Hey, I’m Mustafa Al-Shawwa

I’m a cybersecurity engineer with a deep passion for defending the digital frontier — especially in areas where most people fear to tread: OT security, hardware hacking, and advanced threat hunting.

I love to get my hands dirty, one day I’m unraveling a piece of malware, the next I’m pulling firmware off a board through UART or JTAG, or prodding an old SCADA controller just to see what makes it tick. Whether it’s low-level protocol sleuthing or an off-the-wall hardware hack, I’m driven by the thrill of learning something new and turning curiosity into real insight.

Areas I Dive Into:

  • Security Operations & Threat Hunting – crafting high-fidelity detections with Microsoft Sentinel & Defender
  • Cloud Security (Azure, AWS, GCP) – implementing Zero Trust, IAM, and compliance guardrails
  • Red Teaming & Malware Analysis – from C2 frameworks to reversing binaries
  • OT/ICS Security – SCADA visibility, protocol abuse, hardware-level exploitation
  • GRC – aligning operations with NIST, ISO 27001, and CIS

Highlights:

  • CPTC Global Champion 2024
  • Microsoft Certified: Security Operations Analyst
  • Led major forensics & red team challenges at Armython and AIDTSEC

About Me

I’m based in Amman, Jordan, and when I’m not dissecting packets or building out security labs, you’ll find me mentoring others, experimenting with low-level protocols, or exploring the overlaps between physical and digital security.

Let’s build, break, and secure — together.

🔗 GitHub · LinkedIn