Cybersecurity practitioner building offensive security tooling, writing deep technical breakdowns of real-world attacks, and documenting the craft on YouTube for a practitioner audience.
I'm Mahi, operating as Mahisec — a security practitioner who spends most days somewhere between the terminal and the text editor. My work sits at the intersection of building (scanners, WAFs, detection tooling) and explaining (breaking down real attack chains for other practitioners).
I write long-form technical content covering everything from Active Directory attack paths to supply-chain compromise post-mortems, and I run tooling projects that go from crawler to dashboard — because understanding a vulnerability class properly usually means building something that finds it.
Working primarily in Python, TypeScript, and whatever the target application is written in.
A multi-module Python security platform: crawler, XSS/SQLi scanners, directory brute-forcer, and a header checker feeding a regex-based WAF engine with rate limiting and IP blacklisting. Ships with a Flask REST API, SQLite models, PDF reporting, and a dark-themed dashboard with real-time SSE scan streaming across every module.
A full-stack resume builder with a heuristic ATS scoring engine, live PDF export, and state persisted client-side. Built to help candidates understand and beat applicant tracking systems rather than guess at them.
Two iterations of a portfolio/channel site: a bento-grid cyberpunk build, then a full neon-noir redesign with an animated rain canvas, live clock, and scanline texture — the same visual language this page is built in.
How SUNBURST moved through a trusted build pipeline into thousands of networks — and what it means for how we trust our dependencies.
Kerberoasting through AD CS ESC1, worked through with Impacket, Mimikatz, Certipy, BloodHound, and CrackMapExec.
What actually separates a junior analyst from someone a red team wants on call — and none of it's on the certification syllabus.
Walkthroughs, tool builds, and attack breakdowns for a practitioner audience — the same work that ends up in the write-ups, shown as it happens.