
Masriyan
Masriyan / Reconnaissance & OSINT Automation
441Passive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security assessments
Masriyan / Vulnerability Scanning & Assessment
441Dependency auditing, CVE detection, configuration security review, CVSS scoring, and prioritized vulnerability reporting
Masriyan / Exploit Development & Payload Engineering
441Proof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing
Masriyan / Malware Analysis & Sandboxing
441Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
Masriyan / Threat Hunting & IOC Analysis
441IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
Masriyan / Incident Response & Digital Forensics
441IR playbook execution, evidence collection, forensic timeline analysis, memory forensics, and post-incident reporting following NIST SP 800-61 and SANS PICERL methodology
Masriyan / Network Security & Traffic Analysis
441Network traffic analysis, PCAP parsing, IDS/IPS rule creation, firewall configuration auditing, and network anomaly detection
Masriyan / Web Application Security Testing
441OWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments
Masriyan / Cloud Security & Container Hardening
441AWS/Azure/GCP security auditing, container and Kubernetes hardening, Infrastructure as Code scanning, and cloud compliance assessment
Masriyan / Log Analysis & SIEM Integration
441Security log parsing, anomaly detection, SIEM query building, Sigma rule creation, and correlation rule development across Splunk, Elastic, QRadar, and Microsoft Sentinel
Masriyan / Cryptographic Analysis & Assessment
441SSL/TLS auditing, cipher suite analysis, hash algorithm identification, encryption implementation review, and cryptographic weakness detection in code
Masriyan / Red Team Operations & Engagement Planning
441Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting
Masriyan / Blue Team Defense & Hardening
441System hardening, detection engineering, security baseline monitoring, patch management, defense-in-depth architecture, and security posture improvement
Masriyan / AI & LLM Security
441LLM and AI application security testing — prompt injection, jailbreak resistance, OWASP LLM Top 10 (2025), RAG and agent/tool-use security, model supply chain, and AI red teaming for authorized assessments
Masriyan / Mobile Application Security
441Android and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments
Masriyan / 18-ot-ics-security
441Operational Technology and industrial control system security — Purdue model segmentation, industrial protocol analysis (Modbus, DNP3, S7, EtherNet/IP), PLC/HMI exposure, IEC 62443 alignment, and MITRE ATT&CK for ICS, for authorized and safety-conscious assessments
Masriyan / GRC & Compliance
441Governance, risk, and compliance — risk assessment and scoring, control mapping across NIST CSF 2.0 / ISO 27001:2022 / SOC 2 / CIS Controls v8, gap analysis, audit evidence preparation, and security policy generation
Masriyan / Supply Chain Security
441Software supply chain security — SBOM generation and analysis, dependency confusion and typosquatting detection, malicious package indicators, CI/CD pipeline hardening, and artifact provenance/signing (SLSA, Sigstore)
Masriyan / Threat Intelligence & CTI
441Cyber threat intelligence production — the intelligence cycle, IOC extraction/normalization/enrichment, STIX/TAXII and MISP, structured analytic models (Diamond, Kill Chain, ATT&CK), source scoring, actor/campaign tracking, and finished intelligence reporting
Masriyan / Purple Team & Adversary Emulation
441Collaborative purple-team operations — threat-informed adversary emulation planning (ATT&CK, CTID, Atomic Red Team, CALDERA), the detect-tune-validate loop, detection coverage measurement (DeTT&CT/Navigator), safe execution and deconfliction, and MTTD/coverage reporting