A breakdown of my hands-on work across offensive security (Red Team) and security operations / digital forensics (Blue Team). Full client engagement details are kept confidential — the writeups section covers independent research, personal projects, and lab work.

Red Team / Offensive Security


Red Team Feb 2025 – Present
Penetration Testing — Vantage Point Security

30+ security assessments delivered across web applications, mobile apps, APIs, and thick clients for clients including major banks.

  • Identified critical vulnerabilities including IDORs, SSRF, CSRF, and authentication bypasses
  • Mobile security testing — bypassed RASP and SSL pinning (Frida) on iOS/Android banking apps
  • Built a custom Burp Suite extension to decrypt 3DES/AES-GCM encrypted banking traffic
  • Built a custom JOSE fuzzing framework for a payment gateway engagement

Client-specific findings are confidential.

Responsible Disclosure Ongoing
Independent Vulnerability Research

Independent security research outside of client engagements, reported through responsible disclosure.

  • Discovered a systemic IDOR affecting all major resource controllers in an open-source CRM platform — details withheld until resolved
  • Active bug bounty researcher on Intigriti (handle: ibrahimisramos)

Blue Team / DFIR & Security Operations


Blue Team University Project
Malware Analysis — Static & Dynamic

Analysed a live malware sample in an isolated lab environment.

  • Static: PEView, PEiD, VirusTotal — file structure, packing, known signatures
  • Dynamic: Process Hacker, Process Explorer, Regshot, ApateDNS — runtime behaviour, registry changes, DNS activity
View Report
Blue Team University Project
Digital Forensics — Disk, Memory & Browser Artifacts

Full forensic investigation across disk images, memory captures, and browser artifacts.

  • Disk & file system: Autopsy (4.21.0), The Sleuth Kit (4.12.1)
  • Memory: Volatility Framework (2.7.0)
  • Browser: ChromeHistoryViewer (1.53), MZHistoryView (1.70)
  • Hidden data: TrueCrypt (7.1a), Image Steganography (1.5.2)
Blue Team In Progress
FlareVM Malware Analysis Lab

Building a dedicated FlareVM lab environment for malware analysis and reverse engineering. Tools in use:

  • IDA Pro — static binary analysis and disassembly
  • OllyDbg — dynamic x86 debugging
  • Ghidra — open-source reverse engineering framework (planned focus next)
Blue Team Ongoing
Blue Team Labs Online (BTLO)

25+ completed investigations across DFIR, Security Operations, Threat Intel, and Reverse Engineering. Practical SIEM experience with Splunk via BTL1.

View BTLO Profile
Cloud Security In Progress
Cloud Security — Pwned Labs (ACRTP)

Working through the Amazon Cloud Red Team Professional path — IAM enumeration, EBS snapshot exploitation, CloudTrail analysis, and AWS attack/defence scenarios.