MA-1337Mohamed Amellal
Product datasheetMA-1337-SECRev. 2026.09Morocco · UTC+1

Cybersecurity

Mohamed Amellal

Offensive security and blue team operations, from recon and exploitation to alert triage and clean write-ups.

Status: active, open to junior security roles

MA-1337 pin configuration: 28 pins covering SOC & blue team, Offensive security, Network & systems, and Frameworks. Full list in section 4.SOC & BLUE TEAMOFFENSIVE SECURITYFRAMEWORKSNETWORK & SYSTEMSMOHAMED AMELLALMA-1337 · SECURITYMOROCCO · 2638EN1SPLUNK2ELK / KIBANA3ALERT TRIAGE4LOG ANALYSIS5INCIDENT RESP6PHISHING7FORENSICS8BUG BOUNTY9WEB TESTING10BURP SUITE11METASPLOIT12SQLMAP13JOHN RIPPER14WIRESHARK15NMAP16PYTHON17BASH18LINUX19WINDOWS LOGS20MITRE ATT&CK21KILL CHAIN22OWASP TOP 1023CVSS24THREAT MODEL25DETECTION ENG26CLK27RX28
PIN 01EN · EnableHIGH: open to junior security roles
Figure 1. Pin configuration, DIP-28 top view. Hover or tap a pin.

Features

  • Offensive security and blue team operations
  • Bug bounty: recon, exploitation, and clean write-ups
  • SIEM alert triage and log analysis with Splunk and ELK
  • Incident reports with timelines and IOCs
  • Traffic analysis for C2 beacons and data exfiltration
  • Findings mapped to MITRE ATT&CK and scored with CVSS

Applications

  • SOC monitoring and alert triage
  • Incident response and phishing investigation
  • Web application security testing
  • Bug bounty and vulnerability research
  • Detection engineering from offensive findings

Key specifications

Vulnerabilities foundPublic bug bounty
20+
Web vulnerabilities exploitedDarkly
14+
Linux challenges solvedSnow Crash
10+
SOC analyst path completedTryHackMe
L1
Copyright © 2026 Mohamed AmellalSubmit document feedbackMA-1337-SEC · Page 1 of 5

Pin configuration and functions

Technical skills
Table 4-1. Pin functions (package drawing: Figure 1)
PinFunctionSignals
1ENEnableHIGH: open to junior security roles
2–8SOC & blue team
  • Splunk
  • ELK / Kibana
  • Alert triage
  • Log analysis
  • Incident response
  • Phishing investigation
  • Endpoint forensics
  • Threat intelligence
9–14Offensive security
  • Bug bounty
  • Web application testing
  • Burp Suite
  • Metasploit
  • sqlmap
  • John the Ripper
  • Nikto
  • Vulnerability research
15–20Network & systems
  • Wireshark
  • Nmap
  • Python
  • Bash
  • Linux (Kali, Ubuntu)
  • Windows security event logs
  • Traffic anomaly detection
  • Protocol analysis
21–26Frameworks
  • MITRE ATT&CK
  • Cyber Kill Chain
  • OWASP Top 10
  • CVSS
  • Threat modeling
  • Detection engineering
  • Pyramid of Pain
27CLKClock referenceMorocco · UTC+1
28RXReceivemohamedamellal@outlook.com
Copyright © 2026 Mohamed AmellalSubmit document feedbackMA-1337-SEC · Page 2 of 5

Application information

Labs & training
5.1Mar 2026

SOC Level 1

TryHackMe · Blue team operations

An end-to-end SOC analyst path: ingest the logs, triage the alerts, and write up what happened.

  • SIEM fundamentals, log ingestion pipelines, and structured alert triage in Splunk and ELK
  • Investigated simulated phishing, malware, brute-force, and lateral movement incidents, with full reports, timelines, and IOCs
  • Wireshark traffic analysis for C2 beacons and exfiltration, endpoint forensics, and threat intelligence enrichment

Bill of materials

U1
Splunk
U2
ELK / Kibana
U3
Wireshark
M1
MITRE ATT&CK
LOG SOURCESANALYST OUTPUTSECURITY OPERATIONSENDPOINTMALWARENETWORKC2 · EXFILTRATIONEMAILPHISHINGAUTH LOGSBRUTE-FORCELOG INGESTIONSIEMSPLUNK · ELKALERT TRIAGESTRUCTUREDTHREAT INTELENRICHMENTINCIDENT REPORT01 TIMELINE02 IOCS03 MITRE ATT&CK04 KILL CHAIN
Figure 5-1. SOC Level 1, detection and triage pipeline
5.2Feb 2025

Boot2Root

Penetration testing · threat emulation

Full attack chains on vulnerable machines, from the first scan to root, mapped back to the detections that should catch them.

