Web Penetration Tester & Bug Bounty Hunter with Full-Stack Development depth — blending an attacker's mindset with an engineer's craft to build and break secure systems.
$ nmap -sC -sV target.io PORT STATE SERVICE 80/tcp open http 443/tcp open https 8080/tcp open http-proxy FOUND 2 misconfigs $ ./sahmiye --auto-report → generating assessment PDF... ✔ done.
Blending offensive security expertise with production-grade software engineering.
Offensive-security-focused Full-Stack Developer and Web Penetration Tester with a Bachelor's degree in Computer Science.
Hands-on experience across web application penetration testing, bug bounty hunting, vulnerability research, and security automation. I combine strong software engineering skills (MERN stack, Django) with a practical, attacker's understanding of web security — enabling both the design of secure systems and the discovery of exploitable weaknesses within them.
I build custom offensive tooling — reconnaissance frameworks, vulnerability scanners, and automated reporting pipelines — that streamline the entire pentest and bug bounty workflow, and I've authored five technical books making cybersecurity accessible to Somali-speaking learners.
The domains I operate in every day — from reconnaissance to responsible disclosure.
Vulnerability assessment and exploitation across modern web applications.
Vulnerability research, responsible disclosure and real-world exploitation.
Custom tooling and pipelines that automate the entire assessment workflow.
Passive and active reconnaissance, subdomain enumeration, asset discovery.
Production-grade applications with the MERN stack and Django.
Network scanning, threat analysis and defensive techniques (CCNA fundamentals).
AWS foundations, secure deployment practices and cloud threat modeling.
Security knowledge sharing — 5 published books for Somali learners.
The languages, frameworks and offensive tools I deploy daily.
Production-grade offensive tooling and platforms I've designed and shipped.
Full web security scanning platform that identifies vulnerabilities, detects misconfigurations and generates professional vulnerability reports.
Passive intelligence-gathering tool aggregating data from crt.sh, AlienVault and HackerTarget — zero active scanning, stealthy profiling.
Local-first, zero-footprint analyzer for HTTP, TLS, CORS and CSP security headers — no login required, leaves no external trace.
Full-featured point-of-sale system with transaction processing and real-time inventory management.
View on GitHub →Interactive cybersecurity handbook teaching web pentesting fundamentals with exercises.
View on GitHub →Profiles targets and generates comprehensive pentesting guides using passive reconnaissance.
View on GitHub →Somali-language site teaching Nmap with a built-in interactive terminal for practice.
View on GitHub →Web-based chatbot using natural language processing for intelligent interactions.
View on GitHub →Student Management System (Django/MySQL), Library System (Java), Food Order System (C#).
View on GitHub →Machadyo tababaro (Training Platforms) oo af Somali ku qoran — waxay ku siiyaan ardayda fursad ay kaga shaqeeyaan tools-ka dhabta ah iyo caqabadaha CTF (Capture The Flag).
Platform dhammaan-tirta XSS — waa qaaliyooyin CTF ah oo lagu tababbaro qorista JavaScript-ka sharci-darro ee browser-ka, min bilow ilaa horumar.
Arag →Laboratories SQL Injection oo maxalli ah — adeegsiga tools-ka sida sqlmap iyo taranka sql-ga si aad u tababbarto farsamooyinka jeexitaanka saldhigyada xogta.
Arag →Platform lagu baranayo JWT (JSON Web Tokens) — sida loo tijaabiyo signature-bypass iyo authentication bypass iyadoo la adeegsanayo tools-ka JWT.
Arag →Caqabado CTF ah oo lagu tababbaro SSRF iyo XXE — adeegsiga tools-ka iyo exploitation-ka dhabta ah si loo dhex maro difaaca server-ka.
Arag →Path Traversal iyo IDOR labs — caqabado dhab ah oo CTF ah oo leh flags, si aad u tababbarto farsamooyinka gelitaanka xogta aan la fasixin.
Arag →Nidaam OS-ka browser-ku-salaysan ee simulates hacking — waxaad ku shaqeysaa terminal-ka iyo deegaannada labs-ka si aad u tababbarto tools-ka Linux-ka.
Arag →Platform dib-u-celinta cybersecurity-ka oo af Somali — wuxuu daboolayaa aasaaska amniga si loo xoojiyo aqoonta ka hor CTF-ga.
Arag →Platform dib-u-celinta shabakada CCNA oo af Somali — aasaas xagga networking-ka iyo tools-ka shabakadda loo baahan yahay tababbarka.
Arag →Five technical books making cybersecurity and networking accessible to Somali-speaking learners. Access them on Telegram →
Verifiable credentials and the academic path that sharpened my edge.
Modern bug bounty methodologies, vulnerability research, responsible disclosure, and practical web app security.
Verify ↗Cloud security fundamentals, AWS architecture, and secure deployment practices.
Verify ↗Advanced cloud security, threat modeling, and secure infrastructure management.
Verify ↗Reconnaissance methodologies for bug bounty hunters, pentesters and researchers.
Verify ↗Version control mastery — workflows, branching and CI/CD fundamentals.
Verify ↗Cybersecurity fundamentals, threat modeling, vulnerability analysis and defensive security techniques.
● Currently PursuingEthical hacking methodology — reconnaissance, scanning, exploitation and professional vulnerability reporting.
Full-stack web development — MongoDB, Express.js, React, Node.js — building scalable production applications.
Software engineering, algorithms, data structures, networking, databases and IT systems.
Open to security engagements, bug bounty collaborations, or full-stack development opportunities. My inbox is always open.