mustapha@portfolio:~$ whoami --full

Mustapha Tamime

TitleCybersecurity & Network Specialist | IT Technician | Law Student
LocationSidi Bel Abbès, Algeria
StatusOffensive security learner / red team path

Building practical security labs, judicial IT systems, and field-ready infrastructure skills with a terminal-first mindset.

guest@mt:~$

try: help · whoami · skills · projects · contact · clear

profile.init()

About

Mustapha is an IT Technician at a Judicial Council and IT Administrator at a Bar Association in Sidi Bel Abbès, Algeria. He is also a second-year law student at the Faculty of Law and Political Science.

He is a self-taught cybersecurity learner focused on becoming freelance-ready in offensive security and red teaming within two years, combining hands-on network administration, legal knowledge, and practical security training.

He is a Skills Olympics bronze medal winner and a national CTF hackathon participant, with practical exposure to Wi-Fi security testing, pfSense, Windows Server, privilege escalation, and MITM labs.

[mission] Build discipline, sharpen exploitation methodology, document everything.

cat /var/log/experience.log

Experience

Current Judicial Council — Sidi Bel Abbès

IT Technician

  • Manage IT infrastructure and technical support for judicial institution operations
  • Administer internal networks, workstations, and institutional systems
Current Bar Association (Ordre des Avocats) — Sidi Bel Abbès

IT Administrator

  • Administer all IT systems and infrastructure for the Bar Association
  • Built and deployed Nizam — a full Arabic court-session management system actively used by the organization
  • Manage lawyer records, session scheduling, financial tracking, and document generation
Current Langue Land School — Sidi Bel Abbès

Cybersecurity Trainer

  • Teach the "Foundation to Cybersecurity" course covering networking fundamentals, threat landscape, and practical security concepts
In progress Djilali Liabes University — Faculty of Law & Political Science

Law Student — 2nd Year

  • Algerian criminal procedure law, administrative law, and legal systems
  • Combines legal knowledge with IT security for cybercrime and judicial IT compliance

skills.enumerate --verbose

Skills

mustapha@skills:~$ ./print_capabilities.sh

networking.txt

LAN/WANDHCPDNSNATVPNGNS3Packet TracerpfSenseFortiGate

security-offensive.txt

NmapMetasploitWiresharkSnortBettercapKali LinuxMITM attacksPrivilege escalationCTFOSINTTryHackMe Jr Penetration Tester path

endpoint-infrastructure.txt

Windows Server 2022Active DirectoryGPOUbuntu ServerKaspersky EDRFortiManagerIDS/IPSFirewall configVMware Workstation

development.txt

HTML/CSS/JSFlutter/DartPythonFirebaseOpenStreetMapREST APIs

law-administration.txt

Algerian criminal procedure lawAdministrative lawJudicial IT administration

ls -la /projects

Projects

[01] Nizam — نظام إدارة الجلسات

Court Session Management System for Algerian judicial institutions. Single-file Arabic HTML/JS/CSS application, v19+.

  • Session scheduling and management
  • Financial module with credit/deferred payment system
  • Inventory management for stamps and paper
  • TV display mode with themes and emergency overlay
  • Multi-court support for محاكم / مجالس القضاء
  • Lawyer profile management with XLS import
  • VCF contact export and AI assistant for phone lookups
  • PWA / Android packaging with Capacitor
  • Arabic PDF generation through Canvas rendering

Tech: Pure HTML/CSS/JS, localStorage, jsPDF, SheetJS

[02] Dépannini — Flutter Roadside Assistance App

Mobile app connecting drivers with roadside assistance providers.

  • Firebase authentication and Firestore data layer
  • OpenStreetMap display with flutter_map
  • OSRM routing engine integration
  • Netlify landing page and MediaFire APK distribution

Tech: Flutter/Dart, Firebase, OpenStreetMap, flutter_map, OSRM

[03] Linux PrivEsc Lab — GitHub PoC

Educational privilege escalation lab for cybersecurity learning.

