Security engineering student building systems that turn observed behavior into evidence, decisions, and stronger controls.
FIELD MANUAL / 01
Observe → Model → Validate → Harden
I build detection systems, forensic context, controlled validation, cyberdeception, data workflows, and practical software. My public repositories are case files: architecture, reasoning, sanitized evidence, and engineering decisions from private personal implementations.
Portfolio · LinkedIn · Experience · Email
I connect telemetry, controlled scenarios, forensic context, detection logic, triage, and hardening into a repeatable engineering loop. A control is unfinished until it produces useful evidence, supports a decision, and survives revalidation.
| Step | Practical question |
|---|---|
| Observe | What signal, behavior, or failure is actually visible? |
| Model | What boundary, path, or data relationship explains it? |
| Validate | Can the control be tested in an authorized, repeatable scenario? |
| Harden | What changed after the evidence, and how will it be rechecked? |
01 / DECEPTR-UNIFIED
Cyberdeception · DFIR · CTI correlation · controlled validation
A unified platform design connecting decoy interaction, forensic collection, threat-intelligence context, and controlled validation. The public case file presents architecture, trust boundaries, sanitized configuration patterns, and engineering decisions behind a private implementation.
02 / home-lab-siem
Wazuh · Suricata · Sysmon · MISP · MITRE ATT&CK
A telemetry and detection laboratory where controlled scenarios become evidence, evidence becomes context, and context informs triage and hardening.
CTF methodology · attack-path analysis · defensive takeaways
Owned labs, CTFs, and explicitly permitted environments are used to understand observability gaps, detection opportunities, and control trade-offs. Supporting reference notes are available in the pentest-cheatsheet.
Browse all public repositories →
A showcase is not a source-code dump. Each public artifact is designed to be useful, honest, and technically reviewable without exposing operational material.
| Public case-file evidence | Kept private by design |
|---|---|
| Architecture and trust boundaries | Complete implementation source |
| Sanitized configuration examples | Credentials, keys, and private infrastructure |
| Validation scenarios and design notes | Privileged deployment automation |
| Detection logic and engineering outcomes | Sensitive tuning and private datasets |
| Redacted screenshots and lessons learned | Confidential third-party material |
The wider portfolio demonstrates product and data engineering through HTMLCamp, water-stress-morocco-analytics, FacturationPro-Enterprise, EduFlow, and the Rabat Cultural Website.
These projects cover full-stack architecture, identity and access, dashboards, ETL, business workflows, accessibility, Linux operations, and reporting interfaces.
- Evidence before assertion.
- An authorized scenario is a test case for the control.
- Every alert needs context, a triage action, and a false-positive story.
- A control is not complete until it has been revalidated.
- Private implementation does not mean vague explanation.
I am based in Morocco and building toward security engineering opportunities focused on detection, forensics, controlled validation, hardening, and practical systems engineering.




