Red Team / Offensive Security
Penetration Testing — Vantage Point Security
30+ security assessments delivered across web applications, mobile apps, APIs, and thick clients for clients including major banks.
- Identified critical vulnerabilities including IDORs, SSRF, CSRF, and authentication bypasses
- Mobile security testing — bypassed RASP and SSL pinning (Frida) on iOS/Android banking apps
- Built a custom Burp Suite extension to decrypt 3DES/AES-GCM encrypted banking traffic
- Built a custom JOSE fuzzing framework for a payment gateway engagement
Client-specific findings are confidential.
Independent Vulnerability Research
Independent security research outside of client engagements, reported through responsible disclosure.
- Discovered a systemic IDOR affecting all major resource controllers in an open-source CRM platform — details withheld until resolved
- Active bug bounty researcher on Intigriti (handle: ibrahimisramos)
Blue Team / DFIR & Security Operations
Malware Analysis — Static & Dynamic
Analysed a live malware sample in an isolated lab environment.
- Static: PEView, PEiD, VirusTotal — file structure, packing, known signatures
- Dynamic: Process Hacker, Process Explorer, Regshot, ApateDNS — runtime behaviour, registry changes, DNS activity
Digital Forensics — Disk, Memory & Browser Artifacts
Full forensic investigation across disk images, memory captures, and browser artifacts.
- Disk & file system: Autopsy (4.21.0), The Sleuth Kit (4.12.1)
- Memory: Volatility Framework (2.7.0)
- Browser: ChromeHistoryViewer (1.53), MZHistoryView (1.70)
- Hidden data: TrueCrypt (7.1a), Image Steganography (1.5.2)
FlareVM Malware Analysis Lab
Building a dedicated FlareVM lab environment for malware analysis and reverse engineering. Tools in use:
- IDA Pro — static binary analysis and disassembly
- OllyDbg — dynamic x86 debugging
- Ghidra — open-source reverse engineering framework (planned focus next)
Blue Team Labs Online (BTLO)
25+ completed investigations across DFIR, Security Operations, Threat Intel, and Reverse Engineering. Practical SIEM experience with Splunk via BTL1.
View BTLO ProfileCloud Security — Pwned Labs (ACRTP)
Working through the Amazon Cloud Red Team Professional path — IAM enumeration, EBS snapshot exploitation, CloudTrail analysis, and AWS attack/defence scenarios.