Skip to content
View Aymwvn's full-sized avatar

Highlights

  • Pro

Block or report Aymwvn

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Aymwvn/README.md

🔵 About Me

I'm Aymane Boualam, a Cybersecurity Analyst and Penetration Tester based in Rabat, Morocco, focused on offensive security, secure infrastructure design, and building tooling that makes security testing faster and more precise.

Role: Cybersecurity Analyst & Penetration Tester
Focus: Offensive Security / AppSec / Secure Infrastructure
Frameworks: NIST · ISO/IEC 27001 · OWASP Top 10
Mindset: Build it secure. Break it properly. Document it clearly.

🎯 Open To: Penetration Testing roles · SOC / Security Analyst positions · AppSec Engineering · Freelance security assessments · Collaboration on open-source security tooling


🔵 Tech Stack

Languages

Python Bash Java JavaScript PHP PowerShell HTML CSS

Frontend

React HTML5 CSS3 JavaScript

Backend & Databases

FastAPI PostgreSQL Nginx

Cloud, DevOps & Security Tooling

AWS Azure Docker Linux Windows Wireshark VMware VirtualBox

Nmap Metasploit Burp Suite Splunk OpenSSL Suricata


🔵 Featured Projects

🛡️ BrovanaRange — Secure Open-Source Cyber Range Platform

A full-stack offensive security training platform supporting isolated labs, in-browser terminal access, dynamic flags, and live scoring.

Stack React · FastAPI · PostgreSQL · Docker · Nginx
Scale Multi-tenant, per-user isolated lab environments
Performance Containerized lab spin-up with network segmentation
Security HTTPS reverse proxy, UFW firewalling, Docker network segmentation, JWT auth, RBAC, rate limiting, security headers, audit logs
Impact OWASP WSTG-inspired control validation; Suricata & Zeek IDS monitoring with custom alert rules
Repository github.com/Aymwvn/BrovanaRange

Designed and hardened as a real deployable platform rather than a demo — every exposed service was validated with Nmap, curl, and Gobuster-style testing, and network isolation was independently verified via Docker network inspection.

🤖 AI-Assisted Pentest Co-Pilot

A CLI tool that fuses traditional recon tooling with LLM-based analysis (Claude API or local models) to accelerate the pentesting workflow.

Stack Python · Claude API / Local LLM · CLI
Scale Multi-tool ingestion (Nmap, Gobuster, Whatweb, ffuf, Nikto)
Performance Automated cross-tool finding correlation
Security NVD-based CVE lookups with CVSS scoring
Impact MITRE ATT&CK technique mapping; auto-generated DOCX/PDF/Markdown reports
Repository github.com/Aymwvn/AI-Assisted-Pentest-Co-Pilot

Built to close the gap between raw scan output and a client-ready report — reducing manual triage time while keeping every finding traceable to evidence.

🏴 CTF Writeups

A structured collection of cybersecurity writeups documenting the methodology, exploitation process, privilege escalation techniques, and lessons learned from Capture The Flag (CTF) challenges across multiple security domains.

Stack Markdown · Kali Linux · Burp Suite · Nmap · Gobuster · Metasploit · Wireshark
Coverage Web · Pwn · Reverse Engineering · Cryptography · DFIR · OSINT · Steganography · Networking · Hardware · AI
Methodology Reconnaissance → Enumeration → Exploitation → Privilege Escalation → Post-Exploitation → Documentation
Security Focus OWASP, Active Directory, Linux Privilege Escalation, Web Exploitation, Binary Exploitation, Digital Forensics
Impact Demonstrates practical offensive security skills, structured reporting, and reproducible attack methodologies
Repository github.com/Aymwvn/CTF-Writeups

Each writeup follows a consistent methodology, documenting reconnaissance, attack vectors, exploitation steps, privilege escalation techniques, evidence collection, and remediation insights. The repository serves as both a personal knowledge base and a public portfolio showcasing hands-on offensive security experience.

🖥️ Enterprise Virtual Lab — System & Network Security Setup

A self-built multi-machine infrastructure simulating an enterprise network for security practice and monitoring.

Stack VirtualBox · CentOS · Windows Server 2022 · Windows 10
Scale Multi-VM domain environment
Performance Active Directory, DNS, SSH/RDP, iSCSI storage configured end-to-end
Security Log analysis, basic incident detection, access control configuration
Impact Zabbix monitoring across Apache/PHP/MariaDB and FTP services
Repository Self-hosted lab environment

Replicates a realistic corporate network to practice detection and hardening beyond isolated CTF-style targets.

🕸️ Web Application Penetration Testing Lab — OWASP Juice Shop

Hands-on offensive testing lab targeting the intentionally vulnerable OWASP Juice Shop application.

Stack Kali Linux · Nmap · Burp Suite · Gobuster
Scale Full application surface enumeration
Performance Manual + tool-assisted vulnerability discovery
Security Identified and exploited SQL Injection, XSS, and IDOR vulnerabilities
Impact Professional penetration test report with PoC evidence
Repository Lab environment

Used as a structured exercise to practice professional report writing alongside exploitation technique.


🔵 Connect With Me

Gmail LinkedIn GitHub Portfolio


"Security isn't a feature you bolt on — it's a discipline you build in from the first line of code."

Pinned Loading

  1. BrovanaRange BrovanaRange Public

    Open-source cyber range for offensive security training — isolated labs, live attack detection, and production-grade auth built from scratch

    Python 1

  2. AI-Assisted-Pentest-Co-Pilot AI-Assisted-Pentest-Co-Pilot Public

    AI-assisted pentest methodology co-pilot — parses recon tool output and suggests ranked next steps using Claude + PTES/OWASP methodology

    Python 1

  3. CTF-Writeups CTF-Writeups Public

    Personal CTF writeups across Web, Crypto, Pwn, Reverse Engineering, OSINT, DFIR, and more — documented methodology, not just flags.

    1

  4. web-pentest-owasp-juice-shop web-pentest-owasp-juice-shop Public

    Full web application penetration test of OWASP Juice Shop, including vulnerability discovery, exploitation, and professional reporting.

    1

  5. MallMaps MallMaps Public

    Wayfynd — a "Google Maps for malls" concept. A single-page web app that renders an SVG floor plan of a mall, lets users search/filter stores, and animates a walking route from their position to any…

    JavaScript 1

  6. Model-Page Model-Page Public

    A Modeling page that showcases your art at fullest.

    HTML