Skip to content
View Aymwvn's full-sized avatar

Highlights

  • Pro

Block or report Aymwvn

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Aymwvn/README.md
Typing SVG

Bachelor's DegreeLocation


PortfolioLinkedInEmailGitHub


Profile ViewsFollowersStars


🔵 About Me

I'm Aymane Boualam, a Cybersecurity Analyst and Penetration Tester based in Rabat, Morocco, focused on offensive security, secure infrastructure design, and building tooling that makes security testing faster and more precise.

Role: Cybersecurity Analyst & Penetration TesterFocus: Offensive Security / AppSec / Secure InfrastructureFrameworks: NIST · ISO/IEC 27001 · OWASP Top 10Mindset: Build it secure. Break it properly. Document it clearly.

🎯 Open To: Penetration Testing roles · SOC / Security Analyst positions · AppSec Engineering · Freelance security assessments · Collaboration on open-source security tooling


🔵 Tech Stack

Languages

PythonBashJavaJavaScriptPHPPowerShellHTMLCSS

Frontend

ReactHTML5CSS3JavaScript

Backend & Databases

FastAPIPostgreSQLNginx

Cloud, DevOps & Security Tooling

AWSAzureDockerLinuxWindowsWiresharkVMwareVirtualBox

NmapMetasploitBurp SuiteSplunkOpenSSLSuricata


🔵 Featured Projects

🛡️ BrovanaRange — Secure Open-Source Cyber Range Platform

A full-stack offensive security training platform supporting isolated labs, in-browser terminal access, dynamic flags, and live scoring.

StackReact · FastAPI · PostgreSQL · Docker · Nginx
ScaleMulti-tenant, per-user isolated lab environments
PerformanceContainerized lab spin-up with network segmentation
SecurityHTTPS reverse proxy, UFW firewalling, Docker network segmentation, JWT auth, RBAC, rate limiting, security headers, audit logs
ImpactOWASP WSTG-inspired control validation; Suricata & Zeek IDS monitoring with custom alert rules
Repositorygithub.com/Aymwvn/BrovanaRange

Designed and hardened as a real deployable platform rather than a demo — every exposed service was validated with Nmap, curl, and Gobuster-style testing, and network isolation was independently verified via Docker network inspection.

🤖 AI-Assisted Pentest Co-Pilot

A CLI tool that fuses traditional recon tooling with LLM-based analysis (Claude API or local models) to accelerate the pentesting workflow.

StackPython · Claude API / Local LLM · CLI
ScaleMulti-tool ingestion (Nmap, Gobuster, Whatweb, ffuf, Nikto)
PerformanceAutomated cross-tool finding correlation
SecurityNVD-based CVE lookups with CVSS scoring
ImpactMITRE ATT&CK technique mapping; auto-generated DOCX/PDF/Markdown reports
Repositorygithub.com/Aymwvn/AI-Assisted-Pentest-Co-Pilot

Built to close the gap between raw scan output and a client-ready report — reducing manual triage time while keeping every finding traceable to evidence.

🏴 CTF Writeups

A structured collection of cybersecurity writeups documenting the methodology, exploitation process, privilege escalation techniques, and lessons learned from Capture The Flag (CTF) challenges across multiple security domains.

StackMarkdown · Kali Linux · Burp Suite · Nmap · Gobuster · Metasploit · Wireshark
CoverageWeb · Pwn · Reverse Engineering · Cryptography · DFIR · OSINT · Steganography · Networking · Hardware · AI
MethodologyReconnaissance → Enumeration → Exploitation → Privilege Escalation → Post-Exploitation → Documentation
Security FocusOWASP, Active Directory, Linux Privilege Escalation, Web Exploitation, Binary Exploitation, Digital Forensics
ImpactDemonstrates practical offensive security skills, structured reporting, and reproducible attack methodologies
Repositorygithub.com/Aymwvn/CTF-Writeups

Each writeup follows a consistent methodology, documenting reconnaissance, attack vectors, exploitation steps, privilege escalation techniques, evidence collection, and remediation insights. The repository serves as both a personal knowledge base and a public portfolio showcasing hands-on offensive security experience.

🖥️ Enterprise Virtual Lab — System & Network Security Setup

A self-built multi-machine infrastructure simulating an enterprise network for security practice and monitoring.

StackVirtualBox · CentOS · Windows Server 2022 · Windows 10
ScaleMulti-VM domain environment
PerformanceActive Directory, DNS, SSH/RDP, iSCSI storage configured end-to-end
SecurityLog analysis, basic incident detection, access control configuration
ImpactZabbix monitoring across Apache/PHP/MariaDB and FTP services
RepositorySelf-hosted lab environment

Replicates a realistic corporate network to practice detection and hardening beyond isolated CTF-style targets.

🕸️ Web Application Penetration Testing Lab — OWASP Juice Shop

Hands-on offensive testing lab targeting the intentionally vulnerable OWASP Juice Shop application.

StackKali Linux · Nmap · Burp Suite · Gobuster
ScaleFull application surface enumeration
PerformanceManual + tool-assisted vulnerability discovery
SecurityIdentified and exploited SQL Injection, XSS, and IDOR vulnerabilities
ImpactProfessional penetration test report with PoC evidence
RepositoryLab environment

Used as a structured exercise to practice professional report writing alongside exploitation technique.


🔵 Connect With Me

GmailLinkedInGitHubPortfolio


"Security isn't a feature you bolt on — it's a discipline you build in from the first line of code."

Pinned Loading

  1. BrovanaRangeBrovanaRangePublic

    Open-source cyber range for offensive security training — isolated labs, live attack detection, and production-grade auth built from scratch

    Python 3

  2. AI-Assisted-Pentest-Co-PilotAI-Assisted-Pentest-Co-PilotPublic

    AI-assisted pentest methodology co-pilot — parses recon tool output and suggests ranked next steps using Claude + PTES/OWASP methodology

    Python 4

  3. CTF-WriteupsCTF-WriteupsPublic

    Personal CTF writeups across Web, Crypto, Pwn, Reverse Engineering, OSINT, DFIR, and more — documented methodology, not just flags.

    3

  4. web-pentest-owasp-juice-shopweb-pentest-owasp-juice-shopPublic

    Full web application penetration test of OWASP Juice Shop, including vulnerability discovery, exploitation, and professional reporting.

    3

  5. MallMapsMallMapsPublic

    Wayfynd — a "Google Maps for malls" concept. A single-page web app that renders an SVG floor plan of a mall, lets users search/filter stores, and animates a walking route from their position to any…

    JavaScript 3

  6. Model-PageModel-PagePublic

    A Modeling page that showcases your art at fullest.

    HTML 1