Nawaf Alsahabi
security engineer & builder
open to roles & collaborationsI build security tools — and the interfaces that make their findings readable.
Most recently on Massar (APHE), an exposure-based attack-path engine.
0 — offline replay, no API key, median of 8 runs
Every figure here is quoted from the project’s own README.
A scanner hands you 431 findings. That’s data, not an answer.
Finding the exposure is half the job.
On Massar (APHE) I own the dashboard.
I care about interfaces that tell the truth.
Attack-path analysis, exposure assessment, and vulnerability data end to end.
Python that keeps decision logic pure and testable.
Design tokens, two themes across an entire application.
Contrast and focus that survive both themes, plus a full Arabic RTL interface.
Massar — Attack Path Hypothesis Engine
An exposure-based engine that ranks attacker chains deterministically.
my part
- The light theme, carried across every surface.
- The front door: a real first screen for the app.
- The accessibility mark, rendered correctly in both themes.
- Brand and navigation row, and settings that apply without reloading.
- Test work in the vulnerability layer.
One self-contained HTML file — no build step, no framework.
A slot ready for the next thing — a CTF writeup, a tool, a lab.
Learned the expensive way.
Show the arithmetic
A number on screen with no visible breakdown is just an assertion.
The door and the room share a name
If the tab reads Host map, the page it opens reads Host map.
Look for the computable answer first
Before a language model gets to write anything, ask the data.
Massar (APHE) — KAUST cybersecurity capstone
Dashboard and interface owner on a five-person team.
Your degree or programme goes here
Open index.html and replace this text.
A certification, an internship, a CTF placing
Anything that proves motion.
Let’s build something, or just talk shop.
Every message reaches me directly.