<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pages on MEDDAH Mohamed</title><link>https://meddah.systems/page/</link><description>Recent content in Pages on MEDDAH Mohamed</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Tue, 28 May 2019 00:00:00 +0000</lastBuildDate><atom:link href="https://meddah.systems/page/index.xml" rel="self" type="application/rss+xml"/><item><title>Archives</title><link>https://meddah.systems/page/archives/</link><pubDate>Tue, 28 May 2019 00:00:00 +0000</pubDate><guid>https://meddah.systems/page/archives/</guid><description/></item><item><title>About</title><link>https://meddah.systems/page/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meddah.systems/page/about/</guid><description>&lt;h3 id="the-foundation"&gt;&lt;a href="#the-foundation" class="header-anchor"&gt;&lt;/a&gt;The Foundation
&lt;/h3&gt;&lt;p&gt;Cybersecurity came through infrastructure. Before learning the offensive side of systems,
I learned how they were built, managing servers, configuring networks,
troubleshooting production environments. That background changed how
I read attack surfaces: I look for what&amp;rsquo;s trusted, what&amp;rsquo;s assumed, and what
nobody thought to question.&lt;/p&gt;
&lt;h3 id="where-im-headed"&gt;&lt;a href="#where-im-headed" class="header-anchor"&gt;&lt;/a&gt;Where I&amp;rsquo;m Headed
&lt;/h3&gt;&lt;p&gt;The goal is to be genuinely good at the full stack, from on-premises
infrastructure to cloud architecture, from exploitation to detection. Not
surface-level familiar with everything, but deeply capable across the
offensive and defensive boundary. That takes time and I&amp;rsquo;m not in a rush
to pretend otherwise.&lt;/p&gt;
&lt;p&gt;Right now that means cloud security research, privilege escalation tooling,
and active researcher on HackerOne, Intigriti, and Bugcrowd.
Confirmed findings on production targets. Learning something new on every
program.&lt;/p&gt;
&lt;h3 id="why-research"&gt;&lt;a href="#why-research" class="header-anchor"&gt;&lt;/a&gt;Why Research
&lt;/h3&gt;&lt;p&gt;Not just for the money. Because a well-chained attack against a real production
system is one of the most honest technical puzzles that exists. Either it
works or it doesn&amp;rsquo;t. The target doesn&amp;rsquo;t grade on effort.&lt;/p&gt;
&lt;p&gt;That honesty is what keeps it interesting. Security is one of the few fields
where staying shallow gets punished quickly and going deep always pays off.
That&amp;rsquo;s the only environment worth working in.&lt;/p&gt;
&lt;h3 id="this-site"&gt;&lt;a href="#this-site" class="header-anchor"&gt;&lt;/a&gt;This Site
&lt;/h3&gt;&lt;p&gt;A working log. Write-ups, tooling, notes&amp;hellip; things worth documenting because
they taught me something non-obvious. Nothing published until it&amp;rsquo;s worth
reading.&lt;/p&gt;</description></item><item><title>Certifications</title><link>https://meddah.systems/page/certs/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meddah.systems/page/certs/</guid><description>&lt;h2 id="-certifications"&gt;&lt;a href="#-certifications" class="header-anchor"&gt;&lt;/a&gt;📜 Certifications
&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Certification&lt;/th&gt;
&lt;th&gt;Issuer&lt;/th&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;AWS Certified Cloud Practitioner (CLF-C02)&lt;/td&gt;
&lt;td&gt;Amazon Web Services&lt;/td&gt;
&lt;td&gt;Jul. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Microsoft Certified: Cloud &amp;amp; AI Security Engineer Associate (SC-500)&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Sep. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;AWS Certified Solutions Architect — Associate (SAA-C03)&lt;/td&gt;
&lt;td&gt;Amazon Web Services&lt;/td&gt;
&lt;td&gt;Oct. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="-ctf--labs"&gt;&lt;a href="#-ctf--labs" class="header-anchor"&gt;&lt;/a&gt;🏁 CTF &amp;amp; Labs
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SecDojo National CTF:&lt;/strong&gt; Ranked #100 / 3,500+ participants — top 3% nationally. Techniques: LSASS credential dump, BloodHound attack paths, ADCS ESC11, NTLM relay.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MCP/Prompt Injection Lab (NebulaAssist):&lt;/strong&gt; Full attack chain — Nmap recon, SSE token extraction, hidden tool enumeration via prompt injection.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Contact</title><link>https://meddah.systems/page/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meddah.systems/page/contact/</guid><description>&lt;h3 id="get-in-touch"&gt;&lt;a href="#get-in-touch" class="header-anchor"&gt;&lt;/a&gt;Get in Touch
&lt;/h3&gt;&lt;p&gt;📧 &lt;a class="link" href="mailto:mohamed@meddah.systems" &gt;mohamed@meddah.systems&lt;/a&gt;
🔗 &lt;a class="link" href="https://linkedin.com/in/meddah" target="_blank" rel="noopener"
&gt;linkedin.com/in/meddah&lt;/a&gt;
