// cybersecurity × full-stack × it solutions

BADII ALIaka MR.BULLET

>

I defend systems as a blue team analyst, build production web apps as a full-stack developer, and keep businesses connected with hands-on IT, camera and network solutions.

03
DISCIPLINES
06
SERVICES
04
SHIPPED
LB
BASED IN
badii@kali: ~/portfolio

badii@kali:~$ whoami

blue_team && fullstack && it_support

badii@kali:~$ ./sentinel --audit

[✓] firewall ......... ACTIVE

[✓] cameras .......... ONLINE

[✓] network .......... STABLE

[!] threats .......... 0 DETECTED

badii@kali:~$

SCROLL TO INITIALIZE
badii@kali: /var/log/boot0%

[ scroll to boot the system ]

BOOT░░░░░░░░░░░░░░LOADING...
Next.js TypeScript React Node.js ASP.NET Core Laravel PostgreSQL Python Tailwind CSS Kali Linux Burp Suite CCTV Systems Network Management VMware ESXi Next.js TypeScript React Node.js ASP.NET Core Laravel PostgreSQL Python Tailwind CSS Kali Linux Burp Suite CCTV Systems Network Management VMware ESXi

01 / WHAT I DO

SERVICES

Six things I actually do, not a menu of buzzwords. Open any one of them to see exactly what is involved and what you end up holding at the end of it.

I work the defending side of the fence. That means watching what your systems actually do, hardening the parts that give an attacker leverage, and closing the gaps before somebody else goes looking for them. No fear-selling and no jargon wall — just a system that is measurably harder to break this month than it was last month.

YOU GET → A hardened baseline plus a written report you can hand to anyone.

WHAT'S INCLUDED

  • Operating system & service hardening
  • Log collection and threat monitoring
  • Defensive configuration audits
  • Incident response playbooks
  • Patch and update strategy
  • Plain-language post-incident reports

Every engagement starts with written authorization and an agreed scope — no exceptions. Automated scanners catch the obvious things in ten minutes; I spend the rest of the time on the paths they cannot see. Findings arrive as a reproducible chain of steps, ranked by what it would actually cost you, with a fix your developers can act on today.

YOU GET → A report ranked by real risk — not a raw scanner dump.

WHAT'S INCLUDED

  • Authorized web application testing
  • OWASP Top 10 coverage
  • Manual Burp Suite methodology
  • Business-logic flaw hunting
  • Findings ranked by real-world impact
  • Free retest after you remediate

Most security decisions are business decisions wearing a technical costume. I sit with you and translate: this is what could go wrong, this is how likely it is, this is what fixing it costs, and this is what you can safely accept for now. You leave with a prioritized list instead of a vague sense of dread.

YOU GET → A prioritized roadmap your team can actually execute.

WHAT'S INCLUDED

  • Risk assessment & threat modeling
  • Security roadmap planning
  • Team best-practice training
  • Tooling selection and setup
  • Third-party and vendor review
  • Policy and procedure drafting

I build and ship real applications with Next.js and TypeScript. Authentication, data handling and input validation get designed in at the start rather than patched in three sprints later, because retrofitting security into a shipped product is how projects quietly die. Fast, accessible, and maintainable by someone who is not me.

YOU GET → A fast, secure app that ships — and keeps shipping.

WHAT'S INCLUDED

  • Next.js + TypeScript applications
  • Secure API and authentication design
  • PostgreSQL / MySQL data modeling
  • Payment and subscription flows
  • Performance, SEO and accessibility
  • CI/CD, deployment and monitoring

Machines that boot, printers that print, servers that stay up, backups that actually restore — and somebody who picks up the phone when they don't. This is the least fashionable thing I do and often the most valuable. I fix the problem, then fix the reason it happened, then write down what I did.

YOU GET → Fewer fires — and a number to call when there is one.

WHAT'S INCLUDED

  • Hardware and software troubleshooting
  • Windows and Linux administration
  • Server setup and virtualization
  • Backup and recovery planning
  • User accounts and access management
  • Ongoing maintenance agreements

Cameras and networks deserve to be treated as infrastructure, not accessories. Coverage gets planned before a single hole is drilled, cables get labeled, configurations get documented. The result is footage that is actually usable when it matters and a network the next technician can read without calling me.

YOU GET → A network you can read, and cameras you can trust.

WHAT'S INCLUDED

  • Site survey and coverage planning
  • CCTV installation and configuration
  • Network design and structured cabling
  • Router, switch and firewall setup
  • Remote and mobile monitoring
  • Full documentation and handover

02 / SELECTED WORK

CASE FILES

Four systems I designed, built and shipped. Each one opens into the full brief — the problem, how I approached it, and what actually came out the other side.

CASE FILE 001/SECURITY TOOLACTIVE
SentinelAI — Security Tool
sentinelai.local/dashboard

SentinelAI

AI-assisted Windows security auditing. Strictly read-only scanning, machine-learning posture scoring, four severity tiers and a local analytics dashboard.

0–100
POSTURE SCORE
4
SEVERITY TIERS
6
EXPORT FORMATS
PythonMachine LearningBlue TeamWindows
OPEN CASE FILE
CASE FILE 002/E-COMMERCELIVE
SmartBioRemedies — E-Commerce
smartbioremedies.com

SmartBioRemedies

Lebanese herbal e-commerce storefront with dual USD/LBP pricing, product carousels and a warm apothecary aesthetic.

