Portfolio / Projects
Threat intelligence - DFIR - Offensive Security - AI Security

Selected projects

Case studies that show PFE readiness.

Each project is presented by context, method and evidence: cybersecurity objective, implementation, testing, documentation and limits.

Threat intelligence / PFA completed / July-August 2026

CyberVeille PME - suspicious URL detection MVP

Completed PFA project with CMRPI - Espace Maroc Cyberconfiance: an SME-oriented MVP for analyzing suspicious URLs without opening them.

  • Combined local URLHaus lookup, 21 URL features, scikit-learn Logistic Regression, risk levels, reasons and practical recommendations.
  • Implemented SQLite analysis history, CSV bulk analysis, configurable SMTP alerts, optional AbuseIPDB checks and SME reflex sheets.
  • Validated invalid inputs, URLHaus behavior, CSV processing, SQLite storage, disabled alerts and SMTP failure cases with automated tests.
Threat intelligencePhishing detectionStreamlitSME security

RAG / Secure backend / AI Security

Chatbot USMS academic assistant

Built a multilingual academic assistant for university FAQs, timetables and administrative information, using a RAG architecture and a full-stack application structure.

  • Designed a document-processing pipeline for PDF, JSON, TXT and Markdown sources with chunking and semantic retrieval.
  • Combined FastAPI, Next.js, PostgreSQL, Redis, Qdrant, Docker Compose and SSE streaming.
  • Added security-oriented controls such as JWT, RBAC, rate limiting, audit logs and privacy workflows.
INPUT Documents PDF / JSON / TXT / MD Chunking FastEmbed Embeddings PROCESSING Qdrant Vector Store Semantic search LLaMA 3.3-70B (Groq) Generation + SSE streaming FastAPI Backend PostgreSQL Redis OUTPUT Next.js Frontend Chat UI SSE Streaming SECURITY JWT Auth RBAC PII Masking Audit Logs Rate Limiting
FastAPIRAGPostgreSQLSecurity

Log investigation / Splunk

Intrusion reconstruction from security logs

Reconstructed a Volt Typhoon-style intrusion from Windows and application logs, then organized the result into a readable timeline with indicators and detection queries.

  • Mapped attacker behavior across account takeover, command execution, persistence, credential access and cleanup.
  • Used Splunk searches and event correlation to move from raw logs to an incident narrative.
  • Relevant to cyber reporting, signal triage and clear technical restitution.
SplunkIOCTimeline

Applied ML / Risk classification

Fault classification prototype from sensor data

Built a Python prototype that classifies pump fault risk from sensor values and presents the result through a simple desktop interface.

  • Prepared data with Pandas and trained a Random Forest classifier with Scikit-learn.
  • Translated model output into a readable risk level for the user.
  • Useful supporting evidence for cybersecurity contexts involving operational data, risk classification and explainable output.
PythonScikit-learnRisk

Offensive Security / Web and Linux labs

Controlled vulnerability testing and remediation

Worked on controlled labs that connect attack paths to evidence collection and remediation, instead of stopping at exploitation.

  • Tested SQL injection and XSS in DVWA, then connected the findings to safer input handling.
  • Documented a Linux compromise and DFIR lab with Kali attacker, Ubuntu target, SSH, UFW, auditd and Fail2ban.
  • Tracked evidence, IOCs, containment actions and remediation steps for a complete security narrative.
Offensive SecurityLinuxRemediation

Contact

Open to PFE 2027 discussions.

I can walk through these projects for cybersecurity, AI Security, SOC/DFIR, Offensive Security or secure software opportunities.