About
Oussama Sahnoun
Senior Offensive Cybersecurity Expert Β· Purple Team Lead Β· AI Systems Security Researcher
π Tunisia Β Β·Β sahnoun.oussama11@gmail.com
TL;DR
Iβm a Senior Offensive Cybersecurity Expert with 7+ years of experience sitting at the intersection of offensive security, threat intelligence, and β more recently β AI/LLM system security. I break things for a living (web apps, APIs, Active Directory, and now AI agents), then help teams build detections around what I found.
I spoke at Black Hat MEA 2025 (Riyadh) on applying AI to predictive threat hunting, I hold 3 published Intel CVEs coordinated directly with Intel PSIRT, and Iβve secured everything from banking platforms to Airbus avionics systems under the DOβ326A airworthiness security standard.
I turn logs into stories, alerts into actions, and vulnerabilities into detections. My job isnβt just to prove a system can be broken β itβs to make sure it doesnβt happen again in production.
At a glance
| Β | Β |
|---|---|
| π Experience | 7+ years in offensive & defensive security |
| π€ Speaking | Black Hat MEA 2025, Riyadh β AI & Threat Intelligence |
| π CVEs | 3 published, coordinated with Intel PSIRT |
| π Certifications | CRTP, eCPPTv3, eWPTx, eWPT, eJPT, arcX CTI 101 |
What I do
Purple Teaming. I donβt just hand over a pentest report and walk away β I sit with SOC teams to build detection rules out of the attacks I ran, closing the loop between offense and defense.
Penetration Testing. Web, API, infrastructure, Cloud (AWS/Azure), and full Active Directory compromise chains β recon β domain enum β local priv esc β lateral movement β domain admin β cross-trust attacks. OWASP Top 10 and OWASP ASVS as baseline methodology.
Cyber Threat Intelligence. Operational CTI using MISP, OpenCTI, OSINT, and dark web monitoring β turning raw indicators into reports SOC analysts can actually act on. See my Cicada3301 and Stormous deep-dives, and my CTI methodology guide for what that looks like in practice.
Red Teaming. Realistic adversary simulation mapped to MITRE ATT&CK, designed to stress-test detection and response β not just find a way in.
AI / LLM Security. My newest focus: prompt injection, RAG pipeline attacks, agentic tool abuse, MCP surfaces, and AI supply-chain risk. This is what I spoke about at Black Hat MEA 2025, and what my AI Systems Security Specialist series and Web LLM Attacks posts are built around.
Black Hat MEA 2025 β Riyadh
βAI & Threat Intelligence: Advancing Predictive Threat Hunting.β I presented how AI is moving SOCs from reactive detection to proactive anticipation β automating threat intelligence analysis and cutting response times β and demoed ThreatLens, my open-source LLM/RAG-powered CTI platform.
Full technical write-up: Black Hat MEA 2025 Recap
CVE research
Three vulnerabilities discovered and disclosed responsibly to Intel PSIRT β full cycle from reproduction and PoC to PGP-signed reporting, CVSS validation, and coordinated public disclosure.
| CVE | Severity | Summary |
|---|---|---|
| CVE-2020-12297 (Intel SA-00366) | π΄ High | Improper access control in the Intel CSME Driver Installer β local privilege escalation to SYSTEM via DLL injection. |
| CVE-2020-24454 (Intel SA-00455) | π Medium | XXE in Intel Quartus Prime β external resource inclusion via a malicious project file, risking secret exfiltration from FPGA projects. |
| CVE-2020-24451 (Intel SA-00438) | π Medium | Uncontrolled search path in the Intel Optane DC Persistent Memory Installer β local DLL hijacking and privilege escalation. |
Experience
Cybersecurity Expert β Vermeg for Banking & Insurance Software Β· Dec 2021 β May 2026 Led offensive security audits across the SDLC for banking and insurance clients. 24+ full pentests, 50+ reports, and internal automation that cut manual testing workload by 30% β contributing to a 40% drop in critical vulnerabilities reaching production.
Cybersecurity Consultant β Airbus (via IMH Group) Β· Jun 2021 β Oct 2021 Audited avionics systems (A320/A350/A380) against the DOβ326A airworthiness security standard, reviewing 15+ System Modification Plans and tightening security-requirement traceability.
Cybersecurity Consultant β EY (Ernst & Young) Β· Feb 2020 β Jun 2021 Offensive audits and Red Team engagements for banking and government critical infrastructure β 100+ critical/high findings, executive-level risk reporting, and SOC detection improvement work.
Cybersecurity Consultant β Keystone Group Β· Jan 2019 β Jan 2020 Multi-sector penetration testing across network and web application infrastructure β 50+ critical vulnerabilities identified and demonstrated end-to-end.
Certifications
- CRTP β Certified Red Team Professional (Active Directory attack paths & red team tradecraft)
- eCPPTv3 β Expert-level Linux/Windows infrastructure & Active Directory pentesting β 2026
- eWPTx β Expert Web Application Penetration Tester eXtreme β 2024
- eWPT β Web Application Penetration Tester β 2023
- eJPT β Junior Penetration Tester β 2021
- arcX Foundation β Cyber Threat Intelligence 101 β 2025
Personal projects
ThreatLens β Open-source, AI-assisted Threat Intelligence platform using an LLM/RAG architecture to automatically analyze and contextualize threat data. Presented live at Black Hat MEA 2025.
WinLogHunt-V1.0 β Open-source Windows Event Log (EVTX) analysis tool for anomaly detection β ransomware, malware, and CVE exploitation indicators.
Education
- Computer Engineering, Cybersecurity specialization β UniversitΓ© TeKβUP, Tunisia (2021β2025)
- Bachelorβs Degree in Networks and Information Systems β ISET Zaghouan, Tunisia (2016β2019)
Letβs connect
I write about threat intelligence, ransomware analysis, and AI/LLM security on this blog β start with the AI Systems Security Specialist series or browse the archives.
For collaborations, speaking, or just to talk security: sahnoun.oussama11@gmail.com Β· LinkedIn Β· GitHub Β· X / Twitter