Threat intelligence - DFIR - Offensive Security - AI Security
Selected projects
Case studies that show PFE readiness . Each project is presented by context, method and evidence: cybersecurity objective, implementation, testing, documentation and limits.
Threat intelligence / PFA completed / July-August 2026
CyberVeille PME - suspicious URL detection MVP
Completed PFA project with CMRPI - Espace Maroc Cyberconfiance: an SME-oriented MVP for analyzing suspicious URLs without opening them.
Combined local URLHaus lookup, 21 URL features, scikit-learn Logistic Regression, risk levels, reasons and practical recommendations.
Implemented SQLite analysis history, CSV bulk analysis, configurable SMTP alerts, optional AbuseIPDB checks and SME reflex sheets.
Validated invalid inputs, URLHaus behavior, CSV processing, SQLite storage, disabled alerts and SMTP failure cases with automated tests.
Threat intelligence Phishing detection Streamlit SME security
RAG / Secure backend / AI Security
Chatbot USMS academic assistant
Built a multilingual academic assistant for university FAQs, timetables and administrative information, using a RAG architecture and a full-stack application structure.
Designed a document-processing pipeline for PDF, JSON, TXT and Markdown sources with chunking and semantic retrieval.
Combined FastAPI, Next.js, PostgreSQL, Redis, Qdrant, Docker Compose and SSE streaming.
Added security-oriented controls such as JWT, RBAC, rate limiting, audit logs and privacy workflows.
INPUT
Documents
PDF / JSON / TXT / MD
Chunking
FastEmbed
Embeddings
PROCESSING
Qdrant Vector Store
Semantic search
LLaMA 3.3-70B (Groq)
Generation + SSE streaming
FastAPI Backend
PostgreSQL
Redis
OUTPUT
Next.js Frontend
Chat UI
SSE Streaming
SECURITY
JWT Auth
RBAC
PII Masking
Audit Logs
Rate Limiting
FastAPI RAG PostgreSQL Security
Log investigation / Splunk
Intrusion reconstruction from security logs
Reconstructed a Volt Typhoon-style intrusion from Windows and application logs, then organized the result into a readable timeline with indicators and detection queries.
Mapped attacker behavior across account takeover, command execution, persistence, credential access and cleanup.
Used Splunk searches and event correlation to move from raw logs to an incident narrative.
Relevant to cyber reporting, signal triage and clear technical restitution.
Splunk IOC Timeline
Applied ML / Risk classification
Fault classification prototype from sensor data
Built a Python prototype that classifies pump fault risk from sensor values and presents the result through a simple desktop interface.
Prepared data with Pandas and trained a Random Forest classifier with Scikit-learn.
Translated model output into a readable risk level for the user.
Useful supporting evidence for cybersecurity contexts involving operational data, risk classification and explainable output.
Python Scikit-learn Risk
Offensive Security / Web and Linux labs
Controlled vulnerability testing and remediation
Worked on controlled labs that connect attack paths to evidence collection and remediation, instead of stopping at exploitation.
Tested SQL injection and XSS in DVWA, then connected the findings to safer input handling.
Documented a Linux compromise and DFIR lab with Kali attacker, Ubuntu target, SSH, UFW, auditd and Fail2ban.
Tracked evidence, IOCs, containment actions and remediation steps for a complete security narrative.
Offensive Security Linux Remediation