root@falcon0x1:~# ./init_portfolio.sh
AVAILABLE FOR HIRE

SECURITY ENGINEER

Hello, I'm Mahmoud Elshorbagy (falcon0x1).

RANK: Security Engineer
TARGET: Web, Mobile, API
MISSION: Penetration Testing
falcon0x1
4+
Certifications
50+
Labs Pwned
2
Tools Built
100%
Commitment

# Interactive Terminal // Try typing "help"

falcon0x1@portfolio:~$
Welcome to falcon0x1 Portfolio Terminal v1.0
Type 'help' for available commands
─────────────────────────────────────────
falcon0x1@portfolio:~$

Pro Tip: Try commands like whoami, skills, or contact

# Technical Arsenal

"Every tool is a weapon when you know how to wield it."

>> CERTIFICATIONS

eWPT

eWPT

Web Application Penetration Tester

INE Security
eWPT

eWPT Certified

INE Security

Verify Certificate
CyberTalents

Certified Web Pentester

CyberTalents / ITI

ITI
CyberTalents

Certified Web Pentester

CyberTalents / ITI

Verify Certificate
CyberTalents

Certified Mobile Pentester

CyberTalents / ITI

ITI
CyberTalents

Certified Mobile Pentester

CyberTalents / ITI

Verify Certificate
APIsec

API Penetration Testing

APIsec University

APIsec

API Security Certified

APIsec University

Verify Certificate

SKILLS & TOOLS

90%

Web Pentesting

OWASP Top 10, SQL Injection, XSS

80%

Mobile Pentesting

Android Security, Frida, MobSF

75%

Network Security

Nmap, Wireshark, TCP/IP

95%

Scripting

Bash, Python, Automation

85%

Active Directory

Kerberos, LDAP, BloodHound

65%

Reverse Engineering

Binary Analysis, Debugging

# Projects

"Building tools that break systems, to make them stronger."

# Professional Experience

"Think like an attacker, defend like a guardian."

Trainee — Offensive Security & Penetration Testing Track

Jul 2025 – Nov 2025

Information Technology Institute (ITI), Nasr City, Cairo

  • Conducted comprehensive Black-Box and Grey-Box penetration testing on 15+ lab targets mimicking real-world banking and e-commerce applications
  • Performed manual and automated penetration testing against OWASP Top 10 vulnerabilities
  • Conducted web, API, and Active Directory attacks in controlled lab environments
  • Applied industry-standard methodologies such as PTES and OSSTMM during security assessments
  • Gained hands-on experience with Bash scripting and Red Hat Linux administration
Web Security API Testing Active Directory OWASP

Bachelor of Systems & Computer Engineering

Sep 2019 – Jul 2024

Faculty of Engineering, Al-Azhar University — Cairo, Egypt

  • Cumulative Grade: Very Good
  • Graduation Project: IoT/ICS Automation System — Security & Development (Smart Poultry Farm Automation) — Grade: Excellent
  • Designed a localized IoT-based control system integrating sensors, controllers, and a mobile interface
  • Implemented remote access and API-based communication between embedded hardware and mobile application
  • Addressed security considerations related to unauthorized control, API exposure, and system integrity
IoT Security Embedded Systems API Development Mobile App

# Latest Writeups

Android Security Jan 2026

Android Security: The Falcon's Guide to Permissions & Attack Surfaces

Understanding the Android attack surface when auditing applications. A comprehensive guide to permissions, components, and security testing...

Mobile Security Jan 2026

Hacking Android Services: The Lazy Pentester's Guide

Beyond Activities: exploiting Android Services with automation scripts. A practical guide to finding and exploiting service vulnerabilities...

Web Security Jan 2026

Web Enumeration & Brute Force: From Manual to Python

The art of being a digital detective. From manual enumeration to Python automation for web security testing...

IDOR 2024

Exploiting IDOR Vulnerabilities: A Deep Dive

A comprehensive guide to identifying and exploiting Insecure Direct Object Reference vulnerabilities in modern web applications...

# GitHub Activity

falcon0x1

View Profile →
15+
Repositories
120+
Contributions
50+
Stars
10+
Forks
GitHub Contributions

Initialize Connection

Have a project in mind or want to discuss security? Drop me a message!