Android Security: The Falcon's Guide to Permissions & Attack Surfaces
Understanding the Android attack surface when auditing applications. A comprehensive guide to permissions, components, and security testing...
Hello, I'm Mahmoud Elshorbagy
RANK: Security Engineer
TARGET: Web, Mobile, API
MISSION: Penetration Testing

eWPT Certified
Web Penetration Testing
// Try typing "help"
Pro Tip: Try commands like whoami, skills, or contact
"Every tool is a weapon when you know how to wield it."
Web Application Penetration Tester
CyberTalents / ITI Joint Program
CyberTalents / ITI Joint Program
APIsec University
Offensive Security Track - Hardcopy
"Building tools that break systems, to make them stronger."
Advanced Bash-based automation tool for reconnaissance. Streamlines subdomain enumeration, port scanning, and vulnerability discovery.
Android Service Attack Surface Analyzer - Automated reconnaissance and attack command generation.
Cybersecurity research and automation utility built in Python.
Advanced Zero Trust access implementation designed with robust authentication mechanisms.
IoT/ICS Automation System integrating sensors, controllers, and a mobile interface.
"Think like an attacker, defend like a guardian."
Information Technology Institute (ITI), Nasr City, Cairo
Faculty of Engineering, Al-Azhar University — Cairo, Egypt
Understanding the Android attack surface when auditing applications. A comprehensive guide to permissions, components, and security testing...
Beyond Activities: exploiting Android Services with automation scripts. A practical guide to finding and exploiting service vulnerabilities...
The art of being a digital detective. From manual enumeration to Python automation for web security testing...
A comprehensive guide to identifying and exploiting Insecure Direct Object Reference vulnerabilities in modern web applications...
Have a project in mind or want to discuss security? Drop me a message!