Master's Student in Artificial Intelligence & Emerging Technologies
Portfolio β’ LinkedIn β’ HackerOne β’ Hack The Box
I'm Mohamed Zahir, a Master's student in Artificial Intelligence and Emerging Technologies with a software engineering background and hands-on experience in offensive cybersecurity.
My work is increasingly focused on the intersection of AI engineering and cybersecurity, with interests in:
- Machine Learning & Deep Learning
- Generative AI & LLM applications
- AI Security & LLM Security
- AI Red Teaming
- Web & API Security
- Vulnerability Research & Bug Bounty
- Security Automation
I enjoy building, breaking, testing, and documenting technical systems β from security tools and web vulnerabilities to AI and machine-learning applications.
Currently, I'm developing my AI engineering skills through structured ML/DL and Generative AI training while continuing hands-on offensive security work.
AI Engineering
βββ Machine Learning
βββ Deep Learning
βββ PyTorch
βββ Transformers
βββ Generative AI
βββ LLM Applications
βββ RAG
βββ AI Agents
AI Security
βββ LLM Security
βββ Prompt Injection
βββ Indirect Prompt Injection
βββ RAG Security
βββ Agent Security
βββ AI Red Teaming
Offensive Security
βββ Web & API Security
βββ Penetration Testing
βββ Vulnerability Research
βββ Bug Bounty
βββ Reconnaissance
βββ Security Automation
- Python
- NumPy
- Pandas
- Matplotlib
- Scikit-learn
- TensorFlow
- Keras
- OpenCV
- Machine Learning
- Deep Learning
- Computer Vision
- Transformers
- Generative AI
- LLM applications
- Prompt Injection
- Indirect Prompt Injection
- LLM Security
- System Prompt Leakage
- Data Leakage
- RAG Security
- Tool Abuse
- AI Red Teaming
- Web Application Security
- API Security
- Penetration Testing
- Vulnerability Research
- Bug Bounty
- Reconnaissance
- Authentication & Authorization
- XSS
- SQL Injection
- CSRF
- SSRF
- IDOR / BOLA
- XXE
- SSTI
- Path Traversal
- Command Injection
- GraphQL Security
- JWT Security
- Burp Suite
- Nmap
- Nuclei
- ffuf
- Gobuster
- Amass
- Subfinder
- Sublist3r
- httpx
- SQLmap
- Metasploit
- Wireshark
- Hashcat
- John the Ripper
- Impacket
- BloodHound
- Autopsy
- ExifTool
- Python
- Bash
- C
- Java
- JavaScript
- SQL
- HTML
- Flask
- Django (Still Learning ...)
- Git
- GitHub
- Docker
- Docker Compose
- Linux
- WSL
- Apache Spark
- PySpark
- SparkSQL
- SparkML
- RDD
- DataFrames
- Kafka
- Hadoop / HDFS
- Azure fundamentals
AI security labs and research focused on LLM applications, prompt injection, RAG security, agent security and AI red teaming.
Machine learning, deep learning and Generative AI projects developed through academic work and independent learning.
Web/API security research, penetration testing, vulnerability research, CTFs and bug bounty work.
Tools for reconnaissance, asset discovery, vulnerability testing and security workflow automation.
- CIORA β Bash-based reconnaissance automation for bug bounty and penetration testing workflows.
- AI / ML Projects β Machine learning, computer vision and AI engineering projects.
- Security Research β Web/API security research, CTFs and vulnerability research.
- Big Data Projects β PySpark, SparkML, Kafka and distributed data processing.
- AI Security Projects β Upcoming work focused on LLM security and AI red teaming.
More projects and technical writeups are available on my portfolio.
- IBM AI Engineering Professional Certificate
- Machine Learning
- Deep Learning
- PyTorch
- Transformers
- Generative AI
- LLMs
- RAG
- AI Agents
- Hack The Box CPTS Path
- Hack The Box CBBH Path
- AI Red Teaming
- Web & API Security
- Vulnerability Research
I document my learning, security research and technical experiments on my personal blog.
Topics include:
- Security Research
- Web Security
- CTF Writeups
- Bug Bounty
- AI Engineering
- Projects
- Technical Experiments
Building β’ Breaking β’ Learning β’ Documenting


