Ahmed Abdel Rasoul

Ahmed Abdel Rasoul

Penetration Tester & Bug Bounty Hunter

Profile

Penetration Tester with 500+ vulnerabilities reported across HackerOne, Bugcrowd, HackenProof and Immunefi. Responsibly disclosed issues to Binance, Oracle, VMware, Huawei and John Deere. Specialized in web, API and mobile application security, with a strong focus on business logic flaws, authorization and authentication bypasses, IDORs and API abuse. Also experienced in Active Directory penetration testing and source code review.

Work Experience

Bug Bounty Hunter

HackerOne · Bugcrowd · HackenProof · Immunefi · Independent
2022 – Present Remote
  • 500+ vulnerabilities reported across public and private programs, with 2,220+ reputation and Clear Verified status on HackerOne.
  • Top 10 on HackerOne's iOS mobile app leaderboard, and Top 10 for Android assets (Q1 2026).
  • Ranked #1 on a private fintech bug bounty program after crossing 1,000 reputation on that program alone.

Cyber Security Engineer

Buguard · Internship
07/2025 – 12/2025 Remote
  • Conducted web and mobile application penetration tests, identifying critical vulnerabilities including RCE, SSRF and misconfigurations.
  • Authored client-facing reports covering reproduction steps, business impact and remediation guidance.
  • Used Burp Suite, Nmap and Nessus alongside a manual testing methodology.

Technical Skills

Web Application Security

OWASP Top 10 (XSS, SQLi, SSRF, etc.) Business Logic Testing Authentication & Authorization Testing API Security Testing (GraphQL, REST, SOAP) Source Code Review (Static & Dynamic Analysis)

Android Application Security

Reverse engineering with JADX, Apktool, Ghidra Dynamic analysis with Frida, Objection, Magisk

iOS Application Security

IPA unpacking & binary review with Hopper, Ghidra, class-dump Runtime testing with Frida & Objection SSL pinning bypass on jailbroken devices

Active Directory Penetration Testing

Enumeration & Privilege Escalation (BloodHound, PowerView) Kerberoasting, ASREPRoasting, Pass-the-Hash / Pass-the-Ticket Lateral Movement & Persistence (Mimikatz, Rubeus, Impacket) Domain Escalation (Golden Ticket, Silver Ticket, DCSync) GPO & Group Membership Abuse

Programming & Scripting

Python for automation & tooling Java for Android static analysis

Automation & AI-Assisted Testing

Automated Android pipeline: scope monitoring, APK acquisition, decompilation & triage at scale LLM-assisted static analysis of decompiled code to prioritize findings Custom recon, subdomain monitoring & vulnerability automation Every reported finding manually verified & reproduced before submission

Certifications

eMAPT

Mobile Application Penetration Tester

INE Security View Credential
eWPTX

Web Application Penetration Tester eXtreme

INE Security View Credential
eCPPT

Certified Professional Penetration Tester

INE Security View Credential
Soon
OSCP

Offensive Security Certified Professional

OffSec

Hall of Fame & Awards

John Deere 2026

Bug Bounty Program swag for responsible disclosure

Oracle 2025

Acknowledged in Oracle's Critical Patch Update — On-Line Presence Security Contributors

Binance 2024

Top 3 Researcher in Binance Bug Bounty Program

Huawei 2023

Two official acknowledgment letters for accepted vulnerability reports

VMware 2022

Official swag for responsible disclosure of a security issue

CVE Disclosures

CVE-2026-23524 RCE CRITICAL

Projects & Tooling

h1-asset-fetcher

Fetches, downloads, and decompiles Android/iOS/exe assets from HackerOne bug bounty programs.

Cookie-Swapper

Burp Suite extension that automates session token swapping across Burp tabs during security testing.

h1-monitor

Self-hosted bot that watches HackerOne programs for scope changes and pushes them to Telegram, 24/7.

Education

Computer Science

Arab Open University

2025 – Present · Cairo, Egypt