Miaoui SkanderSecuring systems, breaking assumptions.

From malware analysis to national-scale CyberDrills — a Tunisian cybersecurity community leader building both the tools and the talent shaping the region's security landscape.

Miaoui_Skander_terminal
Type to explore.

My Experience

Hands-on experience across malware analysis, threat intelligence, and SOC operations.

Threat Intelligence Engineer Intern

June 2026 - September 2026

  • Automated OSINT collection & enrichment using AI-driven analysis cutting manual effort significantly
  • Built graph-based analysis to map relationships between threat actors, entities & campaigns
  • Integrated AI to automate correlation and intelligence generation, accelerating actionable insights for security operations
Keystone

Digital Forensics & Malware Analysis Intern

June 2025 - August 2025

  • Performed static and dynamic malware analysis in an isolated FlareVM sandbox to identify behavioral patterns and system artifacts
  • Extracted and correlated IOCs using Wireshark, Process Monitor, Process Explorer & Regshot, mapping findings to MITRE ATT&CK
  • Identified evasion and anti-analysis techniques across multiple malware families
  • Authored technical reports on Zeus Banking Trojan (2013) and Proteus malware (2016), documenting infection chains, persistence, and C2 communication
ANCS

Network Security Engineer Intern

June 2024 - July 2024

  • Configured and monitored enterprise firewalls, routers, and switches to maintain secure connectivity across a banking environment
  • Implemented access control policies and VLAN segmentation to strengthen network isolation and limit lateral movement
  • Supported security investigations through log review and network traffic analysis
BTE

Founder & Technical Lead – Securinets FST

September 2024 - Now

  • Founded the cybersecurity division of Securinets FST, establishing its technical direction, structure, and training philosophy from the ground up
  • Designed FST's first structured cybersecurity training program, building learning roadmaps across offensive security, defensive security, and SOC operations for 200+ members
  • Authored CTF challenges and served as Technical Lead for CyberHorizon 2.0 — Africa's first CTI & DFIR CyberDrill — owning infrastructure, challenge design, and event operations
Securinets FST

My Projects

CyberDrill leadership, a self-built SOC lab, and national CTF authoring.

Conceived and led Africa's first CTI and IR CyberDrill (April 2026) — a real-time simulation covering threat intelligence, network forensics, web exploitation, Active Directory attacks, IT/OT security, and incident reporting. Designed and deployed the full lab infrastructure, led the technical team, and managed challenge development across all tracks, delivering a large-scale hands-on exercise that strengthened participants' detection, investigation, and response capabilities.

Built a multi-VM SOC lab integrating Wazuh, ELK Stack, and Splunk for centralized logging, correlation, and real-time alerting. Simulated realistic attack chains — initial access, lateral movement, data exfiltration — to generate telemetry for SIEM-driven investigation. Tuned detection rules and correlation logic to reduce false positives while preserving true alerts, closely reproducing real SOC monitoring workflows.

Created original CTF challenges spanning beginner to expert level across Digital Forensics, OSINT, MISC, Blockchain, and IoT for national competitions, designed around realistic attack scenarios to build practical skills. Competed as a core member of Securinets FST, achieving Top 3 finishes in the majority of competitions — validating strong offensive and defensive security skills.

Explore my challenges ↗

A small selection of my work. Plenty more where this came from.

BUILT TO CHALLENGE

Challenges I authored

A glimpse into the puzzles, systems, and ideas behind my CTF work.

AI SecurityCTF
CTF-Local

DUMB

An AI security challenge exploring how a chatbot handles confidential information and adversarial prompts.

Explore challenge
BlockchainMedium
CTF-Local

Merkle Chojra

In this universe, trees don’t look the same as in ours. They are different. They are strange. And they hide something big. Try to reveal it.

Explore challenge
MiscEasy
CTF-Local

FIND ME

During the exams, students didn’t write their names the usual way. Something is different in this universe… Can you understand how?

Explore challenge
MiscEasy
CTF-Local

breakchesst

In this world, players don’t take normal breaks — they take breakchesst. We arrive at the final position of a battle between two students. The game is almost over… Black to move and win.

