Skip to content
View bIackr0se's full-sized avatar

Highlights

  • Pro

Block or report bIackr0se

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bIackr0se/README.md

Hey! I'm Jaafer

bloglinkedinemail

AI red teaming • security engineering

papers cve owasp

About

Security engineer and PhD researcher in adversarial machine learning. I break models to make them harder to break: red-teaming ML models, LLM agents, and RAG pipelines, and engineering the ML-driven detection that defends critical infrastructure against attackers who adapt.

Current work

  • AutoMCP - elastic purple-team MCP server: extracts security alerts, analyzes, responds, runs counter-reconnaissance
  • Watching an SSRF walk out of the sandbox - full writeup of CVE-2026-58196, host-side SSRF in an MCP runtime
  • Doctoral research - evaluating and hardening ML-based intrusion detection against adaptive evasion; security of agentic LLM SOC analysts in OT networks
  • Vulnerability research on AI-agent infrastructure: MCP servers, agent runtimes, coding assistants, disclosed responsibly
  • Field notes - writeups land here as disclosures go public

Arsenal

skills

AI red teaming : evasion, model extraction, data poisoning, prompt injection, robustness evaluation

Security engineering : ML-driven detection, SIEM, IDS (Suricata, Zeek), MITRE ATT&CK mapping

Critical infrastructure : OT/ICS protocols (Modbus, CAN, PROFINET), SCADA, fieldbus security

Vulnerability research : AI-agent infrastructure, exploitation, responsible disclosure

Certs : eJPTv2 • ISC2 CC (+ CC exam development volunteer) • NVIDIA Exploring Adversarial Machine Learning

Contact

Research collaboration, responsible disclosure, or an interesting target model: jaafer.rahmani@owasp.org

Popular repositories Loading

  1. AutoMCP AutoMCP Public

    Elastic Purple Team MCP Server, based on Langraph. Extracts security alerts, analyzes them, responds to them and performs Counter-Reconnaissance.

    Python 2

  2. cmux cmux Public

    Forked from manaflow-ai/cmux

    Ghostty-based macOS terminal with vertical tabs and notifications for AI coding agents

    Swift

  3. bIackr0se bIackr0se Public

    AI red teaming // security engineering