Skip to content
View sahnoun11's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report sahnoun11

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sahnoun11/README.md

Hi πŸ‘‹, I'm Oussama Sahnoun

Senior Offensive Cybersecurity Expert Β· Purple Team Lead Β· AI Systems Security Researcher

Purple Teaming Β· Active Directory Β· Threat Intelligence Β· AI/LLM Security

Typing SVG


🧠 About

class OussamaSahnoun:
    role        = "Senior Offensive Cybersecurity Expert"
    experience  = "7+ years β€” offensive & defensive security"
    background  = ["Purple Team Lead", "Red Teamer", "CTI Analyst"]
    sectors     = ["Banking", "Aerospace (Airbus, DO-326A)"]
    speaking    = ["Black Hat MEA 2025, Riyadh β€” AI & Predictive Threat Hunting"]
    cves        = ["CVE-2020-12297", "CVE-2020-24454", "CVE-2020-24451"]  # Intel PSIRT
    certs       = ["eCPPTv3", "eWPTx", "CRTP", "eWPT", "eJPT", "arcX CTI 101"]
    langs       = ["Python", "Bash", "PowerShell"]
    motto       = "Break it, prove it, help fix it β€” then teach the SOC to catch it next time."
  • πŸ”΄ Offensive: Web, API, Infrastructure & Cloud pentesting β€” full Active Directory kill chain (recon β†’ domain enum β†’ priv esc β†’ lateral movement β†’ domain admin β†’ cross-trust attacks)
  • 🟣 Purple Teaming: turning Red Team findings into SIEM detection rules alongside SOC teams
  • 🎯 CTI: MISP, OpenCTI, OSINT & dark web monitoring β€” indicators turned into reports SOC analysts can act on
  • πŸ€– AI/LLM Security: prompt injection, RAG pipeline attacks, agentic tool abuse, MCP surfaces, AI supply-chain risk
  • πŸ› CVE research: 3 published vulnerabilities, responsibly disclosed and coordinated with Intel PSIRT
  • 🌍 Languages: EN Β· FR Β· AR

πŸ“– I write long-form technical breakdowns on my blog β€” threat intel reports, ransomware deep-dives, and an ongoing AI Systems Security series.


πŸš€ Research, Projects & Writing

Project Area What it does
ThreatLens AI + DFIR Free AI SOC analyst for Windows/Linux logs β€” Groq LLaMA 3.3 + local embeddings, RAG over EVTX/log data, Streamlit UI. Presented live at Black Hat MEA 2025
WinLogHunt-V1.0 DFIR PowerShell-based Windows Event Log (EVTX) analyzer for Blue Teams β€” anomaly detection for ransomware, malware & CVE exploitation indicators
Cicada3301 / Stormous CTI reports Threat Intel Full CTI deep-dives: RaaS affiliations, MITRE ATT&CK mapping, IOCs, YARA/Sigma rules
AI Systems Security Specialist AI Security Ongoing series on securing AI systems β€” trust boundaries, agent tool abuse, AI red teaming

🧰 Tech & Tools

Python Bash PowerShell

Burp Suite Metasploit Cobalt Strike Nmap SQLMap OWASP ZAP Nessus InsightVM Prisma Cloud

BloodHound PowerView NetExec/CrackMapExec Impacket Mimikatz Rubeus SharpHound PEASS-ng ProxyChains

WinDbg Procmon Wireshark Sysmon

MISP OpenCTI MITRE ATT&CK YARA Sigma STIX/TAXII

AWS Azure Windows Server Red Hat CrowdStrike

Groq Ollama Streamlit RAG


πŸ… Certifications

CRTP eCPPTv3 eWPTx eWPT eJPT arcX CTI 101

  • πŸ—‘οΈ CRTP β€” Certified Red Team Professional
  • πŸ₯‡ eCPPTv3 β€” Expert-level Linux/Windows infrastructure & Active Directory pentesting β€” 2026
  • βš”οΈ eWPTx β€” Advanced Web Application Pen Tester eXtreme β€” 2024
  • πŸ•΅οΈ eWPT β€” Web Application Penetration Tester β€” 2023
  • πŸ›‘οΈ eJPT β€” Junior Penetration Tester β€” 2021
  • 🧭 arcX Foundation β€” Cyber Threat Intelligence 101 β€” 2025

πŸ“Š GitHub Stats

Contribution heatmap GitHub stats Top languages Commit activity graph GitHub streak

🐍 Contribution Snake

github contribution grid snake animation

"Attack like a Red Teamer. Defend like a Blue Teamer. Think like a Purple one."
β€” Oussama Sahnoun

Popular repositories Loading

  1. WinLogHunt-V1.0 WinLogHunt-V1.0 Public

    WinLogHunt is a PowerShell-based tool designed for Blue Teams and Incident Responders to quickly analyze Windows event logs for suspicious activities.

    PowerShell 3

  2. ThreatLens ThreatLens Public

    ThreatLens is a free, open-source AI assistant that analyses Windows Event Logs and Linux logs like a senior SOC analyst --- powered by Groq LLaMA 3.3 and local embeddings.

    Python 2 1

  3. sahnoun11 sahnoun11 Public

    πŸ‘‹ Hi, I’m Oussama Sahnoun 🎯 **Cybersecurity Engineer | Purple Team Operator** πŸ’‘ Offensive & Defensive Security | Threat Hunting | Detection Engineering 🌍 Based in Tunisia | πŸ“š Lifelong learner | πŸ’» O…

    1

  4. OpenChat OpenChat Public

    Forked from GhnimiWael/OpenChat

    Simple terminal-based chat application that uses the Python sockets library to communicate between a server and multiple clients

  5. sahnoun11.github.io sahnoun11.github.io Public

    HTML