About Skills Projects Labs Books Education Contact
Open to Security Engagements

I'm Abdiwali.
I break into web apps
so you stay safe.

Web Penetration Tester & Bug Bounty Hunter with Full-Stack Development depth — blending an attacker's mindset with an engineer's craft to build and break secure systems.

0
Projects Shipped
0
Training Platforms
0
Published Books
0
Certifications
recon.sh — active-scan
$ nmap -sC -sV target.io
PORT     STATE  SERVICE
80/tcp    open   http
443/tcp   open   https
8080/tcp  open   http-proxy
FOUND   2 misconfigs
$ ./sahmiye --auto-report
→ generating assessment PDF...
✔ done.
🛡️ 3 vulns found
20+ tools built
about

Engineer. Attacker. Author.

Blending offensive security expertise with production-grade software engineering.

Abdiwali Ahmed
4+Years in Security & Dev

Offensive-security-focused Full-Stack Developer and Web Penetration Tester with a Bachelor's degree in Computer Science.

Hands-on experience across web application penetration testing, bug bounty hunting, vulnerability research, and security automation. I combine strong software engineering skills (MERN stack, Django) with a practical, attacker's understanding of web security — enabling both the design of secure systems and the discovery of exploitable weaknesses within them.

I build custom offensive tooling — reconnaissance frameworks, vulnerability scanners, and automated reporting pipelines — that streamline the entire pentest and bug bounty workflow, and I've authored five technical books making cybersecurity accessible to Somali-speaking learners.

📍 Mogadishu, Somalia
🎓 B.Sc. Computer Science
💻 Linux Enthusiast
📚 5 Books Authored
what I do

Core Competencies

The domains I operate in every day — from reconnaissance to responsible disclosure.

01
🛡️

Web App Pentesting

Vulnerability assessment and exploitation across modern web applications.

02
💰

Bug Bounty Hunting

Vulnerability research, responsible disclosure and real-world exploitation.

03
⚙️

Security Automation

Custom tooling and pipelines that automate the entire assessment workflow.

04
🔍

OSINT & Recon

Passive and active reconnaissance, subdomain enumeration, asset discovery.

05
🌐

Full-Stack Dev

Production-grade applications with the MERN stack and Django.

06
📡

Network Analysis

Network scanning, threat analysis and defensive techniques (CCNA fundamentals).

07
☁️

Cloud Security

AWS foundations, secure deployment practices and cloud threat modeling.

08
📝

Technical Writing

Security knowledge sharing — 5 published books for Somali learners.

toolbox

Skills & Tooling

The languages, frameworks and offensive tools I deploy daily.

Programming & Web

JavaScript (ES6+)PythonHTML5CSS3ReactNode.jsExpress.jsMongoDBDjango

Offensive Security

Web App PentestingVulnerability AssessmentExploitationBug Bounty MethodologiesSecurity ReportingJS/API Recon

Reconnaissance & OSINT

Subdomain EnumerationContent DiscoveryCloud Asset EnumerationSubdomain Takeover Detectioncrt.sh / AlienVault / HackerTarget

Security Tools

NmapGitGitHubAutomated PDF ReportingSecurity Header AnalyzerConfig Analyzers

Cloud & Databases

AWS FoundationsSecure DeploymentMySQLMongoDB

Languages

Arabic — NativeSomali — NativeEnglish — Professional
featured work

Security Projects

Production-grade offensive tooling and platforms I've designed and shipped.

SAHBug Bounty
Python · Automation · Security

SAHMIYE

Advanced Web Pentesting & Bug Bounty Automation framework — covering the full workflow from reconnaissance through reporting, with automated PDF assessment reports.

ReconEnumerationReporting
JSBug Bounty
JavaScript · Security Tooling

RaadraacJS

JavaScript API & Secret Discovery tool that uncovers hidden API endpoints, exposed secrets and the client-side attack surface pentesters often miss.

JS AnalysisSecret Discovery
BWSecurity
Django · JavaScript · Bootstrap

BaareWeb

Full web security scanning platform that identifies vulnerabilities, detects misconfigurations and generates professional vulnerability reports.

