Ilyas Ousbaa
Whoami
I’m a cyber security consultant and analyst with 3+ years of experience spanning SOC operations, threat hunting, and vulnerability management, reinforced by mission-critical and freelance engagements. I bring an offensive security mindset to defensive work, studying attacker behavior and mapping exploit paths to cut through noise and prioritize what actually matters.
My methodology is analytical and strategic: I identify exploitable flaws, then design and automate proactive defenses to reduce risk. I collaborate closely with IAM, Vulnerability Management, Penetration Testing, and operations teams, adapting to evolving attack vectors and closing remediation loops end-to-end.
I’m based in Morocco, currently researching on HackerOne, and open to consulting and full-time roles in detection engineering, threat hunting, and offensive-informed defense.
Technologies
Network Security & Defense
FortiGate
Sophos
Check Point
Wazuh (SIEM/XDR)
Reconnaissance & Assessment
Burp Suite
Nuclei
Nmap
Amass
Automation & Engineering
Python
Go
PowerShell
Docker
Experiences
Recent Projects
Latest Research
Compound Exposure Model (CEM) for Software Secret Severity
Preprint
Ilyas Ousbaa
A deterministic hybrid framework combining additive structural severity (5 facets) and noisy-OR exposure (8 factors), with an independent Confidence Index and Floor/Ceiling dual-scoring, validated against 1,373 unified detectors from GitGuardian x TruffleHog.
Skills
Network Architecture & Administration
Routing, switching, VPN deployment, firewall policy management, and high-availability infrastructure maintenance.
Systems Hardening & IT Operations
OS-level security configuration, vulnerability exposure reduction, performance optimization, and business continuity support.
Security Operations (SOC)
Incident response, log analysis, alert tuning, anomaly detection, and SIEM/XDR pipeline engineering.
Vulnerability Management Lifecycle
End-to-end assessment, prioritization via CVSS/EPSS, remediation tracking, patch validation, and SLA-driven risk reduction across hybrid infrastructures.
Identity & Access Management (IAM)
Credential hygiene, privileged access workflows, zero-trust principles, and MITRE ATT&CK-driven detection logic.
Threat Intelligence & Reconnaissance
Attack surface discovery, OSINT gathering, and proactive threat hunting across internal and external environments.
Detection Engineering & Automation
Custom rule development in SIGMA, YARA, and regex, exploit-path prioritization, and CI/CD pipeline security.
Cyber Threat Hunting & Analysis
Studying attacker behavior and mapping exploit paths to prioritize what matters, reinforced through TryHackMe, HackTheBox, and PortSwigger training.