Skip to content
View MustafaSalhaa's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report MustafaSalhaa

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
MustafaSalhaa/README.md

Hi, I'm Mustafa 👋

I'm a penetration tester based in Abu Dhabi, raised here, and this is where I built my entire career.

I help organizations find security vulnerabilities before attackers do. My work sits at the intersection of technical depth and business risk - I don't just find issues, I help organizations understand what they mean and how to fix them.


What I Help Organizations With

Security isn't just a technical problem, it's a business one. A single vulnerability in the wrong place can expose customer data, halt operations, or damage a brand that took years to build.

I work with organizations to identify those risks across their:

  • Web applications and customer-facing platforms
  • Internal networks and enterprise infrastructure
  • Microsoft cloud environments (Azure / Entra ID)
  • Windows-based corporate environments [AD]

The outcome is always the same: a clear picture of where the risk is, how serious it is, and what to do about it, in language that makes sense to both technical teams and leadership.


Track Record

  • 80+ security engagements delivered across the UAE and the region
  • Clients across banking, government, healthcare, and enterprise
  • Internationally certified in offensive security

Certifications: ✅ eJPTv2 · ✅ eWPTXv3 · ✅ CRTA · 🔄 BSCP 🔄 CRTP · 🔄 CARTP · (in progress)


About Me

Abu Dhabi built me. I grew up here, studied here, and grew from knowing nothing about security into doing this professionally for some of the most critical organizations in the region.

I still treat every engagement like it matters - because it does.


📍 Abu Dhabi, UAE · Open to security collaborations and research

Pinned Loading

  1. bundlespy bundlespy Public

    A JavaScript attack-surface intelligence engine for security testing. Discovers and analyzes JS, routes, endpoints, secrets, source maps, chunks, GraphQL, WebSockets, workers, and runtime applicati…

    Python 1