Skip to main content

About

loading · loading ·
Table of Contents

Introduction
#

Taha Marouani, a persistent, serious and ambitious Telecommunications Engineering student.
A self-learner who’s dedicating his time to focus on what really matters: Touching grass, making a change, and developing a solid career.
Armed with passion for Cybersecurity, Philosophy and Books, I’m finding my purpose through this non-sense by learning.

Academic Journey
#

  1. Engineering Degree in Telecommunications

    2024-2027

    With a strong focus on Signal Processing, Telecommunications, and Physics, I study the engineering principles behind how information is transmitted, processed, and received, contributing to the advancement of modern communication infrastructures.
    Operating Systems
    Linux
    Cisco Packet Tracer
    Huawei eNSP
    Bash
    radio_signal [#1026]Created with Sketch.Networking
    C
    C++
    C#
    .NET
    Node.js
    Next.js
    React
  2. National Entrance Exams for Engineering School

    2024-2027

    As a PTSI student within the CPGE program, I underwent an intensive and rigorous scientific training focused on mathematics, physics, and engineering sciences. This was a very rewarding journey as it enhanced my analytical thinking, problem-solving abilities, and capacity to work under pressure (lots of pressure), all while building a solid foundation for advanced studies in engineering having the most important skills as an engineer.
    Physics
    Maths
    Chemistry
    Machanics
    Electronics
    Python
    Problem Solving
    Critical Thinking
    Engineering
    Work under pressure
  3. Baccalaureat Degree with Honors

    2020

Professional Experience
#

Disclaimer

Due to hosting costs, I occasionally put down the AI-related projects. I am using any cloud provider’s free tier so I am saving costs to test and benchmark any current project.
If you need to see a project in action, you can ping me to host it for you in no time.

  1. ODDO BHF Tunis - Vulnerability Management Intern

    Summer 2025

    • Engineered a multi-agents AI system for an internal Vulnerabilities Operations Center and Risk Management.
    • Built a production-ready Agentic RAG system for internal operations.
    • Built an AI-Augmented Kill Chain Detection system, to predict and remediate against advanced threats.
    View it in action ↗View the Codebase ↗
    RAG
    AI
    Management
    Agentic AI
    179Agentic RAG
    Multi-Agent
    Agentic Systems
    Benchmarking
    Vulnerability Management
  2. Freelance - Security Consulting

    Sep 2025 - Present

    • Conducted white-box and black-box penetration tests of small business networks comprising 10–20 endpoints per VLAN.
    • Assessed network segmentation, firewall rules and Wi-Fi security to identify unauthorized access paths and configuration weaknesses.
    • Identified excessive privileges and access-control issues across cloud and on-premises environments, providing prioritized remediation guidance.
    • Reviewed application deployments and CI/CD pipelines for exposed secrets, insecure permissions, misconfigurations and unsafe deployment practices.
    RAG
    AI
    Management
    Agentic AI
    179Agentic RAG
    Multi-Agent
    Agentic Systems
    Benchmarking
    Vulnerability Management
  3. BIAT IT - SOC & CTI Internship

    Summer 2025

    • Created an on-premise Open Source SOC Lab: Wazuh, TheHive, MISP, Cortex.
    • Automated the deployment of different components using Docker containers.
    • Reviewed and enhanced Threat Intelligence reports of previously filtered incidents.
    • Studied and analyzed XDR/NDR logs to trace lateral movement attempts.
    • Analyzed recent severe alerts and enhanced the final provided report.
    • Performed a Threat Hunt based on traces from a critical recent incident.
    SOC
    Firewall
    Wazuh
    IDS
    179IPS
    The Hive
    MISP
    Cortex
    SIEM
    SOAR
    Icon_24px_MicrosoftAd_ColorActive Directory
    Windows
    Threat Hunting
    Threat Intelligence
    Security Operations
    logsLog Analysis
  4. CTF Author & Infrastructure Maintainer

    March 2025 - Now

    • Co-founded Securinets ENIT, the local branch of the Tunisian national cybersecurity organization.
    • Maintained and orchestrated 2 national CTFs and 2 local CTFs serving over 200 teams with 0 downtime.
    • Authored 15+ DFIR, Reverse Engineering and Pwn tasks.
    • Optimized CI/CD and GitHub workflows for the repositories of the CTFs to manage collaboration between the authors.
    flagCTF
    Orchestration
    Infrastructure
    Cloud (GCP/AWS)
    High Availability
    Reverse Engineering
    Binary Exploitation
    DFIR
    Pwn
    GitHub
    cicdCI/CD
    Automation
    DevOps Workflows
    Team Collaboration
    Scalability

