Om Shah

Cybersecurity student & automation engineer

  • Sydney, Australia
  • UTS Cybersecurity, '26
  • Available for opportunities
Featured DNS Exfiltration Live Demo
om@uts:~
$ whoami
om_shah
$ cat skills.txt
[+] Network Scanning
[+] Python Automation
[+] Web App Testing
[+] Vulnerability Assessment
$
Scroll Down

01. About Me

At a glance

UTS cybersecurity student with 3+ years in quality assurance, automation, and scripting.

I build Python and API-driven tooling for security checks and workflow automation.

Delivered 35% faster case handling by replacing manual steps with repeatable systems.

Focused on misconfigurations, attack surface reduction, and practical security tooling.

Python, APIs, Automation, Security Tooling

35% 35% faster case handling
3+ years quality assurance + automation
2026 UTS graduation

My professional journey

02. Experience

Automation Engineer

Migrate Zone

Jul 2023 to present · Part-time · Dec 2024 to present in current role

  • Merged financial audit checks into one workflow, cutting duplicate checks and manual cross-referencing.
  • Co-led modular automations for file naming, risk flagging, and routing; cut average case time from ~8h to ~5.3h (~35%).
  • Built a prefill tool mapping validated case data into Excel lodgement templates, speeding prep and reducing repeat checks.
  • Built a lightweight scraper for policy update pages, replacing repeated manual checks.

03. Featured Projects

Filter by
DNS tunnel PCAP visualization showing network topology and packet timeline
Red teaming Demo video coming soon

Covert Channel: DNS Exfiltration via DLL Sideloading

Sideloaded a DLL via a Microsoft-signed binary and exfiltrated a file by hiding it in normal DNS traffic, bypassing Defender, AMSI, SmartScreen, and Windows Firewall. Includes a paired blue team detector. Isolated VMware lab.

  • C
  • Python
  • DNS tunneling
  • DLL sideloading
  • Wireshark
Immigration Case Workflow Automation Toolkit preview
Production

Immigration Case Workflow Automation Toolkit

Production toolkit at Migrate Zone. Staff upload case documents; the tool merges, OCR-reads, and validates them against visa-specific checklists. Missing or outdated items are flagged and results are bundled into review-ready packages.

  • Python
  • Adobe PDF Services
  • OCR
  • JSON
SMS bulk-style classifier demo UI
Applied ML API status: checking

SMS bulk-style detector (machine learning)

Neural network trained on SMS text that scores how much a message resembles bulk or automated wording. Deployed as a live API with an interactive demo.

  • Python
  • TensorFlow
  • GloVe
Production

Document Completeness Check & Form Pre-fill Tool

Production tool at Migrate Zone. OCR-reads case documents, validates against visa-specific checklists, flags missing or expired items, then auto-fills verified data into Excel lodgement templates.

  • Python
  • OCR
  • Excel
  • JSON schemas
IDS

Intrusion Detection System (IDS)

Multi-class intrusion detection pipeline using Random Forest and MLP models on network flow data. Includes train/test splits, scaling, confusion matrices, and per-class evaluation. Benchmark scope, not a live deployment.

  • Python
  • Pandas
  • Network traffic analysis
Production

PDF Invoicing & Document Tools

ITonKey internship. Converts structured business data into branded, multi-page PDF invoices. Also built inventory tracking and reporting features.

  • Python
  • PDF Generation
  • Excel
TLS interception lab with mitmproxy preview
Red teaming

TLS Interception Lab with mitmproxy

Man-in-the-middle attack using mitmproxy in an isolated lab. Installed a rogue CA on a Windows 10 VM to intercept and decrypt HTTPS traffic in real time, including login flows. Lab environment only.

  • Kali Linux
  • mitmproxy
  • OpenSSL
  • Windows 10 VM
Notification listener Android demo (Wellness Pulse) preview
Education

Notification listener - Android demo (Wellness Pulse)

Android app with a wellness-style UI that demonstrates notification listener risk: what the permission actually exposes and why "tap allow" matters. Tested on my own device/emulator only.

  • Android
  • Kotlin
  • Privacy
  • Notification listener

04. Papers & reports

Technical writing: assessments, lab reports, and research-style submissions from my degree.

05. Education & technical foundations

Formal study and subject depth from my UTS transcript: these are degree topics, not separate industry certifications.

Cybersecurity

description: |

Built STRIDE-style threat models for sample applications and documented mitigations for each threat class in written assessments.

UTS program

System security

description: |

Hardened Linux VMs (services, permissions, updates) and compared access-control models in practical lab submissions.

UTS program

Cloud security (AWS)

description: |

Deployed small workloads using IAM roles, security groups, and least-privilege reviews in AWS console lab exercises.

UTS program

Digital forensics

description: |

Imaged virtual disks, extracted timelines and artefacts with forensic tools, and wrote short reports with documented handling steps.

UTS program

Formal qualification

description: |

Bachelor of Cybersecurity

University of Technology Sydney

2023 to present. Expected graduation: June 2026

06. Skills & Tools

Security Testing

description: |
  • Network scanning (Nmap / NSE)
  • Vulnerability assessment
  • Web application testing
  • Known vulnerability research
  • Offensive security labs (university)

Defensive Security

description: |
  • Threat modeling (STRIDE)
  • Cryptography fundamentals
  • Routing & switching
  • Information security management

Tools & technologies

description: |
  • Metasploit
  • Wireshark
  • Nmap / NSE scripts
  • Postman / Chrome DevTools / Jira
  • VMware / VirtualBox / Cisco Packet Tracer

Programming & Scripting

description: |
  • Python
  • Selenium
  • JSON / CSV / Excel
  • Git / GitHub
  • HTML / CSS

07. Get In Touch

Open to opportunities

availability: |

Open to cybersecurity and automation roles. Summary of experience, roles, and projects: resume. Based in Sydney, Australia.