USD + LBP
CURRENCIES
NEXT.JS
FRAMEWORK
DEPLOYED
STATUS
Next.jsTypeScriptTailwindVercel
OPEN CASE FILE
CASE FILE 003/NFC PLATFORMIN BUILD
MatesMemories — NFC Platform
matesmemories.com/tap

MatesMemories

NFC-based memory sharing platform — tap a card, open a shared world of memories. Layered architecture with a clean API core.

4
ARCH LAYERS
NFC TAP
TRIGGER
ASP.NET
BACKEND
Next.jsASP.NET CoreEF CoreNFC
OPEN CASE FILE
CASE FILE 004/MANAGEMENT SYSTEMDELIVERED
MyBeautySalon — Management System
mybeautysalon.app/admin

MyBeautySalon

Full salon management: services, employees, bookings, payments and reports — with scheduling that refuses double-bookings.

7
MODULES
ZERO
DOUBLE-BOOKINGS
ARCHIVE ONLY
DELETES
LaravelMySQLBladePHP
OPEN CASE FILE

03 / FIELD OPERATIONS

ON THE GROUND

Not everything I do lives in a browser tab. Racks, patch panels, cameras and cable runs — the physical half of the job.

THE TERMINAL

01 / SHELL

THE TERMINAL

Where every audit starts. Kali, root access, and a scope agreed in writing before anything runs.

THE RACK

02 / SERVERS

THE RACK

Servers configured, virtualized and hardened. ESXi, firewalls, and cable runs you can trace by hand.

THE PATCH PANEL

03 / NETWORK

THE PATCH PANEL

Networks designed, labeled and documented — so the next person to open the cabinet can read them.

THE CAMERAS

04 / SURVEILLANCE

THE CAMERAS

CCTV surveyed, installed and configured. Coverage planned to hold up on the night it actually matters.

THE CODEBASE

05 / CODE

THE CODEBASE

Production apps in Next.js and TypeScript — secure from the first commit, not the last sprint.

01
SWIPE →

04 / HOW I WORK

MISSION TIMELINE

The same four phases whether it's a web app, a penetration test or a camera install. You always know which one we're in and what lands at the end of it.

[ PHASE_01 ]2 – 5 days

RECON

Map the terrain before touching anything.

I start by listening. What are you actually trying to protect or build, what already exists, and where does it hurt today? For security work that means an inventory and a threat model. For a build it means users, constraints and a definition of done — agreed in writing before anyone talks about estimates.

WHAT LANDS AT THE END

  • Scope document & rules of engagement
  • Asset and system inventory
  • Risk and threat model
  • Written estimate with timeline

$ nmap -sV --scope authorized

[ PHASE_02 ]3 – 7 days

ARCHITECT

Decide on paper, where decisions are still cheap.

Every choice made here costs minutes; the same choice made after launch costs weeks. The data model, the authentication strategy, the network segmentation, the camera coverage plan — all settled and reviewed with you before a line of code is written or a single cable is pulled.

WHAT LANDS AT THE END

  • Architecture and data model
  • Auth and access-control design
  • Network / camera layout plan
  • Hosting and tooling decisions

$ design --review --before-build

[ PHASE_03 ]2 – 8 weeks

BUILD & HARDEN

Make it work, then attack my own work.

Development and installation happen in reviewable increments, and each increment is hardened as it lands rather than at the end: input validated, privileges dropped, dependencies patched, restores actually tested. I go at my own build adversarially before you ever see it.

WHAT LANDS AT THE END

  • Working system in staging
  • Hardening checklist completed
  • Self-audit findings and fixes
  • Documentation written as we go

$ build && harden && verify

[ PHASE_04 ]Ongoing

DELIVER & MONITOR

Hand over something the next person can read.

A handover only I can understand is a failed handover. You get documentation someone else could follow, monitoring that tells you when something is wrong before a customer does, and a person who answers when you call. Systems get maintained — not abandoned at launch.

WHAT LANDS AT THE END

  • Production launch and smoke tests
  • Written handover documentation
  • Monitoring and alerting configured
  • Support channel and maintenance window

$ deploy --then-stay-reachable

05 / EXPERTISE

THE ARSENAL

three fronts — one standard.

Defending, testing and advising — the side of the work that keeps everything else standing.

Blue Team OperationsVulnerability AssessmentBurp SuiteOWASP Top 10Kali LinuxIncident Response

$ arsenal --load sec

A PRINCIPLE, NOT A SLOGAN

ZERO TRUST.
EVERY SYSTEM EARNS IT.

06 / WHO I AM

SECURITY-FIRST
BUILDER.

I'm Badii — a computer science student and security practitioner from Lebanon. I build full-stack products with Next.js and TypeScript, harden systems as a blue team analyst, and handle the real-world infrastructure most developers never touch: networks, servers and camera systems.

Working across all three is the point, not a lack of focus. Knowing how a network is actually cabled changes how I design an app. Having audited my own code makes me a better defender. Every project ships with the same rule regardless of which hat it needed: clean, connected, and secure.

$ location:
Lebanon 🇱🇧
$ focus:
blue team + full-stack + it solutions
$ status:
open to internships & freelance
RECCAM 01

NO SIGNAL

awaiting feed

STANDBYLebanon

07 / CONTACT

LET'S BUILD
SOMETHING
SECURE.

A web app built right, a system that needs hardening, a camera installation, or a network that just works — tell me what you're dealing with and I'll tell you honestly whether I'm the right person for it.

AVAILABILITY

Open to work

RESPONSE TIME

Usually within a day

LANGUAGES

Arabic · English · French