# about

Engineer first. Researcher always. CTF player on the side.

I am Abdelkader, Security Researcher. I am an RCE enthusiast and mainly focus on Web and Application Security.

I'm a builder passionate about protecting digital infrastructure and creating technology that solves real-world problems.

Beyond my professional work, I continuously research offensive security techniques, enterprise defense strategies, and emerging cyber threats.

Security Researcher · CTF Player · Ethical HackerBeni Mellal, Moroccoresearching AD tiering
about.json — Code
{
  "name": "Abdelkader Belcaid",
  "role": "Security Researcher",
  "focus": [
    "RCE",
    "SSRF",
    "SSTI",
    "SQLi"
  ],
  "ctf": {
    "categories": ["web", "reverse engineering", "crypto", "pwn"],
    "philosophy": "get admin/root access or it didn't happen"
  },
  "now": "shrinking attack surface in OT/IT seams",
  "status": "open to research collabs"
}
# focus

Where I spend the most time

The themes that come up across most engagements and writeups.

PHP & Web Security
Source Code Review
Cybersecurity Problem Solving
Coding and Making New Functionalities
Vulnerability triage at scale
CTF: web · reverse engineering · pwn · cryptography
# stack

What I reach for

Tools I use often enough to have opinions about.

PHPJavaScriptPythonRubyBurp SuiteCodeQLIDA ProgdbGhidrapwntoolsDockerBash
# timeline

Recent path

  1. 2025 — Present
    Security Researcher

    Focused on security research, vulnerability discovery, and exploit development. Specializing in remote code execution (RCE), server-side vulnerabilities, attack surface analysis, vulnerability triage, and proof-of-concept exploitation.

  2. 2023 — 2025
    Cybersecurity Engineer

    Managed cybersecurity initiatives and resilience programs across enterprise environments. Worked on security hardening, attack surface reduction, vulnerability management, identity security, and cyber resilience improvements.

  3. 2019 — 2023
    Cybersecurity Consultant

    Delivered penetration testing, security assessments, hardening projects, and forensic investigations for multiple organizations. Key areas included:

    • Penetration Testing
    • Security Hardening
    • Digital Forensics
    • Vulnerability Management
    • Secure Baseline Configuration
    • SOC Handover & Operationalization
    • Operational Technology (OT) Security
    • Disaster Recovery & Business Continuity Workflows