⚠ ACCESS LEVEL: PUBLIC · CLEARANCE: GRANTED · STATUS: ACTIVE ⚠
| FIELD | DETAIL |
|---|---|
| Codename | TYRION404 |
| Name | Youssef Mohamed |
| Designation | Junior Penetration Tester |
| Specialization | Web Application Security · API Security · Network Security |
| Education | B.Sc. Computer Science — EELU (GPA 3.00) |
| Status | 🟢 Active — accepting new targets |
| Motto | "Break it. Understand it. Report it. Repeat." |
Junior Penetration Tester specialized in exploiting web applications and APIs — SQL Injection, XSS, SSRF, IDOR, JWT attacks, business logic flaws, and authentication bypasses. Manual, methodical, and detail-obsessed: no noisy scanners, no guesswork. Every finding is chained, verified, and documented like it's going in front of a client.
| PERIOD | OPERATION | ROLE | OUTCOME |
|---|---|---|---|
| May 2025 – Nov 2025 | PureSoft | Cybersecurity / Penetration Testing Trainee | Hands-on web, network & API assessments — full-time, 5 months |
| Sep 2025 – Oct 2025 | WE Innovate | Cybersecurity Intern | Applied enterprise security fundamentals in real workflows |
| 2022 – 2026 | EELU | B.Sc. Computer Science | GPA 3.00 / 4.00 — Very Good |
| 🏆 STAT | 📊 VALUE |
|---|---|
| TryHackMe Rank | #1 in Egypt (extended period) |
| HackerOne Reports | 20+ valid, accepted |
| Platforms Active | HackerOne · TryHackMe · HTB Academy · PortSwigger Academy |
Testing methodology: Request Analysis · Recon & Fuzzing · JavaScript Deobfuscation · CSRF / CORS / XXE · Command Injection · File Upload / Inclusion · Broken Authentication · Privilege Escalation · CMS Attacks (WordPress, Joomla, Drupal, Tomcat, Jenkins) · Password Attacks (FTP, SMB, RDP, DNS, SMTP)
| TOOL | DESCRIPTION |
|---|---|
| 🗡️ Tyrion | Flagship offensive-security toolkit — recon, exploitation helpers, and automation built for real engagements. (update link/description to match the actual repo) |
| 🛡️ Arrow | Hacker-first attack surface & bug hunting framework — correlates recon data into prioritized, real vulnerabilities instead of noisy output |
| 🧠 DEXTER | Enterprise-grade, AI-powered web security testing platform — recon, vulnerability assessment, ML-based false-positive filtering, real-time dashboards |
| 🔍 xss-scanner | Python tool that scans web pages for reflected XSS via payload injection in URLs and HTML forms |

