Skip to content
View y-zahidi's full-sized avatar
💭
I may be slow to respond.
💭
I may be slow to respond.

Block or report y-zahidi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
y-zahidi/README.md

Yassir Zahidi

Security engineering student building systems that turn observed behavior into evidence, decisions, and stronger controls.

FIELD MANUAL / 01

Observe → Model → Validate → Harden

Animated identity shell: whoami, focus, stack, method, and availability

I build detection systems, forensic context, controlled validation, cyberdeception, data workflows, and practical software. My public repositories are case files: architecture, reasoning, sanitized evidence, and engineering decisions from private personal implementations.

Portfolio · LinkedIn · Experience · Email


What I build

I connect telemetry, controlled scenarios, forensic context, detection logic, triage, and hardening into a repeatable engineering loop. A control is unfinished until it produces useful evidence, supports a decision, and survives revalidation.

Validation loop: observe, model, validate, harden

Step Practical question
Observe What signal, behavior, or failure is actually visible?
Model What boundary, path, or data relationship explains it?
Validate Can the control be tested in an authorized, repeatable scenario?
Harden What changed after the evidence, and how will it be rechecked?

Selected case files

Cyberdeception · DFIR · CTI correlation · controlled validation

A unified platform design connecting decoy interaction, forensic collection, threat-intelligence context, and controlled validation. The public case file presents architecture, trust boundaries, sanitized configuration patterns, and engineering decisions behind a private implementation.

Wazuh · Suricata · Sysmon · MISP · MITRE ATT&CK

A telemetry and detection laboratory where controlled scenarios become evidence, evidence becomes context, and context informs triage and hardening.

CTF methodology · attack-path analysis · defensive takeaways

Owned labs, CTFs, and explicitly permitted environments are used to understand observability gaps, detection opportunities, and control trade-offs. Supporting reference notes are available in the pentest-cheatsheet.

Browse all public repositories →


Public evidence boundary

A showcase is not a source-code dump. Each public artifact is designed to be useful, honest, and technically reviewable without exposing operational material.

Public case-file evidence Kept private by design
Architecture and trust boundaries Complete implementation source
Sanitized configuration examples Credentials, keys, and private infrastructure
Validation scenarios and design notes Privileged deployment automation
Detection logic and engineering outcomes Sensitive tuning and private datasets
Redacted screenshots and lessons learned Confidential third-party material

Beyond security systems

The wider portfolio demonstrates product and data engineering through HTMLCamp, water-stress-morocco-analytics, FacturationPro-Enterprise, EduFlow, and the Rabat Cultural Website.

These projects cover full-stack architecture, identity and access, dashboards, ETL, business workflows, accessibility, Linux operations, and reporting interfaces.


Engineering principles

  1. Evidence before assertion.
  2. An authorized scenario is a test case for the control.
  3. Every alert needs context, a triage action, and a false-positive story.
  4. A control is not complete until it has been revalidated.
  5. Private implementation does not mean vague explanation.

Connect

I am based in Morocco and building toward security engineering opportunities focused on detection, forensics, controlled validation, hardening, and practical systems engineering.

Portfolio · LinkedIn · Email · GitHub

Pinned Loading

  1. pentest-cheatsheet pentest-cheatsheet Public

    Authorized testing notes — reconnaissance, enumeration, web, directory services, and post-exploitation.

    2

  2. ctf-writeups ctf-writeups Public

    Authorized CTF case studies — methodology, attack-path analysis, and defensive takeaways.

    1

  3. DECEPTR-UNIFIED DECEPTR-UNIFIED Public

    Architecture showcase for cyberdeception, DFIR, CTI correlation, and controlled validation.

    1

  4. home-lab-siem home-lab-siem Public

    Reproducible telemetry and detection lab using Wazuh, Suricata, Sysmon, and MISP.

    Shell 1