0xmvmd
Mohamed Ibrahim Yehia
|
· HTB Top 3%
· G4mra CTF Team
· Pyramids Hier Institute
Write-ups
About Me
0xmvmd — Moahmed Ibrahim Yehia
Offensive Security · Red Team Ops · Bug Hunter · HTB Top 3% · G4mra Team · Penetration Tester · Faculty of Engineering - Major : Electronics & Communication
Skills
Certifications
- Network Security (NTI) Dec 2024
- SANS Institute — AI Cybersecurity Summit 2026 · 8.0 CPE Credits Apr 2026
- NVIDIA DLI — Building RAG Agents with LLMs Feb 2026
- Helwan Hackathon — University CTF 2024 (Rank 3 / 1,014 · 34/34 solved) 2024
- solving Port Swigger LAbs (Score: 56%)
Currently Preparing For
Contact Me
- mohamed01554973816@gmail.com
- Discord
CTF Stats
Achievements
- Hack The Box University CTF 2025 — Ranked 20th globally out of 1,014 teams (Solved 34/34 challenges, 15,475 points)
- picoCTF 2026 — Ranked 21st in the Africa Region (Representing CATReloaded team)
- HTB Global Ranking — Ranked in the Top 1.92%
- Bug Bounty Research — Discovered high-severity vulnerabilities (OIDC issuer mismatch, over-permissive CSP, and webhooks fail-open) in real-world platforms (Signicat, Ory Network)
- PortSwigger Web Security Academy — Solved 80+ labs covering advanced web injection, auth bypasses, and access control
- Active Directory & Windows Labs — Engineered full-chain exploitation paths (BloodHound pathfinding, Kerberoasting, Pass-the-Hash) and pwned multiple HTB machines
- AI & LLM Security Research — Conducted adversarial threat modeling of prompt injections, model abuse, and safety bypasses
- CATReloaded & G4mra CTF Teams — Active member representing in regional and global hacking competitions (KashiCTF, picoCTF)
Arsenal
Python classes for working with network protocols (psexec, wmiexec, secretsdump).
GITHUB ↗Python-based ingestor for BloodHound (runs from Linux without domain-join).
GITHUB ↗Quickly bruteforce and enumerate Active Directory users via Kerberos pre-authentication.
GITHUB ↗Active Directory security auditing tool to evaluate risk and path escalation.
WEBSITE ↗CVE-2021-42278 / CVE-2021-42287 Active Directory domain controller takeover exploit.
GITHUB ↗Active Directory information dumper via LDAP queries into HTML/JSON reports.
GITHUB ↗Extract plain text passwords, NT/LM hashes, and Kerberos tickets from LSASS memory.
GITHUB ↗Windows local privilege escalation tool exploiting Print Spooler service.
GITHUB ↗