terminal
$|

> Summary

A motivated and detail-oriented Computer Science student specializing in Cybersecurity, passionate about securing digital assets and identifying system vulnerabilities. Hands-on experience in web application security, with growing practical exposure and strong interest in mobile application security and reverse engineering. Seeking opportunities in offensive security and penetration testing.

> Experience

Offensive Security Intern

CYBERTEQ
Recent
  • Conducted penetration testing on client infrastructures covering web, network, and mobile applications.
  • Performed mobile application security assessments, including APK reverse engineering, traffic interception, and dynamic analysis (Frida, MobSF, and Burp Suite).
  • Documented findings and prepared detailed security assessment reports with remediation recommendations.

Freelance Bug Bounty Hunter

Self-Employed
Ongoing
  • Discovered and reported security flaws in web applications through responsible disclosure programs.
  • Achieved validated payouts and bounties while continuously improving skills via vulnerability research.

Penetration Testing Training

DEPI
Training Program
  • Trained on practical web application penetration testing and network vulnerability assessment.
  • Developed strong understanding of Linux, network fundamentals, and ethical hacking methodologies.

Network Security Training

ITI
Training Program
  • Completed courses in CCNA, Cybersecurity Essentials, Ethical Hacking, and Firewall Configuration (Fortigate & Palo Alto).

> Projects

OTX-Based Threat Intelligence Analyzer for IOC Correlation and Severity Scoring (Course Project)

Python
  • This project, the OTX-Based Threat Intelligence Analyzer, is a specialized software tool designed to bridge the gap between raw data and actionable intelligence.
  • The system serves as an automated aggregator and analyzer. It ingests potential Indicators of Compromise (IOCs)—such as suspicious IP addresses, file hashes, or domains—and queries the AlienVault Open Threat Exchange (OTX) to determine their malicious nature.
  • By automating the correlation and severity scoring of these indicators, the tool provides security analysts with immediate, context-rich data to accelerate incident response.

AndroPen — Docker-Based Android Penetration Testing Platform (Graduation Project)

Go, React, TypeScript, Python, Docker, MongoDB, Redis
  • AndroPen is a multi-container, Docker-orchestrated platform designed to provide a comprehensive, browser-accessible environment for Android application security testing.
  • The platform delivers end-to-end capabilities including static analysis (manifest audits, secret scanning, Semgrep, FlowDroid taint analysis, and MASVS compliance scoring), APK patching with an integrated smali debugger built on a custom JDWP client and VS Code extension, and dynamic analysis through Frida instrumentation and Burp Suite proxy integration with automated CA installation.
  • It features an AI-powered analysis module supporting six LLM providers for automated vulnerability detection and Frida hook generation, alongside workflow automation, team project collaboration, and full reporting in SARIF, HTML, and PDF formats.

> Education

Egypt-Japan University of Science and Technology (E-JUST)

New Borg El Arab City, Alexandria

Bachelor's Degree in Computer Science

Major: Computer Networks and Cybersecurity

Dakahlia STEM School

Gamasa City, Dakahlia

Math Section

> Skills

Programming

PythonHTMLCSSJavaScriptPHPSQL

Operating Systems

Linux (Kali, Ubuntu)

Networking

Network Scanning & Monitoring (Nmap, Wireshark)Network Protocols (TCP/IP, HTTP/S)

Web Security

Vulnerability AssessmentManual PentestingAutomated Tools (Burp Suite)

Mobile Security

APK AnalysisFridaMobSFADBDynamic Instrumentation

Reverse Engineering

Static/Dynamic Analysis of Applications

Other Tools

GitXAMPPMS SQL ServerBash ScriptingDocker

> Certifications & Trainings

TryHackMe – Junior Penetration Tester PathTryHackMe – Web FundamentalsTryHackMe – Introduction to CybersecurityTryHackMe – Pre-SecurityThe SecOps Group - Certified AppSec Practitioner (CAP)

> Competitions

  • ZINAD-IT CTF
  • Cybertakents Cohort 7 Online CTF
  • ICMTC-2024 CTF