🐙 &lt;a class="link" href="https://github.com/mrmeddah" target="_blank" rel="noopener"
&gt;github.com/mrmeddah&lt;/a&gt;
🌐 &lt;a class="link" href="https://meddah.systems" target="_blank" rel="noopener"
&gt;meddah.systems&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For security research inquiries, project collaborations, or professional
opportunities — email is the best channel. Response time is usually within
48 hours.&lt;/p&gt;
&lt;p&gt;🔐 &lt;a class="link" href="https://meddah.systems/pgp.asc" &gt;Download PGP Public Key&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Resume</title><link>https://meddah.systems/page/resume/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meddah.systems/page/resume/</guid><description>&lt;p&gt;📄 &lt;a class="link" href="https://meddah.systems/cv" target="_blank" rel="noopener"
&gt;Download PDF version&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="mohamed-meddah"&gt;&lt;a href="#mohamed-meddah" class="header-anchor"&gt;&lt;/a&gt;Mohamed MEDDAH
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Cybersecurity Engineer | Cloud Security | Offensive Security&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;📍 Marrakech, Morocco · 🌍 Open to relocation · Open to remote
📧 &lt;a class="link" href="mailto:mohamed@meddah.systems" &gt;mohamed@meddah.systems&lt;/a&gt; · &lt;a class="link" href="https://linkedin.com/in/meddah" target="_blank" rel="noopener"
&gt;linkedin.com/in/meddah&lt;/a&gt; · &lt;a class="link" href="https://github.com/mrmeddah" target="_blank" rel="noopener"
&gt;github.com/mrmeddah&lt;/a&gt; · &lt;a class="link" href="https://meddah.systems" target="_blank" rel="noopener"
&gt;meddah.systems&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-professional-summary"&gt;&lt;a href="#-professional-summary" class="header-anchor"&gt;&lt;/a&gt;🎯 Professional Summary
&lt;/h2&gt;&lt;p&gt;Final-year Cybersecurity Engineering student (Bac+5 / Master&amp;rsquo;s equivalent, Bologna Process EQF Level 7, expected Jun. 2027) with confirmed production bug bounty impact and cloud security tooling across Azure and AWS. Proven across offensive web and API testing, Azure RBAC privilege escalation research, and DORA-aligned defensive tooling. Proficient in English (C1) and French (B2). Seeking PFE internship in EU regulated environments from February 2027.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-technical-skills"&gt;&lt;a href="#-technical-skills" class="header-anchor"&gt;&lt;/a&gt;🛠️ Technical Skills
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Offensive Security:&lt;/strong&gt; Penetration Testing, Web Application Security, API Security, SSRF, IDOR/BOLA, OAuth 2.0 Exploitation, GraphQL Security, Subdomain Enumeration, AD Attacks, NTLM Relay, ADCS Abuse, LFI&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cloud Security — Azure:&lt;/strong&gt; Security Posture Management, Defender for Cloud, Microsoft Entra ID, Conditional Access, Managed Identities, Azure RBAC, Key Vault, Azure Functions, ARM Templates, Azure Monitor&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cloud Security — AWS:&lt;/strong&gt; EC2, VPC, IAM, S3, RDS, Secrets Manager, CloudTrail, Security Hub, GuardDuty, 70+ services via Terraform IaC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Frameworks &amp;amp; Standards:&lt;/strong&gt; OWASP Top 10, OWASP API Security Top 10, MITRE ATT&amp;amp;CK, CWE, Zero Trust, DORA, NIS2, ISO 27001&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Network:&lt;/strong&gt; TCP/IP, BGP, OSPF, VXLAN/EVPN, VLANs, pfSense, Site-to-Site VPN, GNS3, Wireshark (CCNA/CCNP level)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security Tools:&lt;/strong&gt; Burp Suite Professional, Nmap, Subfinder, Amass, httpx, Feroxbuster, ffuf, Shodan, truffleHog, BloodHound, Metasploit&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Development:&lt;/strong&gt; Python, Bash, JavaScript, Java, Go, C++, Django, React, Node.js&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Systems:&lt;/strong&gt; Linux (Debian/Ubuntu/Kali), Windows Server, Active Directory, Docker&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-professional-experience"&gt;&lt;a href="#-professional-experience" class="header-anchor"&gt;&lt;/a&gt;💼 Professional Experience
&lt;/h2&gt;&lt;h3 id="independent-contractor--data-curator"&gt;&lt;a href="#independent-contractor--data-curator" class="header-anchor"&gt;&lt;/a&gt;Independent Contractor — Data Curator
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Veeva Systems&lt;/strong&gt; · Remote · Mar. 2024 – Sep. 2024&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Processed and validated large-scale structured datasets for pharmaceutical CRM pipelines; maintained data integrity and compliance standards across a multi-client regulated environment, directly applicable to NIS2/DORA data governance requirements.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="it-infrastructure-intern"&gt;&lt;a href="#it-infrastructure-intern" class="header-anchor"&gt;&lt;/a&gt;IT Infrastructure Intern
