File Nº 0x6D / Subject: m0rgxn
Local --:--:--
Personnel record / File Nº 0x6DClassification: Public

Photo of m0rgxnTop 5 · HTB TN
m0rgxn0x6D · TUNIS · 2026
Subject — status: active

m0rgxn

Junior Penetration Tester

Standing
Top 5 · HackTheBox Tunisia · 70+ machines solved
Base of operations
Tunis
Languages
English / French / Arabic
§ 02 — Subject statement

Introduction


I am a passionate cybersecurity enthusiast and a dedicated software engineering student. My journey in the tech world has been driven by a deep curiosity for understanding how systems work and a strong desire to create secure and efficient solutions. I thrive on challenges that allow me to apply my knowledge and skills to protect digital assets and contribute to the advancement of technology. I am currently ranked Top 5 in Tunisia on HackTheBox. You can find my full CV here.
National rank · HTB
Top 5
Machines solved
70+
§ 03 — Training history

Studies


  1. EDU-01

    National Engineering School of Tunis (El Manar, Tunisia)

    Engineering Degree in Computer Science, Sept 2023 – present.

  2. EDU-02

    Preparatory Institute for Engineering Studies El Manar (El Manar, Tunisia)

    Preparatory Studies for Engineering in Physics and Technology, Sept 2020 – Jul 2023. Ranked top 8% in the National Entrance Exam to Engineering Schools.

§ 04 — Known capabilities

Technical skills


CAP-01

Web & Active Directory Penetration Testing

Currently focusing on AD and web application penetration testing through HackTheBox active machines, ranked Top 5 nationally with 70+ machines solved. I publish writeups for the labs I find most enjoyable and challenging while preparing for the CPTS certification.

  • HackTheBox
  • Burp Suite
  • Nmap
CAP-02

Red Teaming

Building out red team infrastructure on AWS: C2 frameworks, redirectors, and OPSEC-safe tooling. I use it to simulate lateral movement and privilege escalation across hybrid Active Directory / EntraID environments.

  • AWS
  • Terraform
  • Ansible
CAP-03

Azure Red Teaming & Offensive Tooling

During a red-team internship I've been mapping cloud attack paths, abusing Azure RBAC, managed identities, and service principals to turn a single foothold into tenant-wide access across hybrid AD / EntraID. I like turning what I find into tooling. The most recent is Fenrir, a Python CLI that automates the managed-identity attack chain from recon through to post-exploitation.

  • Azure
  • Managed Identities
  • Python
CAP-04

AI for Security

Experience building NLP models and data pipelines, which I'm now applying toward AI-assisted security tooling, from automating recon and log triage to experimenting with LLMs for vulnerability analysis.

  • Python
  • NLP
§ 05 — Open channels

Contact