Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
View 0xyoussef404's full-sized avatar

Highlights

  • Pro

Block or report 0xyoussef404

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xyoussef404/README.md
Typing SVG

⚠ ACCESS LEVEL: PUBLIC  ·  CLEARANCE: GRANTED  ·  STATUS: ACTIVE ⚠

📁 OPERATIVE FILE

FIELD DETAIL
Codename TYRION404
Name Youssef Mohamed
Designation Junior Penetration Tester
Specialization Web Application Security · API Security · Network Security
Education B.Sc. Computer Science — EELU (GPA 3.00)
Status 🟢 Active — accepting new targets
Motto "Break it. Understand it. Report it. Repeat."

LinkedIn HackerOne TryHackMe Gmail Views

🎯 CASE SUMMARY

Junior Penetration Tester specialized in exploiting web applications and APIs — SQL Injection, XSS, SSRF, IDOR, JWT attacks, business logic flaws, and authentication bypasses. Manual, methodical, and detail-obsessed: no noisy scanners, no guesswork. Every finding is chained, verified, and documented like it's going in front of a client.

🕓 MISSION LOG

PERIOD OPERATION ROLE OUTCOME
May 2025 – Nov 2025 PureSoft Cybersecurity / Penetration Testing Trainee Hands-on web, network & API assessments — full-time, 5 months
Sep 2025 – Oct 2025 WE Innovate Cybersecurity Intern Applied enterprise security fundamentals in real workflows
2022 – 2026 EELU B.Sc. Computer Science GPA 3.00 / 4.00 — Very Good

🧪 FIELD REPORTS

Typing SVG
🏆 STAT 📊 VALUE
TryHackMe Rank #1 in Egypt (extended period)
HackerOne Reports 20+ valid, accepted
Platforms Active HackerOne · TryHackMe · HTB Academy · PortSwigger Academy

🧰 ARSENAL

Burp Suite OWASP SQLi XSS SSRF IDOR JWT GraphQL Nmap Metasploit Wireshark Linux Python Java CCNA

Testing methodology: Request Analysis · Recon & Fuzzing · JavaScript Deobfuscation · CSRF / CORS / XXE · Command Injection · File Upload / Inclusion · Broken Authentication · Privilege Escalation · CMS Attacks (WordPress, Joomla, Drupal, Tomcat, Jenkins) · Password Attacks (FTP, SMB, RDP, DNS, SMTP)

📡 ACTIVE OPERATIONS — CERTIFICATION TRACK

Typing SVG

🛠️ DEPLOYED TOOLS

TOOL DESCRIPTION
🗡️ Tyrion Flagship offensive-security toolkit — recon, exploitation helpers, and automation built for real engagements. (update link/description to match the actual repo)
🛡️ Arrow Hacker-first attack surface & bug hunting framework — correlates recon data into prioritized, real vulnerabilities instead of noisy output
🧠 DEXTER Enterprise-grade, AI-powered web security testing platform — recon, vulnerability assessment, ML-based false-positive filtering, real-time dashboards
🔍 xss-scanner Python tool that scans web pages for reflected XSS via payload injection in URLs and HTML forms
Typing SVG

"Hack like a beast. Think like a threat hunter. Document like a leader."

Pinned Loading

  1. InventoryManagementSystem InventoryManagementSystem Public

    Java

  2. quotes-scraper quotes-scraper Public

    A Python tool that scrapes quotes, authors, and tags from quotes.toscrape.com and saves the data in CSV, JSON, and Excel formats. It handles pagination and errors like timeouts and 404s.

    Python

  3. xss-scanner xss-scanner Public

    🔍 A Python tool to scan web pages for reflected XSS vulnerabilities using payload injection in URLs and HTML forms.

    Python

Morty Proxy This is a proxified and sanitized view of the page, visit original site.