Skip to content
View ashrafmohammedsalih's full-sized avatar

Block or report ashrafmohammedsalih

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Typing SVG

Cybersecurity Professional | OSCP+ Certified | Penetration Testing · IoT Development and Security · Hardware Security

Portfolio LinkedIn Medium Email

profile views


🛡️ About Me

Cybersecurity professional and penetration tester with OSCP and OSCP+ certifications. I specialize in network, web application, IoT, and hardware security assessments.

What sets me apart is my engineering background — I spent years building the exact types of production systems I now test: smart lockers controlled via RS485 serial protocols, vending machines connected through USB APIs, NFC/RFID access control systems, MQTT-connected Raspberry Pi agents, and payment gateways processing real transactions.

I built the systems — now I know how to break and defend them.

  • 🔴 OSCP+ — OffSec Certified Professional Plus (March 2026)
  • 🟠 OSCP — OffSec Certified Professional (March 2026)
  • 📍 Based in Riyadh, Saudi Arabia
  • 🎓 B.Sc. Software Engineering — Sudan University of Science and Technology
  • 🌐 Portfolio: ashrafmohammedsalih.github.io/portfolio

🎯 Core Focus Areas

┌─────────────────────────────────────────────────────────────────┐
│                                                                 │
│  🔴 Penetration Testing     Network, Web, IoT, Active Directory │
│  🔧 IoT & Hardware Hacking  RS485, MQTT, NFC/RFID, Firmware    │
│  🌐 Web & API Security      OWASP Top 10, SQLi, XSS, SSRF     │
│  ⚡ Security Automation      Python, Bash, Custom Tools          │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

🏆 Certifications

OSCP+
OffSec Certified Professional+
Privilege Escalation · Exploitation · Web App Security · Scripting
🔗 Verify
OSCP
OffSec Certified Professional
Network Pentesting · Linux/Windows Security · Active Directory
🔗 Verify

🛠️ Skills & Tools

Offensive Security

Penetration Testing Exploit Development Privilege Escalation Active Directory Vulnerability Research

Security Tools

Burp Suite Metasploit Nmap Wireshark BloodHound Hashcat Ghidra Kali Linux

IoT & Hardware Security

RS485 MQTT NFC/RFID Raspberry Pi Firmware Analysis

Programming & Scripting

Python Bash Dart Kotlin Java PHP JavaScript

Infrastructure

Windows Server IIS MSSQL Kerberos MySQL AWS

Mobile & Frameworks

Flutter Jetpack Compose Laravel Spring Boot


💼 Experience

🔒 Security Research & Penetration Testing

  • OSCP & OSCP+ certified — hands-on exploitation of networks, web apps, and Active Directory
  • Built Magnum Scanner — custom recon automation tool for pentesting environments
  • Published security research on privilege escalation, Nmap scanning techniques, and systemd exploitation

🏢 MOGI ALTIGAH — Mobile & IoT Developer (Dec 2023 – Present)

Riyadh, Saudi Arabia · Vending Machine Solutions

  • Deployed Ministry of Industry employee system on dual Windows Server with IIS, MSSQL, and Kerberos authentication
  • Built smart locker control using Python on Raspberry Pi with RS485 serial protocol and MQTT
  • Developed Wasfaty — automated medication dispensing kiosk integrated with Saudi NUPCO e-Prescribing platform
  • Built 4+ Flutter apps: SaladBar Meals, Fushati Canteen, Khozama Meals, Smart Vending App
  • Integrated 6 payment gateways: Moyasser, Apple Pay, mada, Tamara, STC Pay, Interpay

📱 Full Screen — Mobile Developer (Jun – Dec 2023)

Riyadh, Saudi Arabia · Media · Advertising · Exhibitions

  • Built 3Minutes Taxi — ride-hailing app trusted by 50,000+ customers

📝 Latest Blog Posts

...more on Medium


🚀 Featured Projects

Project Type Description
Ministry of Industry IoT Employee purchase system — Windows Server, IIS, MSSQL, Kerberos, NFC/RFID
Smart Lockers IoT Python/Raspberry Pi locker control via RS485 serial + MQTT
Khozama Meals App + IoT Smart meal subscription with locker pickup — Flutter + MQTT + Hardware
Wasfaty IoT Automated pharmacy kiosk — Kotlin + Wasfaty NUPCO APIs
3Minutes Taxi App Ride-hailing app — 50K+ users, GPS tracking, Flutter
Smart Vending App App Mobile vending companion — QR scan, browse, pay, dispense
Magnum Scanner Security Custom recon automation tool for pentesting labs

📊 GitHub Stats

GitHub Stats GitHub Streak

Top Languages


🔴 Open to penetration testing, security research, and red team opportunities

🌐 Portfolio · 💼 LinkedIn · 📝 Blog · 📧 Email

Popular repositories Loading

  1. Personal-Expenses Personal-Expenses Public

    Personal-Expenses

    C++ 1

  2. ToDo-App-clean-architecture ToDo-App-clean-architecture Public

    A to-do Flutter app built using clean architecture and the BLoC pattern follows a structured and modular approach to software development.

    Dart 1

  3. ashrafmohammedsalih ashrafmohammedsalih Public

    Config files for my GitHub profile.

  4. glasses_store_ui glasses_store_ui Public

    glasses store app ui

    Dart

  5. clean_architecture_get_random_advice clean_architecture_get_random_advice Public

    Dart

  6. Laravel-Task-List-App Laravel-Task-List-App Public

    PHP