Skip to content
View moaazmtaha's full-sized avatar

Block or report moaazmtaha

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
moaazmtaha/README.md

Moaaz Taha

I’m a security engineer in London. I work across red team operations, adversary emulation and threat simulation, following attack paths through identity, endpoints, applications and hybrid infrastructure.

Over the past decade I’ve led red and purple team engagements, developed offensive tooling and worked with defenders to turn attack paths into useful detections and remediation. I’m particularly interested in initial-access routes that do not depend on phishing.

Two tools grew out of review work I kept doing by hand:

  • attack-path-review takes a user-supplied identity or trust graph and finds bounded attack routes, shared choke points, a minimum edge cut, and the control changes with the largest modeled effect. It runs offline and writes JSON, HTML, DOT and SARIF.
  • threat-sim-preflight checks a threat-simulation plan before execution: authorization, scope, windows, action dependencies, telemetry, detection coverage, cleanup and expiring waivers. It can also validate technique IDs against a local ATT&CK STIX bundle.

Selected public work:

Elsewhere:

Pinned Loading

  1. moaaztaha.com moaaztaha.com Public

    Source for moaaztaha.com: selected security work and a source-linked archive of five CVEs.

    TypeScript