Name : Ali Al-Mansori
Handle : AliAlMansoriSec
Role : Application Security Engineer
Focus : Web Applications β’ APIs β’ Mobile Apps
Methodology : OWASP WSTG Β· OWASP API Security Top 10 Β· OWASP MASTG
Experience : Since 2023
Platform : Ψ§ΩΩΩΨ± Ψ§ΩΨ³ΩΨ¨Ψ±Ψ§ΩΩ β Arabic Cybersecurity Education
Status : Open to Remote Freelance & CollaborationI find vulnerabilities before attackers do. My work is built on OWASP standards rather than guesswork β every engagement follows a documented methodology, every finding ships with a proof of concept, a severity rating, and a remediation path a dev team can actually act on.
|
π Web Application Testing Authentication, authorization, session management, injection, business logic β mapped against the OWASP Web Top 10 and tested per WSTG. |
π API Security Testing BOLA, BFLA, mass assignment, excessive data exposure, and the rest of the OWASP API Security Top 10. |
π± Mobile App Testing Static & dynamic analysis, insecure storage, SSL pinning bypass, and OWASP MASTG-based methodology. |
Every engagement ends with a professional report: evidence β severity β business impact β remediation.
β Exploitation & Testing β
β Recon & OSINT β
β Mobile Security β
β Automation & Scripting β
Cybersecurity-Portfolio
β
βββ Web-Security
β βββ OWASP-Top-10
β βββ PortSwigger-Labs
β βββ Web-Methodology
β βββ Web-Pentest-Reports
β
βββ API-Security
β βββ OWASP-API-Top-10
β βββ API-Labs
β βββ API-Methodology
β βββ API-Pentest-Reports
β
βββ Mobile-Security
β βββ OWASP-Mobile-Top-10
β βββ Android-Labs
β βββ Mobile-Methodology
β βββ Mobile-Pentest-Reports
β
βββ Pentest-Automation
βββ Scripts & Workflow Tools
| # | Project | Domain | Description | Status |
|---|---|---|---|---|
| 01 | π§ Web Pentest Methodology | Web | Full professional workflow: Recon β Enumeration β Exploitation β Reporting | β Active |
| 02 | βοΈ Pentest Automation Scripts | Web | Automation scripts for recon, project structure, and workflow ops | β Active |
| 03 | π OWASP Web Top 10 β Deep Dive | Web | Per-vulnerability notes: definition, real examples, detection, exploitation, fix | π In Progress |
| 04 | π OWASP API Security Top 10 | API | Complete API security notes with labs: crAPI, DVWS, PortSwigger | π Planned |
| 05 | π± Android Pentesting Notes | Mobile | Methodology, tooling, and real APK analysis labs | π Planned |
| 06 | π CTF Writeups | General | Documented solutions from TryHackMe, HackTheBox, and competitions | π Planned |
| 07 | π Bug Bounty Findings | Web/API | Real-world vulnerability reports (HackerOne / Bugcrowd) | π Planned |
A certificate is a piece of paper β this is the actual knowledge, documented and provable.
| Certification | Topics Covered | Status |
|---|---|---|
| eJPT (eLearnSecurity) | Network pentesting, web basics, enumeration | π Planned |
| OSWA (Offensive Security) | Web app attacks, advanced exploitation | π Planned |
| PNPT (TCM Security) | Full pentest cycle, reporting, OSINT | π Planned |
| CEH | Security concepts, ethical hacking theory | π Planned |
2023 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ NOW
β
ββ β
Web Pentesting Foundation
ββ β
Built: Web Pentest Methodology (GitHub)
ββ β
Launched: Ψ§ΩΩΩΨ± Ψ§ΩΨ³ΩΨ¨Ψ±Ψ§ΩΩ Platform
ββ β
Tools Mastery: Burp, Nmap, SQLMap, FFUF, Nuclei
ββ β
Positioned as Application Security Engineer (Web + API + Mobile)
β
ββ π OWASP Web Top 10 β Full Documentation
ββ π
OWASP API Security Top 10 β Full Documentation
ββ π
OWASP MASTG β Mobile Testing Notes & Labs
ββ π
CTF Writeups (TryHackMe / HackTheBox)
ββ π
Bug Bounty β First Public Finding (HackerOne / Bugcrowd)
ββ π
Build Volunteer CTF Team (Ψ§ΩΩΩΨ± Ψ§ΩΨ³ΩΨ¨Ψ±Ψ§ΩΩ community)
ββ π
Remote Freelance Position β Application Security Engineer
|
π Personal Portfolio π alialmansori.com |
π§ Ψ§ΩΩΩΨ± Ψ§ΩΨ³ΩΨ¨Ψ±Ψ§ΩΩ |
Available for freelance security assessments, bug bounty collaborations, and security consultations.