Explore challenge
MiscMedium
CTF-Local

CORNPROMISE

In another universe, FST has been compromised. As an investigator, your mission is to discover what the attackers did to the system. You have access to the server, but no privileges — nothing except a single entry point…

Explore challenge
MiscCTF
CTF-Local

VIrtual

A timed, isolated SSH challenge environment with a dedicated instance launcher. Explore the environment and find your way through.

Explore challenge
OSINTMedium
CTF-Local

PROf cracker

One of the proffessor in the other universe work and teach at the same time , instead of publishing notes he leaked a secret zip file we tried to get more info about him , we only found this post , can you access the secret_key ???

Explore challenge
OSINTHard
CTF-Local

hacker-cracked

in the other universe a hacker hacked the university , and after investigations we got a zip file from his connection and he left us a note : "0xbscurity loves games , and you are my game" can you crack the zip file and get the message

Explore challenge
AI SecurityCTF
CyberQuest

DUMB

An AI security challenge exploring how a chatbot handles confidential information and adversarial prompts.

Explore challenge
BlockchainMedium
CyberQuest

Merkle Chojra

In this universe, trees don’t look the same as in ours. They are different. They are strange. And they hide something big. Try to reveal it.

Explore challenge
IoTCTF
CyberQuest

Camera Challenge

In ramadhan , after watching all Tunisian Series u want to watch other series but live ones XD , live serie is here

Explore challenge
MiscEasy
CyberQuest

FIND ME

During the exams, students didn’t write their names the usual way. Something is different in this universe… Can you understand how?

Explore challenge
MiscEasy
CyberQuest

breakchesst

In this world, players don’t take normal breaks — they take breakchesst. We arrive at the final position of a battle between two students. The game is almost over… Black to move and win.

Explore challenge
MiscMedium
CyberQuest

CORNPROMISE

In another universe, FST has been compromised. As an investigator, your mission is to discover what the attackers did to the system. You have access to the server, but no privileges — nothing except a single entry point…

Explore challenge
OSINTMedium
CyberQuest

PROf cracker

One of the proffessor in the other universe work and teach at the same time , instead of publishing notes he leaked a secret zip file we tried to get more info about him , we only found this post , can you access the secret_key ???

Explore challenge

My Skills

01

Detection & Investigation

Digital Forensics
SIEM & Threat Detection
Threat Intelligence
Reverse Engineering & Malware Analysis
02

Offensive Security

Offensive Security
Active Directory
Network
03

Engineering & Infrastructure

Python, Bash, C, JavaScript
Platforms, Cloud & Infrastructure
Machine Learning

My Achievements

Continuously validating my skills through industry-recognized certifications.

ISC2 : Ceritified In Cybersecurity CC

ISC2 : Ceritified In Cybersecurity CC

View credential
NVIDIA:

NVIDIA: Fundemantals of Deep Learning

View credential
TryHackMe:

TryHackMe: TOP 2% & TOP 5 in Tunisia Monthly

View credential
Adapt Africa:

Adapt Africa: Cyber Resilience and Business Continuity

View credential
300+Students trained
3University organizations
KNOWLEDGE SHARING

Cybersecurity Instructor

As a cybersecurity trainer across three university organizations — Securinets FST, Securinets ENECTOM, and GDGC ISSATSO — I designed and delivered SOC training curricula covering threat detection, SIEM operations (Wazuh, Splunk, ELK), log analysis, and incident response. I built structured, beginner-to-intermediate learning paths paired with hands-on lab exercises, giving students practical exposure to real SOC workflows rather than purely theoretical content.

Through multiple cohorts, I trained over 300 students, helping them develop the ability to analyze security events, investigate alerts, and respond to incidents using industry-standard tools.

This work extended my focus beyond individual technical projects into scaling cybersecurity education and building repeatable training frameworks across multiple student communities.

My Socials

Contact Me

Let's talk security, opportunities, or collaboration.

Send a message directly to my inbox.