Projects
#

  1. Advanced OPSEC-compliant and Resilient C2 Infrastructure for Red Team Operations

    current project

    • Engineered a resilient, fault-friendly and reliable C2 architecture for long and short red team engagements.
    • Used and managed resources from multiple cloud providers (AWS, GCP, Digital Ocean and Cloudflare) to craft a multi-cloud infrastruccture.
    • Used domain fronting for new network-level blending in and evasion.
    • Designed well hardened redirectors to not leak informations about our stack in-use.
    • Setup Mythic C2 with HTTP, HTTPx and DNS malleable profiles for interacting with the implant.
    • Designed fail-over domains going through multiple cloud providers' instances to avoid single points of failure.
    • Designed an advanced phishing infrastructure made for fully undetected Initial Access.
    • And much more
    IAM
    Multi-Cloud
    Infrastructure as Code
    Ansible
    Terraform
    ionicons-v5-iDomain Fronting
    Traffic Blending
    OpSec & Hardening
    Mythic C2 Framework
    Malleable C2 Profiles
    Reverse Proxy (Apache)
    Icon_24px_PhishingProtection_ColorInitial Access
    Post-Exploitation
    Long-Haul
    Short-Haul
    Persistence
    Evasion
    Automated Failover
  2. Confidential RF Threat Detection Platform - Public-Sector Engagement

    November - April 2025

    • Created an on-premise and cloud Malware Analysis Lab.
    • Analyzed Zeus Trojan - Banking Version and WannaCry Ransomware.
    • Performed Static and Dynamic analysis on different samples.
    • Reverse Engineered multiple samples and classified differences in tradecraft.
    • Replicated malware behavior and re-created their base source codes.
    • Researched coverd evasion techniques and tactics and mapped them to MITRE IDs.
    View it in action ↗
    Malware Analysis
    Reverse Engineering
    Binary Analysis
    Static Analysis
    Dynamic Analysis
    Assembly (x86)
    Windows PE
    ionicons-v5-iAnti-Debugging & Evasion
    radio_signal [#1026]Created with Sketch.C2 Communication
    Wireshark Logo IconThis is shape (source) for Clarity vector icon theme for gtkWireshark
    ProcMon
    IDA / Ghidra
    MITRE ATT&CK Mapping
    Trojan
    Ransomware
  3. Evasive, OPSEC-Compliant Phishing Infrastructure for MFA Bypass

    current project

    • Engineered a Multi-Layered APT-style phishing infrastructure.
    • Used trusted cloud services to achieve seamless evasion.
    • Crafted multiple Evilginx phishlets for multiple trusted services and websites.
    IAM
    Multi-Cloud
    Infrastructure as Code
    Ansible
    Terraform
    ionicons-v5-iDomain Fronting
    Traffic Blending
    OpSec & Hardening
    Mythic C2 Framework
    Malleable C2 Profiles
    Reverse Proxy (Apache)
    Icon_24px_PhishingProtection_ColorInitial Access
    Post-Exploitation
    Long-Haul
    Short-Haul
    Persistence
    Evasion
    Automated Failover
  4. Malware Analysis Project

    November - April 2025

    • Created an on-premise and cloud Malware Analysis Lab.
    • Analyzed Zeus Trojan - Banking Version and WannaCry Ransomware.
    • Performed Static and Dynamic analysis on different samples.
    • Reverse Engineered multiple samples and classified differences in tradecraft.
    • Replicated malware behavior and re-created their base source codes.
    • Researched coverd evasion techniques and tactics and mapped them to MITRE IDs.
    Malware Analysis
    Reverse Engineering
    Binary Analysis
    Static Analysis
    Dynamic Analysis
    Assembly (x86)
    Windows PE
    ionicons-v5-iAnti-Debugging & Evasion
    radio_signal [#1026]Created with Sketch.C2 Communication
    Wireshark Logo IconThis is shape (source) for Clarity vector icon theme for gtkWireshark
    ProcMon
    IDA / Ghidra
    MITRE ATT&CK Mapping
    Trojan
    Ransomware

CTFs and Ranking
#

HackTheBox Profile
#

Since Summer 2025, I started seriously and methodologically attacking HackTheBox Labs and sherlocks.
You can find my profile stats down below.

avatar

EvilSamirLoussif

Hacker · Tunisia
mini avatar
EvilSamirLoussif
EU Machines 3
Profile ↗
32 Roots
34 Users
1007 Global
1 Points
0 Bloods
Hacker 0% Pro Hacker

CTFTime Profile
#

I’m a part of Curiosity, a Tunisian CTF Team formed in July 2025.
So far, we achieved high rankings in major international and national CTFs, I currently focus on:

  • DFIR
  • Reverse Engineering
  • and some Binary Exploitation tasks.

You can view my CTFTime Profile Here .

There are no articles to list here yet.