Skip to content
View Sajawal007's full-sized avatar

Block or report Sajawal007

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Sajawal007/README.md

views

Hey there, I'm Sajawal

πŸ”’ Full-stack software engineer with a security focus, based in Woking, UK. I build and ship production systems end to end β€” from a live Rails 8 e-commerce platform I designed and run solo, to multi-tenant SaaS serving 1700+ enterprise clients, to AI-driven security automation pipelines. MSc Cybersecurity (Distinction) from London Metropolitan University and CompTIA Security+, with a focus on DevSecOps, full-stack engineering, vulnerability management, and offensive security.


πŸš€ Featured β€” mobilegift.co.uk Β 

A commercial e-commerce platform I designed, built and run solo in Ruby on Rails 8 β€” serving real customers with live Stripe payments, a device catalogue, and a multi-branch inventory & reservations dashboard. Full lifecycle ownership: front end in Hotwire (Turbo + Stimulus) and Tailwind CSS, containerised with Docker, deployed to Azure for testing, then onto my own hardened VPS with TLS in production β€” with Brakeman static analysis and dependency scanning in the workflow. I'm the only engineer and the only person on call. It takes real orders today. β†’ mobilegift.co.uk


πŸ§‘πŸ½β€πŸ’» What am I working on?

πŸ›‘οΈ infrathreats β€” Context-Related Threat Intelligence (Master's Dissertation)

An end-to-end Rails 8 pipeline: IOC β†’ LLM β†’ MCP servers β†’ automated threat intelligence report. Extracts indicators of compromise from unstructured reporting, cross-references them against an organisation's own infrastructure to determine genuine relevance, and produces a CVSS 3.1-scored assessment with MITRE ATT&CK phase mapping. Built for unreliable conditions: Solid Queue background jobs, JSONB caching so inference never repeats, and NDJSON streaming with automatic fallback to a synchronous path.

πŸ§ͺ cybercrime-e-skimming-setup β€” Client-Side Attack Simulation

A dynamic script-loading harness emulating an e-skimming attack, built from the attacker's side to understand how the technique stays unnoticed rather than how to block it.

βš™οΈ MCP for Security β€” AI-Powered Security Automation

Integrating the mcp-for-security framework with Claude Desktop, and running Bolt (Docker-based Kali tooling over MCP) as the execution bridge. Routes IOCs β€” IPs, domains, URLs, APKs β€” to the right offensive-security tool: Nmap, Amass, SQLmap, Nuclei.

πŸ” CVE Research & Offensive Practice

Reproduced and analysed RevSlider vulnerabilities CVE-2014-9734 and CVE-2017-18535 against a controlled WordPress instance β€” working from advisory to working exploitation. Ongoing hands-on practice on HackTheBox and TryHackMe, plus a lab environment I build and attack myself.


πŸ“˜ Education

πŸŽ“ London Metropolitan University β€” Jan 2025 – July 2026

MSc Cybersecurity Β· Distinction Β· 90% in Cyber Forensics & Cyber Incident Response Β· Advanced Ethical Hacking, Cyber Security Management, Cloud Security

Forensic report graded "an exemplary forensic report that sets a benchmark for technical excellence and investigative rigour."

πŸ“š National University of Computer and Emerging Sciences (FAST-NUCES) β€” 2019 – 2023

BS Computer Science Β· Dean's List of Honors (Dec 2022, Jun 2020)


πŸ“œ Certifications

πŸ›‘οΈ CompTIA Security+ β€” 2026


πŸ•° Experience

πŸ“± Mobile Gift β€” Volunteer, In-House Developer & Repair Technician β€” Feb 2025 – Present

Built and maintain the company's live e-commerce platform (see Featured) end to end, from first line of code to production hosting β€” unpaid, alongside a customer-facing retail and device-repair role held throughout my MSc.

πŸ›‘οΈ Devsinc β€” Software Engineer (Cybersecurity SaaS) β€” Jul

Pinned Loading

  1. infrathreats infrathreats Public

    This is going to be a complete system. Where IOCs are leached from web. Different companies infrastructures information will be stored in database. On new ioc and selected company it'll execute its…

    HTML

  2. cybercrime-e-skimming-setup cybercrime-e-skimming-setup Public

    This repository have test setup for dynamic script loading for emulating a real e-skimming attack

    HTML

  3. Location-Intelligent-System Location-Intelligent-System Public

    Project for PSO Virtual Surveys.

    HTML