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Menara Prefa&lt;/strong&gt; · Marrakech, Morocco · April 2024&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deployed and configured pfSense firewall (packet filtering, NAT, segmentation); implemented site-to-site VPN using IPsec tunnelling.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="development--systems-administration-intern"&gt;&lt;a href="#development--systems-administration-intern" class="header-anchor"&gt;&lt;/a&gt;Development &amp;amp; Systems Administration Intern
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Municipality of El Kelaa des Sraghna&lt;/strong&gt; · El Kelaa, Morocco · August 2023&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Built full-stack citizen ticket management application integrated with the national Chikaya platform; RBAC-based routing; Django REST / React / relational DB; Windows Server and Linux administration.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="-projects"&gt;&lt;a href="#-projects" class="header-anchor"&gt;&lt;/a&gt;🏗️ Projects
&lt;/h2&gt;&lt;h3 id="azure-rbac-privilege-escalation-mapper"&gt;&lt;a href="#azure-rbac-privilege-escalation-mapper" class="header-anchor"&gt;&lt;/a&gt;Azure RBAC Privilege Escalation Mapper
&lt;/h3&gt;&lt;p&gt;&lt;em&gt;Python | Azure SDK | Microsoft Graph API | Azure Functions · September 2026&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enumerates multi-hop Azure privilege escalation paths via RBAC misconfiguration; detects the runCommand/IMDS token theft chain — a Defender for Cloud blind spot.&lt;/li&gt;
&lt;li&gt;Maps four attack primitives: Run Command abuse, Custom Script Extension backdoor, Role Assignment write escalation, User Data injection; outputs attacker-ready PoC commands with inline DORA Article 9 and CSSF regulatory citations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azure-deployment-history-sanitizer"&gt;&lt;a href="#azure-deployment-history-sanitizer" class="header-anchor"&gt;&lt;/a&gt;Azure Deployment History Sanitizer
&lt;/h3&gt;&lt;p&gt;&lt;em&gt;Python | Azure Functions | ARM API | Shannon Entropy Analysis · July 2026&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Serverless tool purging ARM/Bicep deployment histories that expose plaintext secrets to any Reader-level account; Shannon entropy + keyword heuristics detect credentials, SAS tokens, and connection strings.&lt;/li&gt;
&lt;li&gt;Three modes: aggressive purge, selective entropy-based, and audit-only; full audit trail to Azure Storage Tables for DORA compliance and CSSF audit readiness.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="zero-trust-distributed-storage-system"&gt;&lt;a href="#zero-trust-distributed-storage-system" class="header-anchor"&gt;&lt;/a&gt;Zero-Trust Distributed Storage System
&lt;/h3&gt;&lt;p&gt;&lt;em&gt;Go | Java | libsodium | AES-256-GCM | ABE | JWT · May 2026&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Mini-IPFS with client-side AES-256-GCM encryption (libsodium), Merkle DAG integrity, 3-node replication, and cryptographic access control via Attribute-Based Encryption and Proxy Re-Encryption; JWT Ed25519 PoP tokens with nonce-based anti-replay (TTL 30s).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="aws-cloud-infrastructure-terraform-iac"&gt;&lt;a href="#aws-cloud-infrastructure-terraform-iac" class="header-anchor"&gt;&lt;/a&gt;AWS Cloud Infrastructure (Terraform IaC)
&lt;/h3&gt;&lt;p&gt;&lt;em&gt;Terraform | AWS | IAM | VPC | Secrets Manager · Feb. 2025&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Provisioned 70+ AWS services via modular Terraform on a live account: least-privilege IAM policies, Secrets Manager integration, multi-service network architecture across EC2, RDS, VPC, S3, and 60+ additional services.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="evpnvxlan-spine-leaf-datacenter-fabric"&gt;&lt;a href="#evpnvxlan-spine-leaf-datacenter-fabric" class="header-anchor"&gt;&lt;/a&gt;EVPN/VXLAN Spine-Leaf Datacenter Fabric
&lt;/h3&gt;&lt;p&gt;&lt;em&gt;FRRouting | GNS3 | BGP EVPN | Linux iproute2 · 2026&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Deployed EVPN/VXLAN overlay on GNS3 with FRRouting (BGP EVPN, OSPF underlay), Route Reflector, and MP-BGP L2VPN; validated MAC/IP distribution via Wireshark; identified VXLAN attack surface: BGP EVPN route poisoning and frame injection via underlay access.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="-bug-bounty--security-research"&gt;&lt;a href="#-bug-bounty--security-research" class="header-anchor"&gt;&lt;/a&gt;🐛 Bug Bounty &amp;amp; Security Research
