Mazin Ahmed

Senior Application Security Engineer II

Vancouver, British Columbia, Canada
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Mazin Ahmed is a cyber security engineer and founder with 11 years of hands-on experience across application, infrastructure, and offensive security. He built and leads FullHunt, an attack-surface discovery and monitoring platform used by thousands of security professionals, and previously shaped security programs at ProtonMail and Namshi. Equally comfortable in defensive engineering and red-team tooling, he authors practical open-source projects like a Firefox penetration-testing toolkit and an automated Log4j scanner that demonstrate a focus on automation and real-world exploit detection. A frequent conference speaker (DEFCON, BlackHat, HITB and others), he combines security research with product-building instincts and a knack for turning hobbyist curiosity into scalable, production-grade solutions.
code11 years of coding experience
job6 years of employment as a software developer
bookBachelor degree, Computer Science, Bachelor degree, Computer Science at The Future university
bookWeb-Development Languages, Web-Development Languages at Code Academy
bookSt. Catharine's Collegiate
languagesArabic, English
github-logo-circle

Github Skills (15)

web-security10
bash10
penetration-testing10
log4j10
scanning10
python10
scripting10
vulnerability-scanners10
security10
dns9
wget9
api8
apim8
github-ci6
githubaction-workflow6

Programming languages (12)

TypeScriptJavaShellC++CJavaScriptGoPHP

Github contributions (5)

github-logo-circle
A tool that transforms Firefox browsers into a penetration testing suite
Role in this project:
userSecurity Engineer
Contributions:14 commits, 6 PRs, 15 pushes in 4 years 5 months
Contributions summary:Mazin's commits primarily focused on creating a tool that transforms a Firefox browser into a penetration testing suite. They wrote a Bash script that automates the download and installation of various security-related Firefox add-ons such as HackBar, Wappalyzer, and Foxy Proxy. The script also includes features to download Burp Suite certificates, enhancing the browser's security capabilities. The user consistently updated the script, releasing versions with added add-ons and features reflecting the tool's evolution.
firefox-browserpenetration-testing
fullhunt/log4j-scan

Dec 2021 - Oct 2022

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
Role in this project:
userBack-end Developer & Security Engineer
Contributions:2 releases, 6 reviews, 62 commits in 10 months
Contributions summary:Mazin primarily contributed to the security and functionality of the log4j-scan tool. Their commits added new features such as the integration of DNS callback providers, including Interact.sh, for vulnerability detection. They refactored proxy setup, and added a disable redirects option, and implemented testing and payloads for CVE-2021-45046 and CVE-2022-42889, enhancing the tool's effectiveness in identifying and exploiting Log4j vulnerabilities. Furthermore, they made code adjustments to improve the tool's usability, such as rstrip lines when reading file input and fixing a bug with the wait time.
cvelog4jrce
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial