number_tracker
Phone number OSINT tool for location and activity analysis. Geolocates numbers and extracts carrier metadata for investigations.
"Most see a locked door.
I see twelve ways in,
and thirteen ways to make it unbreachable."
Hello, I'm
Attack to defend. Break to understand. Secure to protect.
Security Engineer with hands-on experience in penetration testing, vulnerability management, and security operations. Skilled at identifying exploitable weaknesses in web applications and infrastructure, and working closely with engineering teams to implement practical, lasting remediation.
Currently driving AppSec initiatives, contributing to ISO 27001:2022 certification and securing production environments through rigorous testing and hardening. My philosophy: fully understand the attacker's mindset to architect stronger defenses.
When I'm not poking around systems, I'm building open-source security tools, writing CVE walkthroughs, and contributing to the security community.
$ whoami
phinehas_narh
$ cat philosophy.txt
"Attack to defend. Break to build."
$ ls ./expertise/
pentest appsec soc iam devsecops
$ _
Phone number OSINT tool for location and activity analysis. Geolocates numbers and extracts carrier metadata for investigations.
Python backend for ingesting, processing, and visualizing cyber threat intelligence feeds. Supports structured CTI formats with a JS visualization layer.
Browser-based device trust scoring tool that evaluates client-side security posture and assigns risk scores for zero-trust access decisions.
Full incident response walkthrough for the PHP CGI argument injection zero-day. Covers attack chain, CVSS analysis, and mitigation controls.
Versatile port scanning tool built for penetration testing workflows. Fast, configurable, and outputs structured scan reports for analysis.
USB security tool that monitors, logs, and controls device access events in real-time, providing audit trails for endpoint security enforcement.
File integrity monitoring tool that detects unauthorized changes and triggers notifications, supporting host-based intrusion detection workflows.
Five enterprise network topologies with defense-in-depth controls, IPsec VPN tunnels, WPA3, and RBAC across 100+ concurrent device environments.
A collection of personal penetration testing engagements. Covers CVE exploitation, authentication bypass on legacy systems, CVSS-scored findings, and stakeholder-ready pentest reports with compensating controls.
Self-sourced contributions to reputable security and infrastructure projects: real bugs, new detections, and hardening fixes. Every change is one I reviewed, tested, and can defend end to end, with AI assistance disclosed wherever a project's policy asks for it.
Added complete type coverage to cloudinit.distros.parsers.hosts and removed the module from cloud-init's mypy override, advancing the project's long-running static-typing initiative (issue #5445). Worked through four rounds of maintainer review, a merge conflict, mypy fallout on the test module, and CLA sign-off before it was merged by a Canonical maintainer.
A target model could forge a Rating: [[1]] block in its own output and make garak's model-as-judge score a genuine jailbreak as safe. Sanitised the judge input and anchored scoring on the judge's own final verdict. Confirmed against a live judge; 9 regression tests.
Closed a detector-evasion gap: fullwidth homoglyphs and zero-width characters let dangerous model output slip past garak's byte-level string matching. Added optional NFKC normalization with format-character stripping, backward compatible by default. 17 tests.
Added detection rules for Groq (gsk_…) and xAI (xai-…) API keys to the gitleaks scanner, with verified key formats, true and false-positive test cases, and a regenerated ruleset config.
Added CKV_AWS_394 to close a real false negative: a Secrets Manager resource policy granting GetSecretValue to any principal (Principal: *) was silently passing. Modeled on the existing any-principal checks with full pass/fail Terraform fixtures.
Fixed an AttributeError traceback thrown on every Linux wireless-scan event in debug mode, where the netlink layer called .decode() on a list of NLA cells. Five-line isinstance guard with unit tests, for an issue that had sat open 14 months.
Fixed a tar-slip path traversal (CWE-22) in mlrun's project/source download: a malicious .tar.gz extracted with an unfiltered extractall() could write files outside the target directory. Routed extraction through the project's own safe helpers with a member pre-flight and guaranteed temp-file cleanup, plus regression tests. Merged after a maintainer code-review, which included empirically disproving one of its findings.
Discovered and confirmed a stored cross-site scripting vulnerability in a widely-used open-source infrastructure dashboard, with a working proof-of-concept built against the project's real code paths. Handled through responsible disclosure, so specifics are withheld here until a fix ships.
Identified a defense-in-depth gap in an open-source SOAR platform: database-level tenant isolation (Postgres row-level security) was disabled by default, leaving cross-workspace isolation dependent on application checks alone. Documented as a hardening advisory with remediation guidance, handled through responsible disclosure.
Found and confirmed a privilege-escalation to server-side remote code execution in a self-hosted backup tool: a low-privilege role could smuggle an argument into a wrapped command-line tool and run commands on the host. Verified with a working proof-of-concept against the tool's real code path. Handled through responsible disclosure, so specifics are withheld until a fix ships.
A growing library of CVE walkthroughs, each with a written analysis, a detection script, an exploit reference, and incident-response notes. Spans high-impact CVEs including Log4Shell, the XZ Utils backdoor, and PHP-CGI argument injection across web, network, and infrastructure targets.
A full incident-response reconstruction of the PHP-CGI argument-injection zero-day (CVE-2024-4577): tracing the attack from IDS/IPS alerts through Apache logs, timeline analysis with PECmd and Timeline Explorer, and remediation guidance, with exploit specifics deliberately omitted.
Core security competencies in threats, vulnerabilities, architecture, implementation, and incident response.
Digital evidence acquisition, forensic analysis, and incident reconstruction across host and storage media.
Hands-on web application penetration testing: identifying and exploiting real-world vulnerabilities across the OWASP Top 10 and beyond.
Security monitoring, log analysis, incident triage, and threat intelligence within SOC environments.
AWS shared responsibility model, cloud security controls, and architecture best practices.
Network infrastructure security, routing protocols, switching, and network access control implementation.
IT service management principles aligned with business continuity and risk management objectives.
Qualified to plan, conduct, and lead ISMS audits per ISO/IEC 27001:2022 auditing guidelines.
Currently open to new opportunities and collaborations. Whether you have a project, a role, or just want to talk security, my inbox is open.