Available now

Farouq Hassan

Cybersecurity engineer who finds what's broken before attackers do — authorized offensive testing on live government systems, detection-engineering tooling, and cloud security. I build real things and document them in the open. Currently a Cloud Security Intern at Paramount and a Black Hat MEA 2026 speaker.

FH.
// Certifications
CDSA — Certified Defensive Security AnalystVerified ✓ · click to verify ↗Certified Defensive Security Analyst badge
CWSE — Certified Web Security ExpertVerified ✓ · click to verify ↗
CAPT — Certified Associate Penetration TesterVerified ✓ · click to verify ↗
NCP-MCI — Nutanix Certified Professional - Multicloud Infrastructure 6Verified ✓ · click to verify ↗Nutanix Certified Professional - Multicloud Infrastructure 6 badge
AZ-900 — Microsoft Certified: Azure FundamentalsVerified ✓ · click to verify ↗Microsoft Certified: Azure Fundamentals badge
CCEP — Certified Cybersecurity Educator ProfessionalVerified ✓ · click to verify ↗Certified Cybersecurity Educator Professional badge
SC-900 — Microsoft Certified: Security, Compliance, and Identity FundamentalsVerified ✓ · click to verify ↗Microsoft Certified: Security, Compliance, and Identity Fundamentals badge
0+
Projects completed
0
Certifications earned
0
Gov. findings (3 critical)
0+
Students taught
Selected work

What I've built

SOC / DFIR

ChainHunter - Detection & Attack-Chain Correlation Engine

Open-source detection engine (Python, DuckDB, Sigma) that turns raw Windows and cloud logs into correlated incidents - one attack story in place of thousands of alerts. Runs 2,400+ SigmaHQ community rules plus custom multi-stage sequence rules that join on account, host or domain, with behavioural anomaly detection and per-entity risk scoring. v0.5.0, 39 automated tests.

Other

Déjà View - Shoulder-Surfing-Resistant 3FA Identity Provider

Production-deployed 3FA authentication system and standards-compliant OpenID Connect identity provider built to solve a specific threat: shoulder surfing on shared workstations. Watching someone log in gives an attacker nothing - no replayable credential exists. Three cryptographically bound factors: SHA-256 photo key (image never leaves browser), client-side face biometric via WebAssembly (128-float descriptor only), TOTP. HMAC-SHA256 challenge-response replaces hash transmission on enrolled devices. Built as a real OIDC IdP - any OAuth 2.0 app can plug in. Production compliance docs: GDPR Article 30, ISO 27001 Annex A, HIPAA §164.312. Live at deja-view.io. Accepted as a Black Hat MEA 2026 talk and demoed to Jordan's NCSC leadership.

SOC / DFIR

Command Reference - Offline Detection & Pentest Platform

A 950-card offensive + detection-engineering reference, built as a fully offline static platform. Automated 779 flat SIEM queries into 3,693 typed detections across Splunk, Sentinel, Elastic and Sigma, with a fidelity classifier, build-time MITRE coverage index, and ATT&CK Navigator export. Live on this site.

↗ Live
What they say

“Farouq's technical depth is beyond what I typically see at this level. He doesn't just find the vulnerability - he understands the full attack surface, documents the blast radius, and delivers findings that are immediately actionable. His knowledge base is stronger than most professionals I've supervised. Whoever brings him on board is getting more than they're expecting.”

Supervisor, Government / Defense Engagement (under NDA)
Right now
Speaking at Black Hat MEA 2026 - 'Dejaview: Picture-Based MFA for the Post-Quantum World'
Cloud Security Intern @ Paramount Computer Systems (PCCP) - Sentinel detection engineering, Defender XDR
Building ChainHunter - open-source detection & attack-chain correlation engine
Latest writing
HTB CDSA - What It Really Takes to Pass

An honest account of what the CDSA exam demands - the lab hours, the mental pressure, and what actually prepared me to pass. No fluff.

Let's build something secure.

Open to cloud security, SOC / detection engineering, and red team roles - plus assessments, training and mentorship.