About

About

Oussama Sahnoun

Senior Offensive Cybersecurity Expert Β· Purple Team Lead Β· AI Systems Security Researcher

πŸ“ Tunisia Β Β·Β  sahnoun.oussama11@gmail.com

LinkedIn GitHub X


TL;DR

I’m a Senior Offensive Cybersecurity Expert with 7+ years of experience sitting at the intersection of offensive security, threat intelligence, and β€” more recently β€” AI/LLM system security. I break things for a living (web apps, APIs, Active Directory, and now AI agents), then help teams build detections around what I found.

I spoke at Black Hat MEA 2025 (Riyadh) on applying AI to predictive threat hunting, I hold 3 published Intel CVEs coordinated directly with Intel PSIRT, and I’ve secured everything from banking platforms to Airbus avionics systems under the DO‑326A airworthiness security standard.

I turn logs into stories, alerts into actions, and vulnerabilities into detections. My job isn’t just to prove a system can be broken β€” it’s to make sure it doesn’t happen again in production.


At a glance

Β Β 
πŸ•’ Experience7+ years in offensive & defensive security
🎀 SpeakingBlack Hat MEA 2025, Riyadh β€” AI & Threat Intelligence
πŸ› CVEs3 published, coordinated with Intel PSIRT
πŸŽ“ CertificationsCRTP, eCPPTv3, eWPTx, eWPT, eJPT, arcX CTI 101

What I do

Purple Teaming. I don’t just hand over a pentest report and walk away β€” I sit with SOC teams to build detection rules out of the attacks I ran, closing the loop between offense and defense.

Penetration Testing. Web, API, infrastructure, Cloud (AWS/Azure), and full Active Directory compromise chains β€” recon β†’ domain enum β†’ local priv esc β†’ lateral movement β†’ domain admin β†’ cross-trust attacks. OWASP Top 10 and OWASP ASVS as baseline methodology.

Cyber Threat Intelligence. Operational CTI using MISP, OpenCTI, OSINT, and dark web monitoring β€” turning raw indicators into reports SOC analysts can actually act on. See my Cicada3301 and Stormous deep-dives, and my CTI methodology guide for what that looks like in practice.

Red Teaming. Realistic adversary simulation mapped to MITRE ATT&CK, designed to stress-test detection and response β€” not just find a way in.

AI / LLM Security. My newest focus: prompt injection, RAG pipeline attacks, agentic tool abuse, MCP surfaces, and AI supply-chain risk. This is what I spoke about at Black Hat MEA 2025, and what my AI Systems Security Specialist series and Web LLM Attacks posts are built around.


Black Hat MEA 2025 β€” Riyadh

β€œAI & Threat Intelligence: Advancing Predictive Threat Hunting.” I presented how AI is moving SOCs from reactive detection to proactive anticipation β€” automating threat intelligence analysis and cutting response times β€” and demoed ThreatLens, my open-source LLM/RAG-powered CTI platform.

Full technical write-up: Black Hat MEA 2025 Recap


CVE research

Three vulnerabilities discovered and disclosed responsibly to Intel PSIRT β€” full cycle from reproduction and PoC to PGP-signed reporting, CVSS validation, and coordinated public disclosure.

CVESeveritySummary
CVE-2020-12297 (Intel SA-00366)πŸ”΄ HighImproper access control in the Intel CSME Driver Installer β€” local privilege escalation to SYSTEM via DLL injection.
CVE-2020-24454 (Intel SA-00455)🟠 MediumXXE in Intel Quartus Prime β€” external resource inclusion via a malicious project file, risking secret exfiltration from FPGA projects.
CVE-2020-24451 (Intel SA-00438)🟠 MediumUncontrolled search path in the Intel Optane DC Persistent Memory Installer β€” local DLL hijacking and privilege escalation.

Experience

Cybersecurity Expert β€” Vermeg for Banking & Insurance Software Β· Dec 2021 – May 2026 Led offensive security audits across the SDLC for banking and insurance clients. 24+ full pentests, 50+ reports, and internal automation that cut manual testing workload by 30% β€” contributing to a 40% drop in critical vulnerabilities reaching production.

Cybersecurity Consultant β€” Airbus (via IMH Group) Β· Jun 2021 – Oct 2021 Audited avionics systems (A320/A350/A380) against the DO‑326A airworthiness security standard, reviewing 15+ System Modification Plans and tightening security-requirement traceability.

Cybersecurity Consultant β€” EY (Ernst & Young) Β· Feb 2020 – Jun 2021 Offensive audits and Red Team engagements for banking and government critical infrastructure β€” 100+ critical/high findings, executive-level risk reporting, and SOC detection improvement work.

Cybersecurity Consultant β€” Keystone Group Β· Jan 2019 – Jan 2020 Multi-sector penetration testing across network and web application infrastructure β€” 50+ critical vulnerabilities identified and demonstrated end-to-end.


Certifications

CRTP eCPPTv3 eWPTx eWPT eJPT arcX CTI 101

  • CRTP β€” Certified Red Team Professional (Active Directory attack paths & red team tradecraft)
  • eCPPTv3 β€” Expert-level Linux/Windows infrastructure & Active Directory pentesting β€” 2026
  • eWPTx β€” Expert Web Application Penetration Tester eXtreme β€” 2024
  • eWPT β€” Web Application Penetration Tester β€” 2023
  • eJPT β€” Junior Penetration Tester β€” 2021
  • arcX Foundation β€” Cyber Threat Intelligence 101 β€” 2025

Personal projects

ThreatLens β€” Open-source, AI-assisted Threat Intelligence platform using an LLM/RAG architecture to automatically analyze and contextualize threat data. Presented live at Black Hat MEA 2025.

WinLogHunt-V1.0 β€” Open-source Windows Event Log (EVTX) analysis tool for anomaly detection β€” ransomware, malware, and CVE exploitation indicators.


Education

  • Computer Engineering, Cybersecurity specialization β€” UniversitΓ© TeK‑UP, Tunisia (2021–2025)
  • Bachelor’s Degree in Networks and Information Systems β€” ISET Zaghouan, Tunisia (2016–2019)

Let’s connect

I write about threat intelligence, ransomware analysis, and AI/LLM security on this blog β€” start with the AI Systems Security Specialist series or browse the archives.

For collaborations, speaking, or just to talk security: sahnoun.oussama11@gmail.com Β· LinkedIn Β· GitHub Β· X / Twitter