Skip to content
View bIackr0se's full-sized avatar

Highlights

  • Pro

Block or report bIackr0se

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bIackr0se/README.md

Hey! I'm Jaafer

blog • linkedin • email

AI red teaming • security engineering

papers cve owasp

About

Security engineer and PhD researcher in adversarial machine learning. I break models to make them harder to break: red-teaming ML models, LLM agents, and RAG pipelines, and engineering the ML-driven detection that defends critical infrastructure against attackers who adapt.

Current work

  • AutoMCP - CoAnalyst: a LangGraph research analyst for OT/IT alert triage with human review
  • Agentarium - a local, read-only map of agent work, with project islands, mission boards, and evidence replay
  • Watching an SSRF walk out of the sandbox - full writeup of CVE-2026-58196, host-side SSRF in an MCP runtime
  • Doctoral research - evaluating and hardening ML-based intrusion detection against adaptive evasion; security of agentic LLM SOC analysts in OT networks
  • Vulnerability research on AI-agent infrastructure: MCP servers, agent runtimes, coding assistants, disclosed responsibly
  • Field notes - writeups land here as disclosures go public

Arsenal

skills

AI red teaming : evasion, model extraction, data poisoning, prompt injection, robustness evaluation

Security engineering : ML-driven detection, SIEM, IDS (Suricata, Zeek), MITRE ATT&CK mapping

Critical infrastructure : OT/ICS protocols (Modbus, CAN, PROFINET), SCADA, fieldbus security

Vulnerability research : AI-agent infrastructure, exploitation, responsible disclosure

Certs : eJPTv2 • ISC2 CC (+ CC exam development volunteer) • NVIDIA Exploring Adversarial Machine Learning

Contact

Research collaboration, responsible disclosure, or an interesting target model: jaafer.rahmani@owasp.org

Pinned Loading

  1. AutoMCP AutoMCP Public

    CoAnalyst: a LangGraph research analyst for OT/IT alert triage with human review.

    Python 2

  2. agentarium agentarium Public

    A local, read-only world for your AI agents.

    TypeScript 2

  3. fine-print fine-print Public

    Inspect recorded changes Claude left out of its answer, inside Claude Code.

    TypeScript