LÊ NGUYỄN HỒNG PHÚC
094*-***-*** · *******************@*****.*** · github.com/BacSiCode · Tan Binh, Ho Chi Minh City FEATURED PROJECTS
·
– Ran HTTP flood (DoS) with k6, scaling from 1,000 to 4,000 virtual users - server went down at ~ 4,000 concurrent requests from a single IP.
– Scaled to DDoS using 10 Docker containers with rotating IPs, server crashed within seconds, significantly faster than the single-source test.
– Built a custom layer-7 firewall (rate limiting + IP banning) and integrated Cloudflare WAF & DDoS protection - server held stable under the load that had previously caused the crash.
– Wrote a monitoring dashboard tracking request rate, response time and error rate in real time, added a telegram bot to alert administrators automatically when thresholds were crossed.
GitHub: github.com/BacSiCode/spiritads
Team Leader — 4 members 01/2026 – 04/2026
Built a controlled environment to simulate volumetric attacks at scale, then designed and validated a layered defence to verify real-world protection.
DoS / DDoS Attack Simulation & Mitigation
GandCrab Ransomware Analysis · Team Leader — 3 members 02/2025 – 04/2025 Reverse-engineered the GandCrab RaaS infection chain in an isolated lab to understand how ransomware encrypts and holds data hostage.
– Mapped the Ransomware-as-a-Service (RaaS) model and phishing delivery chain used to drop the payload.
– Set up an air-gapped VMware / Kali Linux lab to safely execute and observe ransomware behaviour without risk to live systems.
– Analysedthe AES + RSA hybrid encryption scheme used by GandCrab to lock victim files and protect the decryption key.
– Wrote a Python simulation replicating the file encryption sequence and a controlled recovery scenario, used as a teaching demo.
– Documented recovery options — focused on shadow copy behaviour and offline backup isolation based on observed encryption patterns. GitHub: github.com/BacSiCode/BMMT_GandCrab_v1
(Google Career Certificates / Coursera)
CERTIFICATIONS
English Proficiency: B2 (CEFR)
Google Cybersecurity Certificate
· Laptop Bảo An 2024 – 2025
EXPERIENCE
IT Support Technician
– Diagnosed and fixed hardware failures (RAM, SSD, display) and OS issues across a busy repair-shop environment
– Set up Windows, drivers, and application software on over 100 devices, adapting each configuration to the customer's use case
– Helped customers figure out cost-effective upgrades based on actual usage rather than pushing the highest-spec option
– Tracked open repairs and device status to make sure nothing slipped through the cracks between intake and handoff Academic Competition Finalist – Reached the final round of the university "Database Design Challenge" competition ACHIEVEMENTS & ACTIVITIES
Threat Detection & Monitoring: Snort (rule writing, IDS/IPS), Wireshark (packet analysis), Burp Suite (basic web security testing), Grafana (dashboard & monitoring).
Network Security: pfSense (firewall management), Cloudflare WAF, TCP/IP, OSI Model, LAN/WLAN, IP rate limiting. Attack Simulation: hping3 (SYN flood, ICMP testing), k6 (HTTP load testing), mdk4 (WLAN deauthentication), Docker (lab environments).
Systems & Platforms: Linux (Kali, Parrot, Fedora), Windows Server (Active Directory), VMware Workstation. Programming & Automation: Python, C#, GitHub, Telegram Bot API. TECHNICAL SKILLS
B.Sc. Information Security · GPA: 3.28 / 4.0
Ho Chi Minh City University of Industry and Trade (HUIT) 08/2023 – 08/2027 EDUCATION
SUMMARY
Third-year Information Security student at HUIT who spends most of my lab time breaking things on purpose - ransomware sandboxes, DoS simulations, custom firewalls. I've had real-world exposure through IT support but want to move into SOC work full-time. I pickup new tools quickly, I'm comfortable reading packet captures, and I'd rather dig into an alert than close it unexamined.
SOC INTERN