// Hello, I'm

Mohammed Al-Balushi

AI Security Developer and Cyber Operations Specialist

Open to Opportunities — Cyber Security and AI Developer

B.Tech in IT Cyber and Information Security from UTAS Muscat. Specialist in Agentic AI Development, Security Operations, and Linux Infrastructure. Certified Junior Penetration Tester.

Mohammed Al-Balushi

Featured Security and AI Projects

Tier 1: AI Pentest

MADFA Autonomous AI Pentesting Framework

Multi-agent AI pentesting platform featuring custom ChainAST token compression algorithm, token cost reduction, faster recon discovery, and dynamic ephemeral Docker container sandboxing for security tool execution.

Go React pgvector Docker SDK ChainAST
Tier 1: AI Defense

SOC-assist Local SIEM Alert Sanitizer

Privacy-first SIEM log sanitizer enforcing local regex tokenization prior to LLM processing. Features an interactive Rich TUI analyst workbench, pre-export secret scanner, and shift handover purge.

Python Local LLM Textual TUI SIEM Operations Zero Telemetry Leakage
Tier 2: SOC and SIEM

Splunk SIEM and Active Directory Lab

Enterprise Active Directory threat emulation lab mapping Sysmon telemetry to MITRE ATT&CK TTPs. Captured failed authentication spikes Event 4625 and built custom endpoint security monitors.

Splunk SIEM Active Directory Sysmon Threat Emulation
Tier 3: ZTNA and Edge

Cloudflare Zero Trust and NetBird ZTNA Mesh

Designed and deployed enterprise-grade Zero Trust Network Access using Cloudflare tunnels and WARP client enrollment, eliminating public facing inbound ports. Integrated DNSSEC protected domain routing with an automated Nginx reverse proxy deployment pipeline.

Cloudflare Tunnel NetBird ZTNA WireGuard Mesh Nginx CI/CD Zero Public Ports
Tier 4: DevOps and Tools

XScp and WTF Launcher Host-Safe Sandbox

Cross-platform CLI TUI file transfer manager XScp and modular Bash console wrapping offensive tools into disposable host-safe Kali Linux Docker runtimes with sub-second container spin-up time.

Python TUI Docker Compose Bash Automation Host-Safe Sandbox
Tier 5: Pentesting

TryHackMe Verified Profile and Writeups

Verified TryHackMe profile holding the Junior Penetration Tester certification and Advent of Cyber badge. Completed hands-on labs in Active Directory exploitation, web security, and privilege escalation.

Jr PenTester Cert TryHackMe Profile Advent of Cyber Active Directory OWASP Top 10

Experience and Education

Professional Experience

320 Operational Training Hours

Cybersecurity and SOC Analyst Trainee

Information Technology and Cybersecurity Department

Conducted daily SIEM security monitoring, log auditing, threat detection, and incident response triage. Assisted in analyzing intrusion alerts, evaluating security controls, and refining containment procedures. Presented local AI triage framework to security leadership.

Education and Certifications

University Graduate

B.Tech in IT Cyber and Information Security

University of Technology and Applied Sciences Muscat

Rigorous coursework and research capstones in network security, system hardening, software development, OT protocol security, and IoT security integration.

Verified Certifications

10 Verified Industry Certifications

Cisco Networking Academy, TryHackMe, Simplilearn

1. Cybersecurity Internship Certificate
2. Cisco Cyber Threat Management
3. Cisco CCNA Enterprise Security and Automation
4. Cisco Network Security
5. Cisco Linux 1
6. Cisco CCNA Switching and Routing
7. Cisco IoT Fundamentals
8. TryHackMe Junior Penetration Tester Certified
9. TryHackMe Advent of Cyber
10. Simplilearn Introduction to CISSP

5-Tier Skills Matrix

Tier 1: Agentic AI and Defense Automation

Go Goroutines and Channels Python and Textual TUI Local Ollama LLM Engines pgvector Vector DB ChainAST Token Compression Regex Prompt Sanitization

Tier 2: Security Operations and Threat Intel

Splunk Enterprise SIEM Sysmon Event Analysis Cyber Threat Intelligence Static Ransomware Analysis Incident Response Triage CIS Controls and ISO Standards

Tier 3: Linux Systems and ZTNA Networking

Linux Administration Fedora Ubuntu Debian Cloudflare Zero Trust Tunnels NetBird ZTNA WireGuard Mesh KVM QEMU Virt-Manager LVM Storage and Partitioning Systemd and Bash Automation

Tier 4: DevOps and Container Infrastructure

Docker SDK and Docker Compose VPS CI/CD Deployment Nginx Reverse Proxy Git and GitHub Actions OpenSSH Key Authentication REST and GraphQL APIs

Tier 5: Targeted Penetration Testing and Web Security

TryHackMe Jr PenTester Certified Active Directory Attacks Kerberoasting BloodHound AD Enumeration OWASP Top 10 Web Security Metasploit and Nmap Hydra and GoBuster
Linux Linux
Docker Docker
Python Python
Bash Bash
GitHub GitHub
Kali Linux Kali Linux
JavaScript JavaScript
Linux Linux
Docker Docker
Python Python
Bash Bash
GitHub GitHub
Kali Linux Kali Linux
JavaScript JavaScript