I am a passionate cybersecurity enthusiast and a dedicated software engineering student. My journey in the tech world has been driven by a deep curiosity for understanding how systems work and a strong desire to create secure and efficient solutions. I thrive on challenges that allow me to apply my knowledge and skills to protect digital assets and contribute to the advancement of technology. I am currently ranked Top 5 in Tunisia on HackTheBox. You can find my full CV here.
National Engineering School of Tunis (El Manar, Tunisia)
Engineering Degree in Computer Science, Sept 2023 – present.
EDU-02
Preparatory Institute for Engineering Studies El Manar (El Manar, Tunisia)
Preparatory Studies for Engineering in Physics and Technology, Sept 2020 – Jul 2023. Ranked top 8% in the National Entrance Exam to Engineering Schools.
§ 04 — Known capabilities
Technical skills
CAP-01
Web & Active Directory Penetration Testing
Currently focusing on AD and web application penetration testing through HackTheBox active machines, ranked Top 5 nationally with 70+ machines solved. I publish writeups for the labs I find most enjoyable and challenging while preparing for the CPTS certification.
HackTheBox
Burp Suite
Nmap
CAP-02
Red Teaming
Building out red team infrastructure on AWS: C2 frameworks, redirectors, and OPSEC-safe tooling. I use it to simulate lateral movement and privilege escalation across hybrid Active Directory / EntraID environments.
AWS
Terraform
Ansible
CAP-03
Azure Red Teaming & Offensive Tooling
During a red-team internship I've been mapping cloud attack paths, abusing Azure RBAC, managed identities, and service principals to turn a single foothold into tenant-wide access across hybrid AD / EntraID. I like turning what I find into tooling. The most recent is Fenrir, a Python CLI that automates the managed-identity attack chain from recon through to post-exploitation.
Azure
Managed Identities
Python
CAP-04
AI for Security
Experience building NLP models and data pipelines, which I'm now applying toward AI-assisted security tooling, from automating recon and log triage to experimenting with LLMs for vulnerability analysis.