nawaf@portfolio:~ — security engineer & builder
nawaf@portfolio:~$ whoami

Nawaf Alsahabi

security engineer & builder

open to roles & collaborations
focusattack paths, interfaces
projectMassar (APHE) — KAUST
basedSaudi Arabia
speaksArabic, English
nawaf@portfolio:~$ cat headline.txt

I build security tools — and the interfaces that make their findings readable.

Most recently on Massar (APHE), an exposure-based attack-path engine.

nawaf@portfolio:~$ ./render --attack-path --host metasploitable2
attack path · 6 entry points · 89 chains live
60.2 rank 1 · 3 CVEs
assets discovered24
findings431
chains enumerated89
runtime0.7s

0 — offline replay, no API key, median of 8 runs

Every figure here is quoted from the project’s own README.

nawaf@portfolio:~$ cat about.md

A scanner hands you 431 findings. That’s data, not an answer.

Finding the exposure is half the job.

On Massar (APHE) I own the dashboard.

I care about interfaces that tell the truth.

nawaf@portfolio:~$ ls -l skills/
./security-engineering/

Attack-path analysis, exposure assessment, and vulnerability data end to end.

  • nmap
  • NVD
  • CVE / CPE
  • KEV
  • attack graphs
./product-engineering/

Python that keeps decision logic pure and testable.

  • Python 3.11
  • Streamlit
  • pytest
  • ruff
  • GitHub Actions
./interface-design/

Design tokens, two themes across an entire application.

  • HTML
  • CSS
  • JavaScript
  • design tokens
  • theming
./accessibility-i18n/

Contrast and focus that survive both themes, plus a full Arabic RTL interface.

  • WCAG
  • RTL
  • i18n
  • ARIA
  • keyboard nav
nawaf@portfolio:~$ open work/massar
~/work/massar/dashboard flagship

Massar — Attack Path Hypothesis Engine

An exposure-based engine that ranks attacker chains deterministically.

my part

  • The light theme, carried across every surface.
  • The front door: a real first screen for the app.
  • The accessibility mark, rendered correctly in both themes.
  • Brand and navigation row, and settings that apply without reloading.
  • Test work in the vulnerability layer.
dashboard pages shipped5
tests green in the suite734
themes, light and dark2
interface languagesAR / EN
  • Python
  • Streamlit
  • CSS
  • pytest
  • nmap
  • NVD
./this-site/

One self-contained HTML file — no build step, no framework.

  • HTML
  • CSS
  • vanilla JS
  • i18n
  • RTL
./next-project/

A slot ready for the next thing — a CTF writeup, a tool, a lab.

nawaf@portfolio:~$ cat principles.txt

Learned the expensive way.

rule_01

Show the arithmetic

A number on screen with no visible breakdown is just an assertion.

rule_02

The door and the room share a name

If the tab reads Host map, the page it opens reads Host map.

rule_03

Look for the computable answer first

Before a language model gets to write anything, ask the data.

nawaf@portfolio:~$ history
1 2026 — present

Massar (APHE) — KAUST cybersecurity capstone

Dashboard and interface owner on a five-person team.

2 add a year

Your degree or programme goes here

Open index.html and replace this text.

3 next

A certification, an internship, a CTF placing

Anything that proves motion.

nawaf@portfolio:~$ ./contact --send

Let’s build something, or just talk shop.

Every message reaches me directly.