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Active Researcher — HackerOne | Intigriti | Bugcrowd&lt;/strong&gt; (public and private programs) · Mar. 2024 – Present&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Severity&lt;/th&gt;
&lt;th&gt;Finding&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Critical (CVSS 9.1)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Unauthenticated account creation chained with Django DEBUG mode leaking cloud credentials and JWT secrets, then BOLA/IDOR to full attendee PII exfiltration (CWE-200, CWE-284)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;High — OAuth ATO&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;redirect_uri validation bypass on GitLab SSO flow — 1-click account takeover on an artifact repository via authorization code grant misconfiguration&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;High — SSRF&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Host Header auth bypass on a global advertising platform; reached live Kubernetes microservice returning production data (CWE-918)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Medium — Info Disclosure&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Exposed Swagger UI, Spring Boot Actuator, internal IP leakage on enterprise IoT/B2B SaaS; extracted API constants from obfuscated JS bundles&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Medium — Credential Exposure&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Unauthenticated AI API keys, search credentials, and internal endpoints live on global e-commerce infrastructure (CWE-548)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Medium — Admin Exposure&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;JBoss/WildFly admin console on telecoms infrastructure; AD FS and WS-Trust endpoint enumeration with timing analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Methodology:&lt;/strong&gt; Subfinder, Amass, httpx, Shodan, Feroxbuster, ffuf, gau, Katana, truffleHog, Burp Suite Professional; OWASP Top 10, OWASP API Security Top 10, CWE classification.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-ctf--labs"&gt;&lt;a href="#-ctf--labs" class="header-anchor"&gt;&lt;/a&gt;🏁 CTF &amp;amp; Labs
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SecDojo National CTF:&lt;/strong&gt; Ranked #100 / 3,500+ participants — top 3% nationally. Techniques: LSASS credential dump, BloodHound attack paths, ADCS ESC11, NTLM relay.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MCP/Prompt Injection Lab (NebulaAssist):&lt;/strong&gt; Full attack chain — Nmap recon, SSE token extraction, hidden tool enumeration via prompt injection.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="-education"&gt;&lt;a href="#-education" class="header-anchor"&gt;&lt;/a&gt;🎓 Education
&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Period&lt;/th&gt;
&lt;th&gt;Degree&lt;/th&gt;
&lt;th&gt;Institution&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;2024 – Jun. 2027 (expected)&lt;/td&gt;
&lt;td&gt;State Engineer&amp;rsquo;s Degree in Cybersecurity &amp;amp; Network Infrastructure — Bac+5 / EQF Level 7&lt;/td&gt;
&lt;td&gt;EMSI — École Marocaine des Sciences de l&amp;rsquo;Ingénieur, Marrakech&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2022 – 2024&lt;/td&gt;
&lt;td&gt;Specialized Technician Diploma — Network &amp;amp; Systems Administration&lt;/td&gt;
&lt;td&gt;ISTA — Institut Spécialisé de Technologie Appliquée (OFPPT), Marrakech&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="-certifications"&gt;&lt;a href="#-certifications" class="header-anchor"&gt;&lt;/a&gt;📜 Certifications
&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Certification&lt;/th&gt;
&lt;th&gt;Issuer&lt;/th&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;AWS Certified Cloud Practitioner (CLF-C02)&lt;/td&gt;
&lt;td&gt;Amazon Web Services&lt;/td&gt;
&lt;td&gt;Jul. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Microsoft Certified: Cloud &amp;amp; AI Security Engineer Associate (SC-500)&lt;/td&gt;
&lt;td&gt;Microsoft&lt;/td&gt;
&lt;td&gt;Sep. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;AWS Certified Solutions Architect — Associate (SAA-C03)&lt;/td&gt;
&lt;td&gt;Amazon Web Services&lt;/td&gt;
&lt;td&gt;Oct. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="-languages"&gt;&lt;a href="#-languages" class="header-anchor"&gt;&lt;/a&gt;🌍 Languages
&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Language&lt;/th&gt;
&lt;th&gt;Level&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Arabic&lt;/td&gt;
&lt;td&gt;Native&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;French&lt;/td&gt;
&lt;td&gt;Professional proficiency (CEFR B2)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;English&lt;/td&gt;
&lt;td&gt;Professional proficiency (CEFR C1)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;</description></item></channel></rss>