--:--:-- UTC+3
00.0 Security · Product · Index

Cybersecurity
entrepreneur.

I've been writing code for 10 years and breaking into systems for the last 3. OSCP certified, built vulnerable machines for OffSec Proving Grounds. Now I'm on the other side — building security products for companies that actually need them.

Years pentesting01
3+ yrs
web, mobile, AD, network assessments
Certification02
OSCP/ OffSec
web · mobile · AD · network
OffSec machines03
5/ PG
5 machines, 2 CVE-based scenarios
Products shipped04
2/ 1 live
VulnTracker · landingvideo (retired)
01 Products

Things I shipped.

§ 01 · 2 products
▲ Flagship · Security SaaS
VulnTracker.io
Live 2026

Automated vulnerability tracking for security teams. Continuous visibility across your stack — from disclosed CVEs to the patch landing in production.

✕ Retired · Micro-SaaS
landingvideo.com
2026 Offline

Landing page → promo video in 30 seconds. Shipped in 2026, shut down shortly after — lessons stayed, the domain didn't.

02 Research

Vulnerable machines I designed.

Five vulnerable machines shipped to OffSec Proving Grounds — each a chained exploit scenario, designed to teach the path from foothold to root.

§ 02 · 5 machines
03 Bio

About.

§ 03 · essay

Hey, I'm Ali. I'm a software developer and security researcher with 3+ years of experience in web and mobile security, local network assessments, and Active Directory exploitation. I worked at startups and a telecom company.

OSCP certified. I build vulnerable machines for OffSec Proving Grounds.

Now I'm turning my security work into products by building a cybersecurity company.

04 Dispatch

Build-in-public.

Notes from an indie founder. Occasional, when there's something worth saying.