Skip to content
View Mustafa1p's full-sized avatar
:copilot:
Expert Member
:copilot:
Expert Member
  • IRAQ - Baghdad

Block or report Mustafa1p

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
Mustafa1p/README.md

Typing SVG


whoami

$ whoami
mustafa-ali

$ cat /etc/profile.d/identity.sh
name: Mustafa Ali
role:
  - CTO @ AL-Jedar Group
  - Co-Founder @ EMLAK
  - CTO @ Al-Shuaa Security Services
certifications: [OSCP+, OSEE, OSWE, CEH v12, CAIP, CAPIE]
platforms: [HackerOne, Bugcrowd]
background: [Apple, Meta, Control Risks, Coop]
focus:
  - Offensive Security & Red Teaming
  - Enterprise Software Architecture
  - AI-Driven Security Solutions
  - ATM & API Security Assessments
location: Baghdad, Iraq ๐Ÿ‡ฎ๐Ÿ‡ถ

๐ŸŽฏ The Rare Stack

Most security leaders think like defenders. I spent years thinking like an attacker โ€” then built systems that stop them.

I hold three of OffSec's most demanding certifications simultaneously โ€” OSCP+, OSEE, and OSWE โ€” a combination held by fewer than a few hundred professionals globally. Before moving into the C-suite, I protected diplomatic missions at the Spanish & German Embassies under Control Risks, contributed to Deep Learning research at Meta, and shipped software at Apple.

Today I build companies and break systems โ€” both on purpose.


๐Ÿ”ด Offensive Security

Domain Expertise
๐ŸŒ Web Application Pentesting OSWE-certified โ€” source code review, auth bypass, RCE chains
๐Ÿ’ป Windows Exploitation OSEE-certified โ€” kernel exploits, advanced shellcoding, DEP/ASLR bypass
๐Ÿ”‘ Network Pentesting OSCP+-certified โ€” full kill-chain engagements
๐Ÿ’ณ ATM Security Physical & logical ATM penetration testing
๐Ÿ”Œ API Security CAPIE-certified โ€” REST/GraphQL attack surfaces
๐Ÿ› Bug Bounty HackerOne & Bugcrowd โ€” 6+ years, critical CVEs

๐Ÿ—๏ธ What I Build

Project Stack Role
EMLAK โ€” Property Management Platform Laravel 11 ยท Filament v3 ยท MariaDB ยท Redis Co-Founder & Architect
AL-Jedar ERP โ€” HR ยท Attendance ยท Payroll Laravel ยท PWA ยท Push Notifications CTO
Sec2Tech โ€” Cybersecurity Education Custom LMS Founder
Al-Shuaa Security Tech โ€” Guard Management Laravel ยท Real-time Systems CTO

๐Ÿ› ๏ธ Tech Stack

Languages & Frameworks

PHP Laravel Python JavaScript

Infrastructure & Security

Windows Server Cloudflare CrowdSec Wazuh Caddy

Database & Caching

MariaDB Redis

AI & Dev Tools

GitHub Copilot VS Code TensorFlow


๐Ÿ… Certifications โ€” The Full Arsenal

๐Ÿ”ด Offensive Security (OffSec) โ€” Click to expand
Cert Issuer Year
OSCP+ โ€” Offensive Security Certified Professional Plus OffSec 2025
OSEE โ€” Offensive Security Exploitation Expert OffSec 2021
OSWE โ€” Offensive Security Web Expert OffSec 2020
OSCP โ€” Offensive Security Certified Professional OffSec 2019
๐Ÿ›ก๏ธ Security & Ethical Hacking
Cert Issuer Year
CEH v12 โ€” Certified Ethical Hacker EC-Council 2023
CAPIE โ€” Certified API Hacking Expert Udemy 2026
ATM Penetration Testing & Security Assessment Red Team Leaders 2026
Red Teaming Certificate TryHackMe 2026
CCEP โ€” Certified Cybersecurity Educator Professional Red Team Leaders 2025
๐Ÿค– AI & Engineering
Cert Issuer Year
CAIP โ€” Certified Artificial Intelligence Professional GST Inc. 2020
AI+ Prompt Engineer Level 1โ„ข AI CERTsยฎ 2025
Google Cloud Professional API Engineer Google 2019
PCPP2 โ€” Certified Professional in Python Programming OpenEDG 2017
Microsoft Certified: Python Developer Microsoft 2016
Full-Stack Web Developer CareerFoundry 2018

๐Ÿ“Š GitHub Stats

GitHub Streak


๐Ÿ Contribution Graph

Snake animation

๐Ÿค Connect

LinkedIn HackerOne Bugcrowd


"The most effective security leaders think like attackers. I've spent years proving that in the field."

Profile Views

Popular repositories Loading

  1. DDOS-Telegram-BOT DDOS-Telegram-BOT Public

    ddos attack using telegram bot via API Token and User ID

    Python 39 77

  2. Anti-Youtube-Ads-Extension- Anti-Youtube-Ads-Extension- Public

    A powerful browser extension that blocks YouTube ads at the network level and removes ad UI elements for an uninterrupted viewing experience.

    JavaScript 5 1

  3. SUPER_IPBOT SUPER_IPBOT Public

    Just plugins

    Lua 2 3

  4. hassan-iphone6-meid-call- hassan-iphone6-meid-call- Public

    2

  5. libtelegrambot libtelegrambot Public

    C 1

  6. tg tg Public

    Forked from vysheng/tg

    telegram-cli

    C 1 1