Building security tools, exploring how systems fail, and documenting what I learn.

An open technical archive containing software experiments, network forensics tools, CTF competition write-ups, and security research notes.

Mouhib Mahadbi avatar illustration

About Mouhib Mahadbi

I am a Junior Penetration Tester, CTF player, and independent security builder based in Tunisia (@MouhibMahadbi / @mouhibmh / @mouhib02).

This space serves as a personal laboratory notebook to document working security utilities, network forensics experiments, and CTF challenge notes as I build software.

My focus spans practical offensive security assessments, PCAP packet inspection, metadata privacy utilities, and application security prompt kits.

All code and security tooling linked below are open-source and maintained on GitHub.

Currently Exploring

Penetration Testing & CTF

→ analyzing web application attack vectors, enumeration, and exploit techniques

Linux internals & Privilege Escalation

→ testing local root vectors, SUID misconfigurations, and kernel space isolation

Network Security & PCAP

→ experimenting with raw packet parsing, frame extraction, and network attack surfaces

Privacy Engineering

→ building tools around metadata reduction, EXIF stripping, and digital footprints

AppSec & AI Tooling

→ structuring prompt security frameworks and automated repository vulnerability scanners

Applied Cryptography

→ testing encryption primitives, key exchange mechanics, and verification flows

Things I Built

Perfect Home Real Estate

released

Production luxury real estate web application and boutique property advisory portal for Perfect Home Real Estate in Bahrain, featuring video showcases, RERA license verification, interactive property catalog filters, inquiry modals, and automated WhatsApp integration.

Fratello Fast Food

released

Production responsive web application and digital restaurant portal for Fratello Fast Food in Hammamet, featuring high-performance 60 FPS interactions, custom food media showcase, and automated WhatsApp ordering integration.

Metadata-remover

released

Security utility for inspecting, analyzing, and removing hidden EXIF and sensitive metadata from files.

repoguard-lite

released

Lightweight static analysis scanner for detecting secrets, key leaks, and misconfigurations in codebases.

AppSec-Prompt-Kit

released

Curated repository of application security prompts, threat modeling templates, and code audit guides for LLMs.

pcap-jpeg-extractor-to-video

experiment

Forensic network tool that extracts raw JPEG payloads from packet captures and renders them sequentially into video files.

vidcii

experiment

Command-line tool converting raw video streams and frames into custom ASCII art renders in real time.

Things I Wrote

MouhibMahadbi 2d ago

A Photo Is Not Just a Picture: Understanding Image Metadata and Privacy Risks

You take a photo of your coffee, your workspace, your house, or a trip. You see only the image. A collection of pixels representing a moment, but behind it lies hidden metadata.

Read on Medium →
A Photo Is Not Just a Picture article thumbnail
MouhibMahadbi Jun 15

Would You Notice If Your Machine Was Compromised?

A defensive walkthrough of suspicious traffic patterns, timelines, and the questions I would ask during forensic network analysis.

Read on Medium →
Would You Notice If Your Machine Was Compromised article thumbnail
MouhibMahadbi Jan 12

Do We Really Understand What a Vulnerability Is?

The word vulnerability is used daily in cybersecurity. We repeat it constantly, often with confidence, but rarely with reflection on root causes.

Read on Medium →
Do We Really Understand What a Vulnerability Is article thumbnail

Things I Tested

TryHackMe logo TryHackMe

MouhibMahadbi on TryHackMe

Hands-on CTF challenges and pentesting labs covering web application vulnerabilities, network exploitation, and privilege escalation.

Active profile: MouhibMahadbi • CTF Competitor
Hack The Box logo Hack The Box

Mouhib Mahadbi on Hack The Box

Active machine exploitation, enumeration, and privilege escalation challenges on Hack The Box platform.

Professional Rank • Level 49

Public Profiles