  • SUID/SGID abuse with vulnerable binary and exploit script
  • Sudo misconfiguration: NOPASSWD, env_keep, LD_PRELOAD
  • Cron job hijacking and PATH hijacking
  • Manual enumeration script with linpeas-style checks
  • Each module includes setup.sh, exploit.sh, and README

Tech: Bash, Linux permissions, vulnerable lab design

[04] Langue Land Certificate Generator

Professional certificate generator for a language school, supporting five languages with Arabic text rendering.

  • Canvas-based certificate rendering
  • Multilingual layout support
  • Browser-only generation workflow

Tech: HTML/CSS/JS, Canvas API

[05] Legal Case Management System

In-progress full-stack system designed for VPS deployment on Algérie Télécom infrastructure.

  • Backend API planned with FastAPI
  • React web interface
  • Flutter companion app direction

Tech: FastAPI, React, Flutter

[06] PDF Document Processing Tools

Automation tools for document overlays, delivery notes, form filling, and manipulation.

  • PDF overlays for employment contracts
  • Delivery note automation
  • Form filling and manipulation workflows

Tech: Python, pypdf alternatives

[08] Web App Pentest Lab

Hands-on web vulnerability labs built while progressing through TryHackMe's Jr. Penetration Tester path toward PJPT-level web application testing.

  • SQL Injection (SQLi) — detection, exploitation, and mitigation with runnable vulnerable code
  • Cross-Site Scripting (XSS) — reflected, stored, DOM-based variants with PoC outputs
  • Each folder: overview, training notes, detection methodology, real command output, mitigation
  • Structure mirrors the Linux PrivEsc lab repo: one folder per technique

Tech: PHP, Python, HTML/JS · github.com/anounymous68/web-pentest-lab

[09] CTF Write-ups

Documented write-ups for completed TryHackMe and HackTheBox machines — each covering full exploitation path from enumeration to root.

  • Bashed, Basic Pentesting 1 & 2, Mr. Robot, Simple CTF (CVE-2019-9053 blind SQLi)
  • Copy Fail — CVE-2026-31431 Linux kernel AF_ALG / splice() research
  • Each write-up: enumeration → exploitation → privilege escalation → lessons learned

github.com/anounymous68/write-ups-CTF

[10] ARGUS — Linux Privilege Escalation Monitor

Continuously-running blue-team daemon that detects Linux privilege escalation vectors in real time and alerts over Telegram — not a linPEAS clone, an always-on monitor.

  • Hybrid detection: polling for SUID/SGID inventory, real-time watchdog-based monitoring for sudoers and cron
  • Hash-based baseline diffing in SQLite — only genuinely new findings alert, eliminating alert fatigue
  • Rate-limited Telegram alerting with automatic overflow batching
  • Tested end-to-end on a live Kali Linux VM: SUID detection, baseline diffing, and Telegram delivery confirmed working
  • Dry-run mode, rotating logs, and a documented threat model / limitations section

Tech: Python, asyncio, SQLite, watchdog, Telegram Bot API

cat certifications.log

Certifications

Completed

  • FortiManager 7.6 Administrator
  • Fortinet Certified Fundamentals Cybersecurity
  • CCNA Intro to Networking (Cisco)
  • Cisco Ethical Hacker
  • TryHackMe Cyber 101
  • Security+ (Cybrary)
  • ISC2 Network Security
  • ISC2 Incident Response & BCDR Concepts
  • ISC2 Access Control Concepts
  • ISC2 Security Principles
  • CCNA: Switching, Routing, and Wireless Essentials

In Progress

  • PJPT (Practical Junior Penetration Tester) — TCM Security
  • CISCO CCNA

grep -R "wins|ctf" ./history

Achievements & CTF

#1

1st Place — Skills Olympics 2025, Wilaya Level

Cyber Security & Networking: Wi-Fi security testing, WPA password cracking, and security policy setup.

#3

3rd Place — Skills Olympics Regional, Northwest Algeria

pfSense firewall, NAT, VPN, Windows Server 2022, Active Directory, DNS, DHCP, and GPO.

CTF

National CTF Hackathon — Participant

Hands-on national competition exposure with attack methodology, enumeration, and problem solving under time pressure.

LAB

TryHackMe Practical Labs

Privilege escalation, Metasploit, MITM with Bettercap, GTFOBins, Dirty COW CVE-2016-5195, SUID, cron abuse, and PATH hijacking.