Skip to content
View cy1ingachref's full-sized avatar

Block or report cy1ingachref

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cy1ingachref/README.md

Achref Ferjani  DevOps, DevSecOps, Software Engineering

Achref Ferjani

DevOps • DevSecOps • Software Engineering

Student at ISSATM Bizerte, Tunisia. I build and harden automated systems — CI/CD pipelines that catch vulnerabilities before merge, detection rules that fire on real attacks, and Python infrastructure with a security-first mindset.

Looking for opportunities in DevOps, DevSecOps, or software engineering roles.


All projects

Click to expand — 8 more projects
Project Track What it does CI
02-jwt-audit-tool DevSecOps JWT security audit CLI — detects alg:none, cracks weak HMAC secrets, tests expiry abuse, validates audience and signing assumptions. CI
03-cloud-soc-detection-lab DevSecOps Cloud SOC detection lab — simulate atomic attacks (auth brute-force, impossible travel), tune detection logic, and validate coverage with evidence. CI
04-vuln-app-autograder DevSecOps Vulnerability app autograder — runs OWASP Top 10 checks against a target application and produces a scored, reproducible security assessment. CI
05-purple-team-gym DevSecOps Purple-team simulation — an adaptive RED attacker and BLUE defender coevolve over 200 rounds, learning at each step to optimize attack or defense strategies. CI
sigma-lab DevSecOps Sigma detection lab — 4 detection rules (auth brute-force, impossible travel, SSRF probe, data exfiltration) with a green-check validation workflow. CI
mastermind SWE Multi-agent orchestration — a lead AI decomposes a task, delegates to worker agents, and aggregates results. Built for coordination and structured AI workflows. CI
bcrypt-5digit-cracker SWE Educational security demo — brute-force a bcrypt hash to recover a 5-digit numeric PIN. Web Worker-based and interactive. CI
netmon-lan-monitor DevOps LAN monitor + blue/red defense console (Windows-first). Continuous packet capture, MAC-primary device recognition, and handshake tracking. CI
tn-watch DevOps Zero-dependency change/digest monitor for RSS, JSON, and HTML feeds. Deduplicates and reports diffs. Clean Python CLI designed for lightweight monitoring. CI

Stack

Languages: Python (primary), Shell, JavaScript, HTML/CSS, YAML, SQL

DevOps: GitHub Actions, Docker, Semgrep, Trivy, tfsec, gitleaks, Sigma

Security: OWASP Top 10, JWT analysis, SSRF/IDOR/XSS/SQLi detection, ARP networking, authorized red-team, detection engineering

Infrastructure: SQLite, HTTP daemons, MCP servers, BM25 retrieval, WebSocket, Web Workers

Practices: Test-driven development, CI-gated workflows, evidence-backed findings, zero-dependency where practical, MIT licensing


About

  • Education: ISSATM Bizerte, Tunisia
  • Background: Authorized pentest internship at E-Tafakna (legal-tech SaaS), where I found bugs in a production application and wrote the report. That experience shaped the security projects here.
  • Approach: Build things that work, prove they work with tests, document how to use them. No "trust me bro" security — every finding in evidence-guardian carries a reproducible evidence chain.

