Skip to content
View MahdiAlemi's full-sized avatar

Block or report MahdiAlemi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
MahdiAlemi/README.md

Mahdi Alemi Offensive Security

Offensive Security Terminal
Mahdi Alemi System Operational Authorized Only



WEB SECURITY  •  NETWORK SECURITY  •  RESEARCH  •  AUTOMATION


mahdi@offsec:~$ whoami

NAME      : Mahdi Alemi
ROLE      : Web & Network Pentester
CLASS     : Security Researcher
STATUS    : Operational
MISSION   : Break · Analyze · Build · Share

mahdi@offsec:~$ _

// COMMAND CENTER

IDENTITY NODE

identity: Mahdi Alemi
role: Web & Network Pentester
class: Security Researcher
status: Operational
Identity Verified Online

PRIMARY MISSION

objectives:
  - Break
  - Analyze
  - Build
  - Share

I break systems
to understand them.

OPERATING MODE

mode: Offensive Security
scope: Authorized Targets
focus:
  - Research
  - Validation
  - Automation
Recon Mode Authorized Scope

// ACTIVE OPERATIONS

CURRENT SECURITY RESEARCH AND ENGINEERING WORKLOAD

OP-01

Web Research



Web vulnerability research



STATUS: ACTIVE

OP-02

Network Mapping



Network attack-surface mapping



STATUS: ACTIVE

OP-03

Recon Automation



Recon workflow automation



STATUS: ACTIVE

OP-04

Security Tooling



Security tool development



STATUS: BUILDING

OP-05

Technical Documentation



Technical documentation



STATUS: ACTIVE


// ATTACK SURFACE

PRIMARY OFFENSIVE SECURITY CAPABILITIES



Web Pentesting Network Security Reconnaissance Exploit Research Python Automation



VULNERABILITY CLASSES

XSS SQL Injection Remote Code Execution IDOR API Security Authentication Bypass CSRF CORS LFI RFI File Upload

// OFFENSIVE OPERATION LIFECYCLE

flowchart TD
    A["◉ AUTHORIZED TARGET"] --> B["01 // RECONNAISSANCE"]

    B --> C["02 // ENUMERATION"]

    C --> D["03 // ATTACK-SURFACE ANALYSIS"]

    D --> E{"VULNERABILITY<br/>IDENTIFIED?"}

    E -->|NO| B

    E -->|YES| F["04 // CONTROLLED VALIDATION"]

    F --> G["05 // IMPACT ANALYSIS"]

    G --> H["06 // DOCUMENTATION"]

    H --> I["07 // AUTOMATION & TOOLING"]

    I --> J["◉ RESPONSIBLE SHARING"]

    classDef terminal fill:#020202,stroke:#00ff88,color:#eafff3,stroke-width:3px
    classDef operation fill:#07150f,stroke:#00ff88,color:#eafff3,stroke-width:2px
    classDef decision fill:#003c27,stroke:#00ff88,color:#ffffff,stroke-width:3px

    class A,J terminal
    class B,C,D,F,G,H,I operation
    class E decision
Loading

RECONENUMERATIONVALIDATIONANALYSISDOCUMENTATIONAUTOMATION


// FEATURED INTELLIGENCE FILE

┌────────────────────────────┐
│  INTELLIGENCE FILE         │
├────────────────────────────┤
│  CODE: EXPLOITOLOGY-WEB    │
│  TYPE: SECURITY BOOK       │
│  DOMAIN: WEB APPLICATIONS  │
│  SIZE: 609 PAGES           │
│  STATUS: AVAILABLE         │
└────────────────────────────┘
Declassified File

Exploitology: Web Apps Exploits

A practical offensive security reference focused on web application vulnerabilities, exploitation concepts and real-world scenarios.


609 Pages Real World Scenarios



COVERED ATTACK VECTORS

XSS SQL Injection RCE CSRF CORS Authentication Bypass LFI RFI File Upload



Access Exploitology

// LEGACY VAULT

ARCHIVED SOURCE-CODE NODE

╔══════════════════════════╗
║       LEGACY NODE        ║
╠══════════════════════════╣
║ ACCESS       : DENIED    ║
║ RECOVERY     : LOCKED    ║
║ REPOSITORIES : ONLINE    ║
║ SOURCE CODE  : ALIVE     ║
╚══════════════════════════╝

The original GitHub account is no longer accessible for management.

Its repositories, source code and previous security research remain publicly available as a legacy archive.


Access Denied Recovery Locked Repositories Online Source Code Alive



Lost the account.
Not the code.


Open Legacy Repositories

// SECURE COMMUNICATION CHANNELS

ESTABLISHING ENCRYPTED CONNECTION...



LinkedIn Email Leanpub



[01] RECON        ██████████ ONLINE
[02] ANALYZE      ██████████ ONLINE
[03] VALIDATE     ██████████ ONLINE
[04] DOCUMENT     ██████████ ONLINE
[05] AUTOMATE     ██████████ ONLINE
[06] SHARE        ██████████ READY

Recon Analyze Validate Automate Share



AUTHORIZED SECURITY RESEARCH ONLY

All security testing and research must be conducted with explicit authorization and within a clearly defined scope.



Footer

Pinned Loading

  1. secpath-radar secpath-radar Public

    Rust

  2. secpath-proxypool secpath-proxypool Public

    Python

  3. secpath-status secpath-status Public

    A self-hosted status page platform powered by GitHub Actions and GitHub Pages

    Python