Purple Teaming Β· Active Directory Β· Threat Intelligence Β· AI/LLM Security
class OussamaSahnoun:
role = "Senior Offensive Cybersecurity Expert"
experience = "7+ years β offensive & defensive security"
background = ["Purple Team Lead", "Red Teamer", "CTI Analyst"]
sectors = ["Banking", "Aerospace (Airbus, DO-326A)"]
speaking = ["Black Hat MEA 2025, Riyadh β AI & Predictive Threat Hunting"]
cves = ["CVE-2020-12297", "CVE-2020-24454", "CVE-2020-24451"] # Intel PSIRT
certs = ["eCPPTv3", "eWPTx", "CRTP", "eWPT", "eJPT", "arcX CTI 101"]
langs = ["Python", "Bash", "PowerShell"]
motto = "Break it, prove it, help fix it β then teach the SOC to catch it next time."- π΄ Offensive: Web, API, Infrastructure & Cloud pentesting β full Active Directory kill chain (recon β domain enum β priv esc β lateral movement β domain admin β cross-trust attacks)
- π£ Purple Teaming: turning Red Team findings into SIEM detection rules alongside SOC teams
- π― CTI: MISP, OpenCTI, OSINT & dark web monitoring β indicators turned into reports SOC analysts can act on
- π€ AI/LLM Security: prompt injection, RAG pipeline attacks, agentic tool abuse, MCP surfaces, AI supply-chain risk
- π CVE research: 3 published vulnerabilities, responsibly disclosed and coordinated with Intel PSIRT
- π Languages:
ENΒ·FRΒ·AR
π I write long-form technical breakdowns on my blog β threat intel reports, ransomware deep-dives, and an ongoing AI Systems Security series.
| Project | Area | What it does |
|---|---|---|
| ThreatLens | AI + DFIR | Free AI SOC analyst for Windows/Linux logs β Groq LLaMA 3.3 + local embeddings, RAG over EVTX/log data, Streamlit UI. Presented live at Black Hat MEA 2025 |
| WinLogHunt-V1.0 | DFIR | PowerShell-based Windows Event Log (EVTX) analyzer for Blue Teams β anomaly detection for ransomware, malware & CVE exploitation indicators |
| Cicada3301 / Stormous CTI reports | Threat Intel | Full CTI deep-dives: RaaS affiliations, MITRE ATT&CK mapping, IOCs, YARA/Sigma rules |
| AI Systems Security Specialist | AI Security | Ongoing series on securing AI systems β trust boundaries, agent tool abuse, AI red teaming |
- π‘οΈ CRTP β Certified Red Team Professional
- π₯ eCPPTv3 β Expert-level Linux/Windows infrastructure & Active Directory pentesting β 2026
- βοΈ eWPTx β Advanced Web Application Pen Tester eXtreme β 2024
- π΅οΈ eWPT β Web Application Penetration Tester β 2023
- π‘οΈ eJPT β Junior Penetration Tester β 2021
- π§ arcX Foundation β Cyber Threat Intelligence 101 β 2025
"Attack like a Red Teamer. Defend like a Blue Teamer. Think like a Purple one."
β Oussama Sahnoun