About

I'm Ahmed Ramadan, an offensive security engineer, penetration tester and security researcher.

Four years testing web applications, REST and GraphQL APIs, mobile, external networks and Active Directory. Most of what I find is logic: an identifier the server trusts, a state nobody designed for, an authorisation check that verifies the session but not the person holding it.

Alongside the testing, I build autonomous offensive security tooling: agents pairing a deterministic execution engine with LLM decision making, and the scope enforcement and destructive-action controls that any agent holding live credentials actually needs.

I hold OSCP+, CREST CRT and CREST CPSA, and I'm credited with CVE-2026-44977 along with disclosure acknowledgements across healthcare, fintech, AI infrastructure, B2B SaaS, education and civic technology.

Everything I publish here is my own research, tested against systems I own or am authorised to test.

Certifications

All credentials →

OffSec Certified Professional Plus (OSCP+)

Credential ID: OS-57216833

Verify

CREST Registered Tester (CRT)

Credential ID: 7657380034

Verify

CREST Practitioner Security Analyst (CPSA)

Credential ID: 7657380034

Verify

Recent posts

All research →

Get in touch

Open to conversations about offensive security work, research collaboration, and interesting vulnerabilities.