Connect

⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡾⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡼⠀⢰⠀⢀⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⢲⠶⣂⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡞⠁⠀⠈⣍⣿⣿⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠈⡄⠈⠑⠢⢄⡀⠀⠀⠀⠀⠀⡜⠀⠀⠀⠀⢻⣿⣿⡇⠀⠀⠀⠀⠀⠀⣀⣤⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠠⢵⠀⠀⠀⠀⠈⠓⠤⣤⠄⡼⠀⠀⠀⠀⠀⠘⣿⣿⣿⠤⠄⠀⣠⠴⠊⢡⣿⠀⠠⠤⣤⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⢧⠀⠀⠀⠀⠀⠀⠈⠲⠃⠀⠀⠀⠀⠀⠀⢻⣿⡿⠗⠒⠉⠀⠀⠀⣾⣏⣠⣴⣾⡏⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠈⢆⠀⠀⠀⠀⠀⠀⢀⡠⠤⠔⠒⠂⠤⠄⣈⠁⠀⠀⠀⠀⠀⠀⢰⣿⣿⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢆⠀⠀⠀⡤⠊⠁⠀⠀⠀⠀⠀⠀⠀⠀⠉⠒⢄⠀⠀⠀⠀⣼⣿⣿⣿⣿⡟⠀⠀⠀⠀⠀⠀⠀
⠔⡀⠀⠀⠀⠀⠀⠈⠉⠉⠉⠀⢀⠎⠀⠀⠀⠀⣀⠤⢒⡠⠖⠂⠀⣀⣀⣀⠱⡀⠀⠀⣿⣿⣿⣿⣿⠃⠀⠀⠀⠀⠀⠀⠀
⠀⠈⠑⣤⡀⠀⠀⠀⠀⠀⠀⠀⡎⠀⠀⠠⠄⠋⠒⢈⡠⠄⠒⣈⠡⠤⠐⠚⠁⠙⡄⠀⠙⠛⠛⠻⢿⡶⠓⢶⣦⠀⠀⠀⠀
⠀⠀⠀⠀⠙⢢⡀⠀⠀⠀⠀⢰⢁⡤⠐⠒⠒⢊⣉⡠⠔⠚⠉⡀⠀⠀⠀⠈⠒⢄⠰⡀⠀⠀⠀⣠⠞⢀⣴⣯⣅⣀⣀⠀⠀
⠀⠀⠀⠀⠀⠀⠓⠤⡀⠀⠀⢸⠈⢉⠁⠉⠉⠀⠉⠢⡀⠀⡘⠀⢀⣀⣠⡤⠀⠘⢇⢣⠀⠀⣴⣭⣶⣿⣿⣿⣿⣿⡿⠟⠁
⠀⠀⠀⠀⠀⠀⠀⣀⠼⠃⠀⢸⣠⠃⠀⠀⠀⣀⡠⠤⠼⡀⢻⠉⠁⠀⠉⠀⠀⠀⡼⠸⡀⠀⠈⠻⢿⣿⣿⣿⠟⠉⠀⠀⠀
⠀⠀⢠⣠⠤⠒⠊⠁⠀⠀⠀⠈⡏⡦⠒⠈⠙⠃⠀⠀⢠⠇⠈⠢⣀⠀⠀⠀⣀⠔⠁⠀⣇⠀⠀⠀⢀⡽⠛⣿⣦⣀⡀⠀⠀
⠀⠀⠀⠈⠑⠢⢄⡀⠀⠀⠀⠀⢇⠘⢆⡀⠀⠀⢀⡠⠊⡄⠀⢰⠀⠉⠉⠉⣠⣴⠏⠀⣻⠒⢄⢰⣏⣤⣾⣿⣿⣿⣦⣄⠀
⠀⠀⠀⠀⠀⠀⠙⢻⣷⣦⡀⠀⢸⡀⠀⡈⠉⠉⢁⡠⠂⢸⠀⠀⡇⠙⠛⠛⠋⠁⠀⠀⣿⡇⢀⡟⣿⣿⣿⣿⣿⣿⠟⠋⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⢈⠇⠀⡴⠇⠀⠈⠉⠉⠀⠀⠀⠀⢣⣠⠇⠀⠀⠀⠀⠀⠀⠀⣿⣿⡟⠀⢻⠻⣿⡟⠉⠉⠉⠁⠀
⠀⠀⠀⠀⠀⠀⢀⡠⠖⠁⠀⢸⠀⠘⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⠐⢶⣿⢷⣯⣭⣤⣶⣿⣿⣦⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠒⠛⠒⠒⠤⠤⢲⠑⠦⢧⠀⠀⠀⠀⢀⡤⢖⠂⠉⠉⡸⠁⠀⠀⠀⢀⣾⣾⠈⣿⣿⣿⣿⣿⣿⣿⣷⡄⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠰⠾⣿⠀⠀⠈⢆⠸⣄⠊⠁⠀⠀⡉⢆⠀⡆⣀⠀⠀⠀⣰⢿⣷⣶⣾⣿⣿⣏⠉⠉⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠼⠠⠴⢞⣿⢦⠀⠀⠀⠀⠀⠛⠀⠉⠁⠛⠃⢀⣴⣿⣾⣿⣿⣿⣿⡿⠿⠆⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣿⣶⡷⢄⡀⠀⠀⠀⠀⠀⠀⢀⣴⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠉⠀⠀⠀⣿⠷⡖⠢⠤⠔⠒⠻⣿⣿⣿⣿⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠉⠉⠉⢉⡩⢽⢻⠗⠤⢀⣀⣀⡠⢿⣿⣿⠿⣏⠉⠉⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⠴⠊⠁⢠⠊⣸⠀⠀⠀⠀⠀⠀⠀⢻⠈⢖⠂⢉⠒⢤⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀

Pinned Loading

  1. 05-purple-team-gym 05-purple-team-gym Public

    Purple-team exercise gym — simulated attacker/defender loops with a live posture dashboard. Technique coverage scoring, MITRE ATT&CK mapping. Built for security training and self-assessment.

    HTML 1

  2. bcrypt-5digit-cracker bcrypt-5digit-cracker Public

    Educational security demo — brute-force a bcrypt hash to recover a 5-digit numeric PIN. Features a Web Worker-based in-browser cracker and a Python CLI. Clean architecture, tested.

    Python 1

  3. evidence-guardian evidence-guardian Public

    AI-native security research framework. Scans for SSRF, IDOR, XSS, SQLi, open redirect, and more — every finding carries a reproducible evidence chain with PoC scripts. 9 free AI providers, 17 tests.

    Python 1

  4. sigma-lab sigma-lab Public

    Sigma detection lab — 4 detection rules (auth brute-force, impossible travel, SSRF probe, data exfiltration) with a green-check harness that proves each rule fires against real simulation data.

    Python 1

  5. 01-devsecops-pipeline 01-devsecops-pipeline Public

    DevSecOps CI/CD pipeline as code — Gitleaks, Semgrep, Trivy, tfsec on every push/PR. Cross-project JWT gate proves pipeline + auditor work together. GitHub Actions + Docker.

    Python

  6. one-mind one-mind Public

    Shared memory layer for AI agents — SQLite + threaded HTTP daemon + MCP server. BM25 retrieval, provenance tracking (agent_id), garbage collection. Pluggable architecture, 40+ tests, zero external …

    Python 1