HosamAlassaf

Hosam Alassaf avatar
I MAP ATTACK SURFACES, EXPLOIT THE GAP, PROVE THE IMPACT —
[ OFFENSIVE MINDSET ]

Security becomes real when a finding survives contact with the system.

I’m Hosam, a cybersecurity graduate from Hashemite University with hands-on experience in penetration testing, threat intelligence, digital forensics, and security tool development across both offensive and defensive domains.

Backed by 200+ hours of specialized training through Jordan's National Cybersecurity Center and the Path2Cyber Offensive Security program, I deliver complex, research-driven projects with measurable technical outcomes.

[ 01 / OFFENSIVE PROJECTS ]

FieldWork

Frameworks, engagements, and research built around one principle: demonstrate the risk, preserve the evidence, improve the defense.

MS://ASSESS

1. static > surface

2. bypass > unpin

3. mastg > execute

4. evidence > dedup

STATICDEVICEDYNAMICREPORT
assessment_id: MS-2048
target: android.apk
confidence: 0.95
pipeline: armed_
/01Android Pentest Automation / v1.0 Architecture

MobileStrike

An advanced hybrid Android security assessment framework that correlates static APK analysis, adaptive Frida instrumentation, and network proxy captures into reproducible, evidence-backed findings. Features structural version regression, deterministic MASTG test scoring, and a plugin-ready architecture.

Phase 1 (Core Engine) Build In Progress
Python 3.11FridaSQLitemitmproxyOWASP MASVS
ROOT
$ nmap -sV target.local
PORT    STATE  SERVICE
8080   open   tomcat
3389   open   ms-wbt-server
[+] session opened as SYSTEM_
AUTHORIZED
TESTING
/02Adversary Simulation / Completed

Operation Redline

A 42-hour penetration-test engagement against a custom financial-sector lab—moving from Tomcat initial access to NT AUTHORITY\SYSTEM, persistence, detection engineering, and a 60+ page PTES report.

Full engagement completed
CVE ResearchKali LinuxWindowsSIGMA
/03Threat Intelligence / Full Stack

SafeVision

A responsive threat-intelligence platform combining PE static analysis, YARA-powered malware classification, heuristic URL scanning, and steganography forensics in one analyst-focused workflow.

Four analysis modules completed
PythonFlaskReactYARAPE Analysis
/04Adversary Simulation / v2.0.0-RELEASE

Chimera

An advanced adversary simulation, in-memory endpoint evasion, and multi-platform command & control framework. Features assembly-level polymorphism, native kernel section mappings, Ekko sleep masking, BYOVD, and zero-width steganography.

62 / 62 Verified Subsystems
PolymorphismIndirect SyscallsEkko ROPBYOVDeBPF
[ 02 / APPROACH ]

FROM SIGNALTO SYSTEM.

01

Map

Enumerate the attack surface, trust boundaries, identities, exposed services, and likely paths.

02

Exploit

Validate real impact with controlled techniques and the minimum force required.

03

Escalate

Follow privileges, credentials, and weak boundaries to the highest defensible impact.

04

Evidence

Capture the chain clearly enough that another tester can reproduce every result.

05

Strengthen

Translate exploitation into detection ideas and remediation ordered by practical risk.

[ 03 / CREDENTIALS ]

TRAINEDFOR THEREAL WORLD.

CompTIASecurity+

Certified foundation across threats, architecture, operations, and governance.

INE SecurityeCPPT & eJPTv2

Certified Professional and Junior Penetration Tester credentials.

Red TeamCRTA

Practical adversary simulation and Active Directory attack skills.

Cyber Warriors CTF34th

Ranked among 224+ teams.

[ 04 / START A CONVERSATION ]

Need an offensive-security perspective on a system, product, or opportunity?

Let'sTalk