Skip to content
View AliAlMansorisec's full-sized avatar

Block or report AliAlMansorisec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AliAlMansorisec/README.md

β–Έ About Me

Name        : Ali Al-Mansori
Handle      : AliAlMansoriSec
Role        : Application Security Engineer
Focus       : Web Applications β€’ APIs β€’ Mobile Apps
Methodology : OWASP WSTG Β· OWASP API Security Top 10 Β· OWASP MASTG
Experience  : Since 2023
Platform    : الفكر Ψ§Ω„Ψ³ΩŠΨ¨Ψ±Ψ§Ω†ΩŠ β€” Arabic Cybersecurity Education
Status      : Open to Remote Freelance & Collaboration

I find vulnerabilities before attackers do. My work is built on OWASP standards rather than guesswork β€” every engagement follows a documented methodology, every finding ships with a proof of concept, a severity rating, and a remediation path a dev team can actually act on.


β–Έ What I Deliver

🌐 Web Application Testing

Authentication, authorization, session management, injection, business logic β€” mapped against the OWASP Web Top 10 and tested per WSTG.

πŸ”Œ API Security Testing

BOLA, BFLA, mass assignment, excessive data exposure, and the rest of the OWASP API Security Top 10.

πŸ“± Mobile App Testing

Static & dynamic analysis, insecure storage, SSL pinning bypass, and OWASP MASTG-based methodology.

Every engagement ends with a professional report: evidence β†’ severity β†’ business impact β†’ remediation.


β–Έ Skills & Tools

β€” Exploitation & Testing β€”

β€” Recon & OSINT β€”

β€” Mobile Security β€”

β€” Automation & Scripting β€”


β–Έ Repository Structure

Cybersecurity-Portfolio
β”‚
β”œβ”€β”€ Web-Security
β”‚   β”œβ”€β”€ OWASP-Top-10
β”‚   β”œβ”€β”€ PortSwigger-Labs
β”‚   β”œβ”€β”€ Web-Methodology
β”‚   └── Web-Pentest-Reports
β”‚
β”œβ”€β”€ API-Security
β”‚   β”œβ”€β”€ OWASP-API-Top-10
β”‚   β”œβ”€β”€ API-Labs
β”‚   β”œβ”€β”€ API-Methodology
β”‚   └── API-Pentest-Reports
β”‚
β”œβ”€β”€ Mobile-Security
β”‚   β”œβ”€β”€ OWASP-Mobile-Top-10
β”‚   β”œβ”€β”€ Android-Labs
β”‚   β”œβ”€β”€ Mobile-Methodology
β”‚   └── Mobile-Pentest-Reports
β”‚
└── Pentest-Automation
    └── Scripts & Workflow Tools

β–Έ Projects

# Project Domain Description Status
01 🧭 Web Pentest Methodology Web Full professional workflow: Recon β†’ Enumeration β†’ Exploitation β†’ Reporting βœ… Active
02 βš™οΈ Pentest Automation Scripts Web Automation scripts for recon, project structure, and workflow ops βœ… Active
03 πŸ“– OWASP Web Top 10 β€” Deep Dive Web Per-vulnerability notes: definition, real examples, detection, exploitation, fix πŸ”„ In Progress
04 πŸ”Œ OWASP API Security Top 10 API Complete API security notes with labs: crAPI, DVWS, PortSwigger πŸ“… Planned
05 πŸ“± Android Pentesting Notes Mobile Methodology, tooling, and real APK analysis labs πŸ“… Planned
06 πŸ† CTF Writeups General Documented solutions from TryHackMe, HackTheBox, and competitions πŸ“… Planned
07 πŸ› Bug Bounty Findings Web/API Real-world vulnerability reports (HackerOne / Bugcrowd) πŸ“… Planned

β–Έ Knowledge Base (Self-Study Certifications)

A certificate is a piece of paper β€” this is the actual knowledge, documented and provable.

Certification Topics Covered Status
eJPT (eLearnSecurity) Network pentesting, web basics, enumeration πŸ“… Planned
OSWA (Offensive Security) Web app attacks, advanced exploitation πŸ“… Planned
PNPT (TCM Security) Full pentest cycle, reporting, OSINT πŸ“… Planned
CEH Security concepts, ethical hacking theory πŸ“… Planned

β–Έ Roadmap

2023 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ NOW
  β”‚
  β”œβ”€ βœ…  Web Pentesting Foundation
  β”œβ”€ βœ…  Built: Web Pentest Methodology (GitHub)
  β”œβ”€ βœ…  Launched: الفكر Ψ§Ω„Ψ³ΩŠΨ¨Ψ±Ψ§Ω†ΩŠ Platform
  β”œβ”€ βœ…  Tools Mastery: Burp, Nmap, SQLMap, FFUF, Nuclei
  β”œβ”€ βœ…  Positioned as Application Security Engineer (Web + API + Mobile)
  β”‚
  β”œβ”€ πŸ”„  OWASP Web Top 10 β€” Full Documentation
  β”œβ”€ πŸ“…  OWASP API Security Top 10 β€” Full Documentation
  β”œβ”€ πŸ“…  OWASP MASTG β€” Mobile Testing Notes & Labs
  β”œβ”€ πŸ“…  CTF Writeups (TryHackMe / HackTheBox)
  β”œβ”€ πŸ“…  Bug Bounty β€” First Public Finding (HackerOne / Bugcrowd)
  β”œβ”€ πŸ“…  Build Volunteer CTF Team (الفكر Ψ§Ω„Ψ³ΩŠΨ¨Ψ±Ψ§Ω†ΩŠ community)
  └─ πŸ“…  Remote Freelance Position β€” Application Security Engineer

β–Έ Platforms

🌐 Personal Portfolio

Application Security Engineer profile β€”
methodology, projects, and reports.

πŸ”— alialmansori.com

🧠 الفكر Ψ§Ω„Ψ³ΩŠΨ¨Ψ±Ψ§Ω†ΩŠ

Arabic cybersecurity education platform.
Tutorials, blog content, and security services.

πŸ”— cyber-thought.vercel.app/ar


β–Έ GitHub Stats


β–Έ Connect

Available for freelance security assessments, bug bounty collaborations, and security consultations.


Popular repositories Loading

  1. Web-Pentest-Methodology Web-Pentest-Methodology Public

    Professional web pentesting methodology based on OWASP standards. Structured workflow from reconnaissance to reporting. Enterprise-grade testing framework.

    Shell 1

  2. PortSwigger-Writeups PortSwigger-Writeups Public

    "PortSwigger lab write-ups with clear steps, analysis, and remediation. Sharing knowledge to help others learn"

  3. OWASP-Top-10-2025 OWASP-Top-10-2025 Public

    Complete OWASP Top 10 2025 reference. Structured methodology, deep vulnerability analysis, and PortSwigger lab solutions. Enterprise-grade security assessment skills aligned with industry standards.

  4. AliAlMansorisec AliAlMansorisec Public

  5. AliAlMansorisec.github.io AliAlMansorisec.github.io Public

    HTML

  6. ecommerce ecommerce Public