-stage insider attack across ~12M packets in 41 PCAPs — DCSync credential harvesting, SAMR reconnaissance, IRC C2 beaconing, SMB2 ransomware — mapping every step of the evidence to the Cyber Kill Chain.

Owned the disk-image forensics workstream (FTK): reconstructed the initial compromise from USB registry artifacts, link files, prefetch records, and email stores. Findings anchored the attack timeline in the team's incident-response report.

FTK Volatility Wireshark TShark Event Logs Cyber Kill Chain
CYBER 362
Security Analytics Aug – Dec 2025

Spam & phishing classifiers — ~97% accuracy on TREC07p.

Built classifiers in Python/scikit-learn using TF-IDF feature extraction across logistic regression, decision-tree, and neural-network models. Trained on the ~75,000-message TREC07p corpus and SMS Spam Collection; evaluated with confusion matrices, precision, recall, and F1 across stratified splits. Reached ~97% classification accuracy on 1,115 held-out messages.

Companion SIEM work in Splunk: ingested and indexed event datasets, wrote SPL searches enriched with lookup tables, and built interactive reports, charts, and dashboards.

Python scikit-learn TF-IDF pandas Splunk SPL
CYBER 366
Malware Analytics Aug – Dec 2025

Malware analysis & reverse engineering in Ghidra.

Static and dynamic analysis of live samples in isolated Windows VMs: MD5 hashing and VirusTotal triage, strings/FLOSS extraction, PEiD packer detection with UPX unpacking, DLL import inspection, and registry monitoring.

Reverse-engineered four CrackMe binaries in Ghidra, recovering embedded authentication logic from disassembly to defeat password checks; used debuggers to trace and control malware execution paths safely at runtime. Reconstructed real-world infection chains from PCAPs — victim hosts, download URLs, C2 IPs — and co-presented the REMnux toolkit (Detect It Easy, CyberChef, edb) to the class.

Ghidra PEiD UPX FLOSS Volatility REMnux Windows VM
03skills

What I work with, day to day.

Security & Analysis
Network Security Digital Forensics Malware Analysis Incident Response SIEM (Splunk) Risk Analysis
Networking
Wireshark TShark PCAP Analysis Packet Manipulation TCP/IP HTTP DNS
Programming & Tools
Python Scapy scikit-learn pandas CherryPy Java SQL Linux VMware iptables Ghidra FTK Volatility
04credentials & honors

Credentials & active certifications.

honors & awards
Scholarship Government Scholarship — Ministry of Higher Education, Kuwait 2022 – 2026
Dean's List Recognized — Fall '23, Summer '24, Summer '25, Spring '26 Penn State