Skip to content
View moza369's full-sized avatar
πŸ˜€
Happy
πŸ˜€
Happy

Highlights

  • Pro

Block or report moza369

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
moza369/README.md

πŸ‘‹ Mohamed Zahir

AI Engineering β€’ AI Security β€’ Offensive Security

Master's Student in Artificial Intelligence & Emerging Technologies

Portfolio β€’ LinkedIn β€’ HackerOne β€’ Hack The Box


About Me

I'm Mohamed Zahir, a Master's student in Artificial Intelligence and Emerging Technologies with a software engineering background and hands-on experience in offensive cybersecurity.

My work is increasingly focused on the intersection of AI engineering and cybersecurity, with interests in:

  • Machine Learning & Deep Learning
  • Generative AI & LLM applications
  • AI Security & LLM Security
  • AI Red Teaming
  • Web & API Security
  • Vulnerability Research & Bug Bounty
  • Security Automation

I enjoy building, breaking, testing, and documenting technical systems β€” from security tools and web vulnerabilities to AI and machine-learning applications.

Currently, I'm developing my AI engineering skills through structured ML/DL and Generative AI training while continuing hands-on offensive security work.


Current Focus

AI Engineering
β”œβ”€β”€ Machine Learning
β”œβ”€β”€ Deep Learning
β”œβ”€β”€ PyTorch
β”œβ”€β”€ Transformers
β”œβ”€β”€ Generative AI
β”œβ”€β”€ LLM Applications
β”œβ”€β”€ RAG
└── AI Agents

AI Security
β”œβ”€β”€ LLM Security
β”œβ”€β”€ Prompt Injection
β”œβ”€β”€ Indirect Prompt Injection
β”œβ”€β”€ RAG Security
β”œβ”€β”€ Agent Security
└── AI Red Teaming

Offensive Security
β”œβ”€β”€ Web & API Security
β”œβ”€β”€ Penetration Testing
β”œβ”€β”€ Vulnerability Research
β”œβ”€β”€ Bug Bounty
β”œβ”€β”€ Reconnaissance
└── Security Automation

Technical Skills

AI / Machine Learning (Still Learning ...)

  • Python
  • NumPy
  • Pandas
  • Matplotlib
  • Scikit-learn
  • TensorFlow
  • Keras
  • OpenCV
  • Machine Learning
  • Deep Learning
  • Computer Vision
  • Transformers
  • Generative AI
  • LLM applications

AI Security (Still Learning ...)

  • Prompt Injection
  • Indirect Prompt Injection
  • LLM Security
  • System Prompt Leakage
  • Data Leakage
  • RAG Security
  • Tool Abuse
  • AI Red Teaming

Cybersecurity

  • Web Application Security
  • API Security
  • Penetration Testing
  • Vulnerability Research
  • Bug Bounty
  • Reconnaissance
  • Authentication & Authorization
  • XSS
  • SQL Injection
  • CSRF
  • SSRF
  • IDOR / BOLA
  • XXE
  • SSTI
  • Path Traversal
  • Command Injection
  • GraphQL Security
  • JWT Security

Security Tools

  • Burp Suite
  • Nmap
  • Nuclei
  • ffuf
  • Gobuster
  • Amass
  • Subfinder
  • Sublist3r
  • httpx
  • SQLmap
  • Metasploit
  • Wireshark
  • Hashcat
  • John the Ripper
  • Impacket
  • BloodHound
  • Autopsy
  • ExifTool

Development & Systems

  • Python
  • Bash
  • C
  • Java
  • JavaScript
  • SQL
  • HTML
  • Flask
  • Django (Still Learning ...)
  • Git
  • GitHub
  • Docker
  • Docker Compose
  • Linux
  • WSL

Big Data & Cloud (Still Learning ...)

  • Apache Spark
  • PySpark
  • SparkSQL
  • SparkML
  • RDD
  • DataFrames
  • Kafka
  • Hadoop / HDFS
  • Azure fundamentals

Featured Work

AI Security

AI security labs and research focused on LLM applications, prompt injection, RAG security, agent security and AI red teaming.

AI Engineering

Machine learning, deep learning and Generative AI projects developed through academic work and independent learning.

Offensive Security

Web/API security research, penetration testing, vulnerability research, CTFs and bug bounty work.

Security Automation

Tools for reconnaissance, asset discovery, vulnerability testing and security workflow automation.


Selected Projects

  • CIORA β€” Bash-based reconnaissance automation for bug bounty and penetration testing workflows.
  • AI / ML Projects β€” Machine learning, computer vision and AI engineering projects.
  • Security Research β€” Web/API security research, CTFs and vulnerability research.
  • Big Data Projects β€” PySpark, SparkML, Kafka and distributed data processing.
  • AI Security Projects β€” Upcoming work focused on LLM security and AI red teaming.

More projects and technical writeups are available on my portfolio.


Current Learning

Artificial Intelligence

  • IBM AI Engineering Professional Certificate
  • Machine Learning
  • Deep Learning
  • PyTorch
  • Transformers
  • Generative AI
  • LLMs
  • RAG
  • AI Agents

Cybersecurity

  • Hack The Box CPTS Path
  • Hack The Box CBBH Path
  • AI Red Teaming
  • Web & API Security
  • Vulnerability Research

Technical Writing

I document my learning, security research and technical experiments on my personal blog.

moza369.github.io

Topics include:

  • Security Research
  • Web Security
  • CTF Writeups
  • Bug Bounty
  • AI Engineering
  • Projects
  • Technical Experiments

GitHub Stats

GitHub statistics Top languages

Connect


Building β€’ Breaking β€’ Learning β€’ Documenting

Pinned Loading

  1. ciora ciora Public

    Ciora is a Bash-based recon automation tool built for bug bounty hunters and pentesters. It downloads the HackerOne program scope (public or private with session cookie), extracts web assets & wild…

    Shell 4