Penetration tester, red team operator, and bug bounty hunter. I find vulnerabilities before they become incidents. Every finding comes with a proof-of-concept.
Industry-recognized credentials that back up the skills.
Every finding comes with a proof-of-concept script.
OSINT tool exposing origin IPs behind Cloudflare. Multi-source engine using DNS history, SSL CT logs, and SPF records with intelligent verification scoring.
Active on YesWeHack. Targeting auth bypasses, IDOR, SQLi, XSS, and API logic flaws. First bounty earned March 2026.
Full-scope adversary emulation and advanced pentesting. Simulating real-world attack chains to strengthen security postures.
SPF/DKIM/DMARC deployed across 20+ enterprise domains with measurable 90% phishing reduction.
1st place recently, 3rd national in 2019. Active on HackTheBox and TryHackMe platforms.
Discovered an Improper Authentication vulnerability on a live production target through YesWeHack. The flaw allowed unauthorized access through a flawed authentication mechanism — reported responsibly with full PoC and remediation guidance.
Freelance & contract. Based in Casablanca, operating globally. Also open to full-time offensive security roles.