Mustapha Tamime
Cybersecurity & Network Specialist | IT Technician | Law Student
Profile
IT Technician at a Judicial Council and IT Administrator at a Bar Association in Sidi Bel Abbès, Algeria, and a second-year law student. Self-taught cybersecurity learner working toward freelance-ready offensive security and red teaming within two years, combining hands-on network administration, legal knowledge, and practical security training. Skills Olympics bronze medalist and national CTF hackathon participant, with hands-on exposure to Wi-Fi security testing, pfSense, Windows Server, privilege escalation, and MITM labs.
Experience
IT Technician
Judicial Council — Sidi Bel Abbès, Algeria
Current
- Manage IT infrastructure and technical support for judicial institution operations
- Administer internal networks, workstations, and institutional systems
IT Administrator
Bar Association (Ordre des Avocats) — Sidi Bel Abbès, Algeria
Current
- Administer all IT systems and infrastructure for the Bar Association
- Built and deployed Nizam — a full Arabic court-session management system actively used by the organization
- Manage lawyer records, session scheduling, financial tracking, and document generation
Cybersecurity Trainer
Langue Land School — Sidi Bel Abbès, Algeria
- Teach the "Foundation to Cybersecurity" course covering networking fundamentals, threat landscape, and practical security concepts
Featured Projects
SECURITY TOOL
ShellForge — Reverse / Bind / Web Shell Payload Generator
- Python CLI tool generating payloads across 15+ languages: bash, Python, PowerShell, Java, C#, C, Go, PHP, ASP, JSP, Perl, Ruby, Lua, AWK
- Interactive menu mode (
-m) + full flag-based CLI with built-in encoders (base64, URL-encode, PowerShell -EncodedCommand) - Listener helper: nc, rlwrap, socat, msfconsole multi/handler — tested end-to-end on Kali + Windows lab
- 59 passing pytest tests — modular ABC architecture, MIT licensed
Python · argparse · rich · pytest · github.com/anounymous68/ShellForge-
BLUE TEAM
ARGUS — Linux Privilege Escalation Monitor
- Continuously-running daemon detecting Linux privilege escalation vectors in real time with Telegram alerting
- Hybrid detection: poll-based SUID/SGID inventory + watchdog-based sudoers/cron monitoring
- Hash-based SQLite baseline diffing to eliminate alert fatigue; rate-limited alerting with overflow batching
- Tested end-to-end on Kali VM — detection, diffing, and Telegram delivery confirmed working
Python · asyncio · SQLite · watchdog · Telegram Bot API
WEB SECURITY LAB
Web App Pentest Lab
- Hands-on labs: SQLi, XSS — each folder contains overview, training notes, runnable vulnerable code, PoC with real output, and mitigation
- Built while progressing through TryHackMe's Jr. Penetration Tester path toward PJPT
PHP · Python · HTML/JS · github.com/anounymous68/web-pentest-lab
CTF
CTF Write-ups
- Bashed, Basic Pentesting 1 & 2, Mr. Robot, Simple CTF (CVE-2019-9053 blind SQLi), Copy Fail (CVE-2026-31431)
- Each write-up covers enumeration → exploitation → privilege escalation → lessons learned
Nizam (نظام إدارة الجلسات) — Court Session Management System
- Single-file Arabic web app for Algerian judicial institutions: session scheduling, financial module, inventory, multi-court support, Arabic PDF generation, PWA/Android packaging
Hajzli (حجزلي) — Flutter Barber Booking Platform
- Mobile app for barber appointment booking in Algeria — queue management, FCM notifications, OpenStreetMap
- Flutter/Dart · Firebase · Firestore · FCM · OpenStreetMap — prepared for Google Play
Dépannini — Flutter Roadside Assistance App
- Mobile app connecting drivers with roadside assistance providers; Firebase auth/Firestore, OpenStreetMap + OSRM routing
Technical Skills
Networking
Offensive Security
Infrastructure
Development
Legal & Domain
Certifications
CCNA — Intro to Networking (Cisco)
CCNA — Switching, Routing & Wireless
Cisco Ethical Hacker
ISC2 CC
FortiManager 7.6 Administrator
Fortinet Certified Fundamentals Cybersecurity
ISC2: Network Security
ISC2: Incident Response & BCDR
ISC2: Access Control Concepts
ISC2: Security Principles
TryHackMe Cyber 101
Security+ (Cybrary)
PJPT — TCM Security (in progress)
Achievements & CTF
1st Place — Skills Olympics 2025, Wilaya Level
Wi-Fi security testing, WPA cracking, and security policy setup
3rd Place — Skills Olympics Regional, Northwest Algeria
pfSense, NAT, VPN, Windows Server 2022, Active Directory, DNS, DHCP, GPO
National CTF Hackathon — Participant
Attack methodology, enumeration, and problem solving under time pressure
TryHackMe Practical Labs
Privilege escalation, Metasploit, MITM with Bettercap, GTFOBins, Dirty COW (CVE-2016-5195), SUID, cron abuse, PATH hijacking
Education
Law Student — 2nd Year
Faculty of Law & Political Science, Djilali Liabes University — Sidi Bel Abbès
Current
Languages
Arabic — Native
English — Fluent
French — Professional