Proud to share that we have successfully completed and defended OT Sentinel AI 🚀 — a Detection & Response Platform for ICS/OT environments. I led the Detection Pipeline: data processing, feature engineering, model development, and integrating detection capabilities into the platform.
Ahmed
Mahmoud
Jr. Penetration Tester
Building systems that think like attackers
and detect threats before they land.
About Me
I'm Ahmed Mahmoud, a penetration tester focused on offensive security, vulnerability research, and security engineering.
My work spans web, API, and network penetration testing, with a strong interest in identifying exploitable weaknesses, analyzing attack paths, and understanding how real-world systems can be broken and defended. I'm also active in bug bounty hunting, with a focus on vulnerabilities such as IDOR, SSRF, authentication bypass, broken access control, and business logic flaws.
Alongside offensive security, I build cybersecurity projects that apply AI, machine learning, and deep learning to network traffic analysis, anomaly detection, and threat monitoring, including detection and response workflows for enterprise and industrial environments.
I'm currently studying Network & Cybersecurity at Elsewedy University of Technology, while continuously sharpening my skills through hands-on labs, applied security research, technical writing, and real-world cybersecurity projects.
Download CVWhere I've Worked
Hunting vulnerabilities across public and private programs — IDOR, XSS, SSRF, auth bypass, and business logic flaws. Chaining attack paths to demonstrate real-world impact beyond surface-level findings.
Training ML models for cybersecurity — classification, anomaly detection, and sequence models applied to network traffic analysis. Building real-time threat scoring pipelines.
Gained hands-on experience in digital forensics, SOC operations, and penetration testing. Analyzed network traffic and system logs to detect malicious activity using Wireshark and Splunk. Performed vulnerability assessments and basic exploitation with Metasploit Framework, and worked on network security simulations using GNS3 while applying security best practices aligned with NIST frameworks.
Microsoft-backed program on cloud security and DevSecOps — Azure security services, cloud-native threat monitoring, and secure pipeline practices.
Hands-on training covering vulnerability scanning, web app security, cloud security, and SIEM operations with enterprise-grade tooling at Smart Village.
Technical Stack
What I've Built
AI-powered Network Detection & Response platform for Industrial Control Systems (ICS/OT) — real-time traffic monitoring with centralized threat visibility.
- Hybrid detection pipeline: XGBoost for known attacks + Autoencoder for zero-day anomalies
- Fusion engine with risk scoring to prioritize alerts and cut analyst noise
- Validated on a realistic ICS lab (GRFICSv3 + Modbus TCP) — not just a synthetic dataset
- Owned the full AI detection pipeline: feature engineering → model dev → inference API integration
Designed to solve a core OT security challenge — limited visibility into industrial traffic and the difficulty of detecting both signature-based attacks and unknown threats — the system combines a hybrid detection pipeline using XGBoost for known attack classification and an Autoencoder for zero-day anomaly detection, with a Fusion Engine and risk scoring layer to prioritize alerts and improve response accuracy.
Built and validated in a realistic ICS lab environment based on GRFICSv3 and Modbus TCP traffic, supporting real-time monitoring, threat analysis, alerting, asset visibility, and operator-focused security monitoring for industrial networks. My contribution focused on the AI Detection Pipeline — feature engineering, XGBoost and Autoencoder model development, fusion and risk scoring logic, and integrating the AI inference workflow into the platform's detection API.
Hybrid ensemble (LightGBM + XGBoost + Isolation Forest + DBSCAN) with BiLSTM + GRU + Attention for sequential analysis and SHAP explainability.
Real-time IDS combining Suricata + XGBoost on CIC-IDS datasets, Zeek enrichment, and a live Streamlit alert dashboard.
Linux iptables firewall with dynamic IP/port/protocol blocking, persistent SQLite logging, real-time stats, and an interactive CLI.
ESP32 honeypot studying real IoT behaviour under Evil Twin attacks, with Flask logging server and Chart.js analytics dashboard.
End-to-end GRC framework for M&A cyber risk: due diligence → quantitative scoring → integration decision → post-merger governance tracking.
Infrastructure-as-Code platform that transforms YAML campus blueprints into automated enterprise network deployments, including topology generation, router and switch configurations, security policy enforcement, validation workflows, and fully orchestrated GNS3 environments.
Hybrid AI and digital forensics platform designed to detect deepfakes, AI-generated images, and manipulated media using ensemble machine learning models, forensic signal analysis, and evidence-driven reporting. Combines deepfake detection, tampering analysis, compression artifact inspection, and authenticity scoring into a unified forensic workflow with real-time dashboard visualization and automated report generation.
Adaptive reconnaissance orchestration platform that correlates recon data into prioritised attack chains, automated risk scoring, and intelligent exploitation paths for web security assessments.
Education
What I Write
A technical teardown of a real-world WhatsApp-delivered malware chain — how attackers weaponize trusted messaging platforms to establish initial access, evade detection, and move laterally.
Bug Bounty Recon in 2026 — What Works, What's Dead, and What Most People Skip
Let's Connect
Looking to collaborate on security research, or AI-driven detection? Open to internships, freelance work, and research partnerships.