ABDALLA ABDELRHMAN

Offensive Security Consultant

Penetration Testing & Security Consulting Services
I help organizations identify and mitigate real-world security risks across their digital assets.

🔐 Request Free Initial Pentest

|

5+ Years Experience
OSWE | ISO 27001 LI | eWPTX | eMAPT | 5x HTB Prolabs Certified Certifications

System_Breach

Initializing profile...

root@0x2nac0nda:~
root@0x2nac0nda:~$ whoami
Cybersecurity Consultant specializing in offensive security, vulnerability assessment, and penetration testing (VAPT).
root@0x2nac0nda:~$ cat expertise.txt
Web Applications: OWASP Top 10, API Security, Thick Clients
Mobile Security: Android & iOS Pentesting
Infrastructure: AD Attacks, Internal/External Networks
Code Review: PHP, Java, Python, Node.js (Manual + Automated)
Cloud Pentesting: Fortify your cloud environments by uncovering misconfigurations and insecure practices.
AI / LLM Pentesting: Check your AI / LLM applications for exposures and emerging threat vectors.
Standards: NCA ECC, SAMA CSF, PTES, ISO 27001
root@0x2nac0nda:~$ cat mission.txt
Simulating real-world attacks to uncover vulnerabilities and delivering actionable technical reports. Committed to building the next generation of security professionals through training programs at universities across Sudan.
root@0x2nac0nda:~$ status
[ACTIVE] CTF Player @ Hack The Box | Bug Bounty Hunter | Writer on Medium | Security Researcher

Attack_Vectors

Specialized penetration testing services

🌐

Web & API Pentesting

Comprehensive assessment of web applications and APIs against OWASP Top 10 and business logic flaws. Specialized in authentication bypass, injection attacks, and privilege escalation.

OWASP REST GraphQL
📱

Mobile App Security

In-depth security testing for Android and iOS applications. Static and dynamic analysis, reverse engineering, and assessment of local storage, inter-process communication, and backend APIs.

Android iOS eMAPT
🏢

Active Directory Pentesting

Internal network penetration testing with focus on Active Directory environments. Enumeration, privilege escalation, lateral movement, and domain compromise simulations.

AD Attacks BloodHound C2
💻

Source Code Review

Manual and automated security assessment of application source code. Identifying vulnerabilities in PHP, Java, Python, and Node.js applications before deployment.

SAST Regex Secure SDLC
🖥️

Infrastructure Pentesting

Internal and external network penetration testing. Server hardening assessment, firewall rule analysis, and vulnerability exploitation on Windows and Linux environments.

Network Cloud Hardening
☁️

Cloud Pentesting

Fortify your cloud environments by uncovering misconfigurations and insecure practices. Assessments across AWS, Azure, and GCP for IAM weaknesses, exposed storage, and privilege escalation paths.

AWS Azure GCP
🤖

AI / LLM Pentesting

Check your AI / LLM applications for exposures and emerging threat vectors. Testing for prompt injection, data leakage, model manipulation, insecure plugin integrations, and OWASP LLM Top 10 risks.

LLM Prompt Injection OWASP AI

⬡ Industries Served

🛢️
Oil & Gas
🛡️
Defense
🏦
Banking & Finance
🏥
Healthcare & Insurance
✈️
Transportation
🎓
Education
Youth & Sports
🏛️
Government & Private Enterprises

Operation_History

Professional engagements timeline

AUG 2024 - PRESENT
Cyber Security Consultant
Confidential Careers | Riyadh, Saudi Arabia
  • Delivered end-to-end penetration testing across web applications, APIs, desktop applications, mobile applications (iOS & Android), network, WiFi, and Active Directory environments.
  • Conducted internal and external security assessments aligned with industry standards and best practices.
  • Performed white-box and black-box penetration testing across various environments.
  • Conducted source code reviews and vulnerability analysis to identify security weaknesses.
  • Provided security consulting services to software companies and development teams to support secure application design.
  • Authored detailed technical and executive reports outlining findings, risks, and remediation recommendations for stakeholders.
  • Conducting internal and external security assessments aligned with NCA and SAMA standards.
SEP 2023 - APR 2024
Security Consultant
OISSG Consultancy | Doha, Qatar
  • Delivered security assessments for government and financial entities.
  • Conducted internal and external security assessments for enterprise environments.
  • Tested web applications, APIs, and mobile applications (iOS & Android).
  • Delivered detailed technical reports with clear remediation recommendations to stakeholders.
JAN 2023 - OCT 2023
Cyber Security Engineer
Kilotech Security | Jeddah, Saudi Arabia
  • Executed vulnerability assessments and penetration testing for web applications and network infrastructure
  • Identified and mitigated security vulnerabilities across client environments.
MAR 2020 - MAR 2022
Penetration Tester
National Information Center | Khartoum, Sudan
  • Conducted penetration testing across web applications, APIs, networks infrastructure.
  • Performed both internal and external security testing engagements.
  • Executed OS and server hardening for Linux and Windows environments.
  • Discovered and documented vulnerabilities with detailed technical reporting.

Credentials

Certifications and specialized training

🏆
OSWE
Offensive Security
Certified - Advanced Web Exploitation
📱
eMAPT
eLearnSecurity
Certified - Mobile App Pentesting
🌐
eWPTx
eLearnSecurity
Certified - Web Pentesting Extreme
🔌
APIsec
APIsec University
Certified - API Pentesting
🔒
ISO 27001
Lead Implementer
Certified - Information Security
🌐
CNSS
Certified Network Security Specialist
Certified
🖥️
HTB Pro Labs
Hack The Box
Dante, Zephyr, Rastalabs, Offshore, Cybernetics

Research_&_Publications

Security guides, tools and technical writeups

Published: February 01, 2026

Source Code Review & Regex Guide

A comprehensive guide for security-focused source code reviews and regex-based vulnerability detection. Covers manual review techniques, automated tools integration, and pattern matching for identifying security flaws across multiple languages.

SAST Regex Code Review Guide
View Publication →
Published: April 10, 2024

Preparation for the OSWE/AWAE Exam

Technical preparation guide featuring three Python scripts targeting critical vulnerabilities: deserialization, file upload, and SSTI (Server-Side Template Injection). Designed to aid security professionals in preparing for the OSWE certification exam with practical exploit development techniques.

OSWE AWAE Python Exploit Dev
View Publication →
Published: November 19, 2025

APK Security Analyzer

Advanced command-line tool for comprehensive security analysis of Android APK files with detailed JSON reporting. Automates static analysis, permission analysis, and vulnerability detection for mobile applications.

Android Python Automation Tool
View Tool →

Establish_Connection

Ready to secure your digital assets? Let's talk.

📧 Email abdallaabdalrhman629@gmail.com 💼 LinkedIn /in/0x2nac0nda 🐦 Twitter @0x2nac0nda