โโโ[ INTEL-REPORT // CLASSIFIED: OPEN-SOURCE ]โโโโโโโโโโโโโโโโโโโ
โ CODENAME .......... APT-AHMED โ
โ REAL_NAME ......... Ahmed BARGADY โ
โ ORIGIN ............ Morocco ๐ฒ๐ฆ โ
โ FIRST_OBSERVED .... 2019 (commit hash: a17d3f...) โ
โ STATUS ............ ACTIVE โฎโฎโฎโฎโฎโฎโฎโฎโฎโฎ 100% โ
โ SECTOR ............ Academia ยท Cybersecurity ยท AI Research โ
โ MOTIVATION ........ curiosity ยท open-source ยท โ โ
โ THREAT_LEVEL ...... HIGH-CURIOSITY โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
|
+ Detect stealthy multi-stage APTs
+ Reason over MITRE ATT&CK with LLMs
+ Open-source an APT benchmark
+ Publish first PhD paper (2026)
! Sleep more
- Boring dashboards
|
RECON โ WEAPONIZE โ DELIVER โ EXPLOIT โ INSTALL โ C2 โ ACTIONS ย ย vs. ย ย ๐ก๏ธ ย AI ยท Graphs ยท LLMs
Detecting stealthy, multi-stage attackers (APTs) inside enterprise telemetry
with graph-based and LLM-assisted anomaly detection.
| ๐ง Direction | ๐ฌ What I'm exploring |
|---|---|
| Provenance Graphs | Lateral-movement detection via temporal GNNs |
| LLM-augmented SOC | Reasoning over alerts, MITRE ATT&CK mapping |
| Adversarial Robustness | Evasion attacks on EDR/ML detectors |
| Benchmarks & Data | Reproducible APT datasets for the community |