ScannerReports
INTOSINT
Python · OSINT

SahminINT

Passive intelligence-gathering tool aggregating data from crt.sh, AlienVault and HackerTarget — zero active scanning, stealthy profiling.

PassiveAggregation
SSSecurity
Security · Web

SecureScope

Local-first, zero-footprint analyzer for HTTP, TLS, CORS and CSP security headers — no login required, leaves no external trace.

HeadersZero-Footprint
CHWeb · AI
Django · AI · Automated Pipeline

Cod Hufan

AI-powered platform that fully automates audio/video enhancement into studio-quality speech while preserving the speaker's original voice identity.

AIAudio
more builds

Additional Projects

Bakaaro POS System
MERN Stack

Full-featured point-of-sale system with transaction processing and real-time inventory management.

View on GitHub →
Web Pentesting Handbook
16-Chapter Interactive

Interactive cybersecurity handbook teaching web pentesting fundamentals with exercises.

View on GitHub →
SahalHadiye
Recon · Guide Generator

Profiles targets and generates comprehensive pentesting guides using passive reconnaissance.

View on GitHub →
Nmap — Bilow ilaa Dhamaad
Educational

Somali-language site teaching Nmap with a built-in interactive terminal for practice.

View on GitHub →
Intelligent Chatbot
Django · NLP

Web-based chatbot using natural language processing for intelligent interactions.

View on GitHub →
Academic Projects
Django · Java · C#

Student Management System (Django/MySQL), Library System (Java), Food Order System (C#).

View on GitHub →
teaching & giving back

Training Platforms

Machadyo tababaro (Training Platforms) oo af Somali ku qoran — waxay ku siiyaan ardayda fursad ay kaga shaqeeyaan tools-ka dhabta ah iyo caqabadaha CTF (Capture The Flag).

my writing

Published Books

Five technical books making cybersecurity and networking accessible to Somali-speaking learners. Access them on Telegram →

📘

Nmap in Somali

Network Scanning

Read →
📗

Fundamentals of Cybersecurity

Beginner Guide

Read →
📕

Networking Basics in 30 Days

Networking

Read →
📙

SQL Injection

Techniques & Prevention

Read →
📔

Cross-Site Scripting (XSS)

Vulnerabilities & Mitigation

Read →
credentials

Certifications & Education

Verifiable credentials and the academic path that sharpened my edge.

🏅

Bug Bounty Masterclass

Wiz

Modern bug bounty methodologies, vulnerability research, responsible disclosure, and practical web app security.

Verify ↗
☁️

Cloud Security Foundations

AWS Academy Graduate

Cloud security fundamentals, AWS architecture, and secure deployment practices.

Verify ↗
🔐

Cloud Computing Security

Beidat Academy

Advanced cloud security, threat modeling, and secure infrastructure management.

Verify ↗
🔍

Recon for Bug Bounty

Udemy

Reconnaissance methodologies for bug bounty hunters, pentesters and researchers.

Verify ↗

Git & GitHub Collaboration

Udemy

Version control mastery — workflows, branching and CI/CD fundamentals.

Verify ↗
IN PROGRESS

Master's Degree in Cybersecurity

City University, Mogadishu

Cybersecurity fundamentals, threat modeling, vulnerability analysis and defensive security techniques.

● Currently Pursuing
2025

Web Penetration Testing

Self-Directed · Udemy, TryHackMe

Ethical hacking methodology — reconnaissance, scanning, exploitation and professional vulnerability reporting.

2025

MERN Stack Development Training

City University, Mogadishu

Full-stack web development — MongoDB, Express.js, React, Node.js — building scalable production applications.

2020 — 2024

Bachelor of Computer Science

University of Somalia (UNISO)

Software engineering, algorithms, data structures, networking, databases and IT systems.

Let's find the vulnerabilities together.

Open to security engagements, bug bounty collaborations, or full-stack development opportunities. My inbox is always open.

LocationMogadishu, Somalia