Security Engineer specializing in Web, API, Mobile (Android), and Active Directory security.
I break systems (ethically), build reconnaissance tools, and document real-world attack techniques.
- π B.Sc. in Systems & Computer Engineering from Al-Azhar University (2024)
- π€ Certified: eWAPT (INE), CyberTalents Web/Mobile/AD Pentester, APIsec University
- π² ITI Graduate: Completed intensive 4-month Offensive Security & Penetration Testing program (2025)
- π Focused on OWASP Top 10, API business logic flaws, Android static/dynamic analysis, and AD attack chains
- π Building automation tools for reconnaissance and attack surface mapping
- π Documenting security research, CTF writeups, and exploitation techniques
- π Based in Cairo, Egypt
- π Web & API Pentesting: Manual exploitation, authentication bypass, JWT manipulation, business logic vulnerabilities
- π² Android Security: Static/dynamic analysis using Frida, JADX, MobSF, and objection
- π€ Active Directory Attacks: Lateral movement, privilege escalation, Kerberos exploitation
- π FalconRecon β Bash-based reconnaissance automation framework for attack surface enumeration β View Project
- π FalconServiceAnalyzer β Android service attack surface analyzer with automated command generation
- π Daily Security Notes β TIL Documentation
- π Technical articles on web, API, and mobile exploitation
- π CTF walkthroughs from PortSwigger Academy, TryHackMe, HackTheBox, CyberTalents
- π² Real-world attack vectors and remediation guidance
- π Read my writeups on Medium
- eWAPT β eLearnSecurity Web Application Penetration Tester (INE)
- Certified Web Application Penetration Tester β CyberTalents / ITI
- Certified Mobile Penetration Tester β CyberTalents / ITI
- Certified Active Directory Penetration Tester β CyberTalents / ITI
- API Penetration Testing β APIsec University