Security Research // Offensive Tooling

MAHISEC

Cybersecurity practitioner building offensive security tooling, writing deep technical breakdowns of real-world attacks, and documenting the craft on YouTube for a practitioner audience.

mahi@mahisec:~
Scroll
01

About

I'm Mahi, operating as Mahisec — a security practitioner who spends most days somewhere between the terminal and the text editor. My work sits at the intersection of building (scanners, WAFs, detection tooling) and explaining (breaking down real attack chains for other practitioners).

I write long-form technical content covering everything from Active Directory attack paths to supply-chain compromise post-mortems, and I run tooling projects that go from crawler to dashboard — because understanding a vulnerability class properly usually means building something that finds it.

Working primarily in Python, TypeScript, and whatever the target application is written in.

3+
Long-form Technical Articles
15
AD Attack Techniques Documented
02
Full Tooling Platforms Shipped
Terminal Tabs Open
02

Capabilities

Offensive / AD

  • Kerberoasting & AS-REP Roasting
  • ACL abuse & AD CS (ESC1)
  • Impacket / CrackMapExec
  • Mimikatz / Certipy
  • BloodHound path analysis

AppSec Tooling

  • XSS / SQLi detection engines
  • Web crawlers & dir brute-forcing
  • Regex-based WAF design
  • Rate limiting & IP blacklisting
  • Security header auditing

Engineering

  • Python / Flask REST APIs
  • Next.js 15 / TypeScript
  • SQLite & data modeling
  • SSE real-time streaming
  • Report & PDF generation
03

Projects

01

Mahisec — Web AppSec Scanner & WAF Platform

A multi-module Python security platform: crawler, XSS/SQLi scanners, directory brute-forcer, and a header checker feeding a regex-based WAF engine with rate limiting and IP blacklisting. Ships with a Flask REST API, SQLite models, PDF reporting, and a dark-themed dashboard with real-time SSE scan streaming across every module.

PythonFlaskSQLiteSSEWAF Engine
Shipped
02

ATS Resume Builder

A full-stack resume builder with a heuristic ATS scoring engine, live PDF export, and state persisted client-side. Built to help candidates understand and beat applicant tracking systems rather than guess at them.

Next.js 15TypeScriptZustandReact-PDFTailwind
In Progress
03

Mahisec Brand Sites (v1 → v2)

Two iterations of a portfolio/channel site: a bento-grid cyberpunk build, then a full neon-noir redesign with an animated rain canvas, live clock, and scanline texture — the same visual language this page is built in.

HTML/CSS/JSCanvasCloudflare Pages
Shipped
04

Writing

The SolarWinds Supply Chain Attack: A Technical Breakdown

How SUNBURST moved through a trusted build pipeline into thousands of networks — and what it means for how we trust our dependencies.

15 Active Directory Attack Techniques (With Real Commands)

Kerberoasting through AD CS ESC1, worked through with Impacket, Mimikatz, Certipy, BloodHound, and CrackMapExec.

Cybersecurity Skills They Don't Teach You in Courses

What actually separates a junior analyst from someone a red team wants on call — and none of it's on the certification syllabus.

Security research, on camera.

Walkthroughs, tool builds, and attack breakdowns for a practitioner audience — the same work that ends up in the write-ups, shown as it happens.

Watch on YouTube →
05

Contact

mahi@mahisec:~/contact
$ whoami --contact
→ Open to research collabs, tooling contributions, and technical writing opportunities.
$ echo $STATUS
→ Available