  • Executed full attack chains on vulnerable VMs: enumeration, exploitation, and privilege escalation
  • Operated Nmap, Nikto, Metasploit, and John the Ripper, the tools SOC alert sources and threat intel feeds reference
  • Wrote penetration test reports mapping each attack step to MITRE ATT&CK techniques

Bill of materials

U1
Nmap
U2
Nikto
U3
Metasploit
U4
John the Ripper
ATTACK CHAINTARGET · VULNERABLE VMENUMERATIONNMAP · NIKTOEXPLOITATIONMETASPLOITPRIVILEGE ESCALATIONJOHN THE RIPPERACCESS LEVELROOTUSERNONEPENTEST REPORTSTEPS MAPPED TO MITRE ATT&CKDEFENSIVE DETECTIONSBRIDGED FROM FINDINGS
Figure 5-2. Boot2Root, attack chain
5.3Nov 2024

Snow Crash

Linux security · privilege escalation

A ladder of Linux security challenges, each one a weakness to find, abuse, and learn to detect.

  • Solved 10+ Linux security challenges covering SUID abuse, weak credentials, and misconfigurations
  • Wrote Python and Bash scripts to automate exploit delivery and credential cracking
  • Studied each endpoint attack technique alongside how it can be detected

Bill of materials

U1
Linux
U2
Python
U3
Bash
S1
SUID
REPEAT PER LEVELLEVEL NUSER SHELLSUID ABUSEWEAK CREDENTIALSMISCONFIGURATIONSAUTOMATEDEXPLOITPYTHON · BASHFLAG10+LEVELS SOLVEDLINUX CHALLENGESFLAG UNLOCKS LEVEL N + 1
Figure 5-3. Snow Crash, level loop
5.4Oct 2024

Darkly

Web application security · OWASP Top 10

A practical security assessment covering the attack paths that put modern web applications at risk.

  • Identified and exploited 14+ vulnerabilities, including SQLi, XSS, CSRF, path traversal, and open redirects
  • Analyzed HTTP traffic, session tokens, and access control flaws in Burp Suite
  • Documented every finding with CVSS scoring, reproduction steps, and remediation

Bill of materials

U1
OWASP
TP1
Burp Suite
M1
CVSS
J1
Reports
CLIENTBROWSERBURP SUITEINTERCEPT · REPLAYDUT · WEB APPTP1 INJECTIONTP2 XSSTP3 CSRFTP4 TRAVERSALTP5 SESSIONSTP6 ACCESS CONTROL14+RISKS ASSESSEDCVSS-SCOREDFIX · SECURE PATTERNS APPLIED
Figure 5-4. Darkly, test circuit
Copyright © 2026 Mohamed AmellalSubmit document feedbackMA-1337-SEC · Page 3 of 5

Revision history

Training & experience
Table 6-1. Revision history
RevDateRoleChanges
COngoingBug Bounty HunterPublic programs
  • Found 20+ vulnerabilities across public bug bounty programs, of High, Medium, and Low severity.
  • Works the full loop of recon, exploitation, and clean write-ups that developers can act on.
BCompleted Mar 2026SOC Level 1 PathTryHackMe
  • Completed the end-to-end SOC analyst curriculum: SIEM fundamentals, log ingestion pipelines, and alert triage in Splunk and ELK.
  • Applied MITRE ATT&CK, the Cyber Kill Chain, and the Pyramid of Pain to threat modeling and detection engineering.
ANov 2021 - Apr 2026IT & Computer Science1337 School · 42 Network
  • Security, systems, and low-level programming through peer-driven, project-based learning.
Copyright © 2026 Mohamed AmellalSubmit document feedbackMA-1337-SEC · Page 4 of 5

Ordering information

Contact

Have an application to test or alerts to triage?

Let's secure it properly.mohamedamellal@outlook.com
Table 7-1. Orderable options
Orderable partEngagementStatus
MA-1337-SOCJunior SOC analyst roleActive
MA-1337-PTJunior offensive security roleActive