
SentinelAI
AI-assisted Windows security auditing. Strictly read-only scanning, machine-learning posture scoring, four severity tiers and a local analytics dashboard.
- 0–100
- POSTURE SCORE
- 4
- SEVERITY TIERS
- 6
- EXPORT FORMATS

// cybersecurity × full-stack × it solutions
I defend systems as a blue team analyst, build production web apps as a full-stack developer, and keep businesses connected with hands-on IT, camera and network solutions.
badii@kali:~$ whoami
blue_team && fullstack && it_support
badii@kali:~$ ./sentinel --audit
[✓] firewall ......... ACTIVE
[✓] cameras .......... ONLINE
[✓] network .......... STABLE
[!] threats .......... 0 DETECTED
badii@kali:~$
[ scroll to boot the system ]
01 / WHAT I DO
Six things I actually do, not a menu of buzzwords. Open any one of them to see exactly what is involved and what you end up holding at the end of it.
I work the defending side of the fence. That means watching what your systems actually do, hardening the parts that give an attacker leverage, and closing the gaps before somebody else goes looking for them. No fear-selling and no jargon wall — just a system that is measurably harder to break this month than it was last month.
YOU GET → A hardened baseline plus a written report you can hand to anyone.
WHAT'S INCLUDED
Every engagement starts with written authorization and an agreed scope — no exceptions. Automated scanners catch the obvious things in ten minutes; I spend the rest of the time on the paths they cannot see. Findings arrive as a reproducible chain of steps, ranked by what it would actually cost you, with a fix your developers can act on today.
YOU GET → A report ranked by real risk — not a raw scanner dump.
WHAT'S INCLUDED
Most security decisions are business decisions wearing a technical costume. I sit with you and translate: this is what could go wrong, this is how likely it is, this is what fixing it costs, and this is what you can safely accept for now. You leave with a prioritized list instead of a vague sense of dread.
YOU GET → A prioritized roadmap your team can actually execute.
WHAT'S INCLUDED
I build and ship real applications with Next.js and TypeScript. Authentication, data handling and input validation get designed in at the start rather than patched in three sprints later, because retrofitting security into a shipped product is how projects quietly die. Fast, accessible, and maintainable by someone who is not me.
YOU GET → A fast, secure app that ships — and keeps shipping.
WHAT'S INCLUDED
Machines that boot, printers that print, servers that stay up, backups that actually restore — and somebody who picks up the phone when they don't. This is the least fashionable thing I do and often the most valuable. I fix the problem, then fix the reason it happened, then write down what I did.
YOU GET → Fewer fires — and a number to call when there is one.
WHAT'S INCLUDED
Cameras and networks deserve to be treated as infrastructure, not accessories. Coverage gets planned before a single hole is drilled, cables get labeled, configurations get documented. The result is footage that is actually usable when it matters and a network the next technician can read without calling me.
YOU GET → A network you can read, and cameras you can trust.
WHAT'S INCLUDED
02 / SELECTED WORK
Four systems I designed, built and shipped. Each one opens into the full brief — the problem, how I approached it, and what actually came out the other side.

AI-assisted Windows security auditing. Strictly read-only scanning, machine-learning posture scoring, four severity tiers and a local analytics dashboard.

Lebanese herbal e-commerce storefront with dual USD/LBP pricing, product carousels and a warm apothecary aesthetic.

NFC-based memory sharing platform — tap a card, open a shared world of memories. Layered architecture with a clean API core.

Full salon management: services, employees, bookings, payments and reports — with scheduling that refuses double-bookings.
03 / FIELD OPERATIONS
Not everything I do lives in a browser tab. Racks, patch panels, cameras and cable runs — the physical half of the job.

01 / SHELL
Where every audit starts. Kali, root access, and a scope agreed in writing before anything runs.

02 / SERVERS
Servers configured, virtualized and hardened. ESXi, firewalls, and cable runs you can trace by hand.

03 / NETWORK
Networks designed, labeled and documented — so the next person to open the cabinet can read them.

04 / SURVEILLANCE
CCTV surveyed, installed and configured. Coverage planned to hold up on the night it actually matters.

05 / CODE
Production apps in Next.js and TypeScript — secure from the first commit, not the last sprint.
04 / HOW I WORK
The same four phases whether it's a web app, a penetration test or a camera install. You always know which one we're in and what lands at the end of it.
MISSION PHASE
01
EST. DURATION
2 – 5 days
Map the terrain before touching anything.
I start by listening. What are you actually trying to protect or build, what already exists, and where does it hurt today? For security work that means an inventory and a threat model. For a build it means users, constraints and a definition of done — agreed in writing before anyone talks about estimates.
WHAT LANDS AT THE END
$ nmap -sV --scope authorized
Decide on paper, where decisions are still cheap.
Every choice made here costs minutes; the same choice made after launch costs weeks. The data model, the authentication strategy, the network segmentation, the camera coverage plan — all settled and reviewed with you before a line of code is written or a single cable is pulled.
WHAT LANDS AT THE END
$ design --review --before-build
Make it work, then attack my own work.
Development and installation happen in reviewable increments, and each increment is hardened as it lands rather than at the end: input validated, privileges dropped, dependencies patched, restores actually tested. I go at my own build adversarially before you ever see it.
WHAT LANDS AT THE END
$ build && harden && verify
Hand over something the next person can read.
A handover only I can understand is a failed handover. You get documentation someone else could follow, monitoring that tells you when something is wrong before a customer does, and a person who answers when you call. Systems get maintained — not abandoned at launch.
WHAT LANDS AT THE END
$ deploy --then-stay-reachable
05 / EXPERTISE
three fronts — one standard.
Defending, testing and advising — the side of the work that keeps everything else standing.
$ arsenal --load sec

A PRINCIPLE, NOT A SLOGAN
06 / WHO I AM
I'm Badii — a computer science student and security practitioner from Lebanon. I build full-stack products with Next.js and TypeScript, harden systems as a blue team analyst, and handle the real-world infrastructure most developers never touch: networks, servers and camera systems.
Working across all three is the point, not a lack of focus. Knowing how a network is actually cabled changes how I design an app. Having audited my own code makes me a better defender. Every project ships with the same rule regardless of which hat it needed: clean, connected, and secure.
NO SIGNAL
awaiting feed
07 / CONTACT
A web app built right, a system that needs hardening, a camera installation, or a network that just works — tell me what you're dealing with and I'll tell you honestly whether I'm the right person for it.
AVAILABILITY
Open to work
RESPONSE TIME
Usually within a day
LANGUAGES
Arabic · English · French