bash — 0xmrerror@terminal: ~
0xmrerror@terminal:~$ ./init_session.sh
> Skandar Hadrich
Security Engineering Intern · ICT Engineering Student @ ENIT · Malware Analyst
Malware Analysis Reverse Engineering Penetration Testing eBPF · VMI SOC · Blue Team CTF Player
Top 1% TryHackMe Global
8-Stage Sandbox Pipeline
4 Certifications
5+ Security Projects
uptime: calculating...
0xmrerror@terminal:~$ cat whoami.txt
whoami.txt
# handle 0xmrerror
# real_name Skandar Hadrich
# location Tunis, Tunisia 🇹🇳
# affiliation ENIT · Keystone Group
# focus Malware Analysis · RevEng · PenTest
# tryhackme Top 1% Global
# clubs SECURINETS ENIT · G2FOSS
I'm a cybersecurity-focused ICT Engineering student at ENIT, currently serving as a Security Engineering Intern at Keystone Group where I built a solo, end-to-end 8-stage nested-VM malware analysis pipeline integrating eBPF syscall tracing, Volatility3 VMI, C2 sinkholing, and automated MITRE ATT&CK attribution. My toolkit spans the full spectrum — from Ghidra and GDB for static/dynamic reversing to Wazuh + Shuffle for SOC automation. I compete in CTFs through SECURINETS ENIT and actively contribute to open-source security projects via G2FOSS.
🏆 TryHackMe: Top 1% globally ranked
0xmrerror@terminal:~$ ls -la /arsenal
🕸️ Web Security
SQLi / XSS / SSRF
88%
Burp Suite
85%
LFI / RFI / SSTI
82%
API Security
75%
Burp Suite Nikto ffuf sqlmap
🔬 Reverse Engineering
Ghidra / IDA
90%
GDB / pwndbg
87%
Frida / JADX
80%
angr (symbolic exec)
72%
Ghidra GDB angr Frida JADX
🦠 Malware Analysis
Static Analysis
92%
Dynamic / Sandbox
90%
eBPF / VMI
85%
MITRE ATT&CK Mapping
88%
Speakeasy Volatility3 de4dot INetSim DNSChef
📡 Network & Forensics
Wireshark / PCAP
88%
Nmap / Recon
92%
Memory Forensics
82%
Log Analysis / SIEM
85%
Wireshark Bettercap Nmap Wazuh Splunk
💻 Programming
Python
93%
C / C++
85%
Bash / Shell
90%
JavaScript / Node.js
78%
Python C/C++ Bash JavaScript C#
🏗️ Infrastructure
QEMU / KVM
88%
Docker
82%
Linux (Kali / Ubuntu)
95%
CI/CD DevSecOps
77%
QEMU-KVM Docker VMware Linux iptables
0xmrerror@terminal:~$ cat /var/log/experience.log
Keystone Group · Jul 2026 – Sep 2026 · Tunis, TN
Security Engineering Intern — Malware Analysis
  • Architected an 8-stage automated malware analysis pipeline: static triage → de4dot deobfuscation → Speakeasy emulation → live QEMU-KVM detonation → eBPF syscall capture → Volatility3 VMI → MITRE ATT&CK mapping → PDF report.
  • Correlated host eBPF syscall traces with VMI on QEMU-KVM; patched KUSER_SHARED_DATA.TickCount to defeat anti-sandbox timing checks.
  • Deployed C2 sinkhole layers using iptables, DNSChef, and INetSim to capture malware network traffic and extract IOCs at scale.
  • Automated threat attribution by matching IOCs against VirusTotal, AlienVault OTX, and MalwareBazaar using LSH clustering and automated PDF report generation.
Tunisie Telecom · Jun 2025 – Jul 2025 · Sfax, TN
Network Operations Intern
  • Triaged and resolved 15+ daily technical support tickets, maintaining network uptime across multiple customer sites.
  • Configured and provisioned network modems at scale, reducing average per-unit configuration time by 20%.
ENIT — National School of Engineers of Tunis · 2024 – Present
ICT Engineering Student — Telecommunications & Networking
  • Cybersecurity specialization: malware analysis, network security, cryptography, and secure systems design.
  • Active member of SECURINETS ENIT (cybersecurity club) and G2FOSS (open-source software group).
0xmrerror@terminal:~$ ls -la ~/projects/
Open-Source SOC Automation
Production-grade SOC integrating Wazuh (SIEM) and Shuffle (SOAR) for automated incident response. Custom detection rules and playbooks validated via simulated attacks: brute force, lateral movement, and privilege escalation scenarios.
Wazuh Shuffle SOAR MITRE ATT&CK Python Docker
Wi-Fi Security Research
Demonstrated WPA2 and ARP-spoofing vulnerabilities using Wireshark and Bettercap in a controlled lab environment. Documented MITM attack vectors with proposed mitigations: 802.1X, HSTS enforcement, and certificate pinning.
Wireshark Bettercap Kali Linux WPA2
Village Under Attack — C++ Game
Real-time terminal strategy game engineered in C++ using OOP principles, non-blocking I/O, NPC pathfinding algorithms, and collision detection. Demonstrates systems programming and algorithmic design outside a security context.
C++ OOP Non-blocking I/O Pathfinding
Face Recognition — Arduino + Python
Real-time face recognition pipeline using Python (OpenCV) and an Arduino-connected camera module. Triggers automated hardware responses on match — demonstrates embedded security and computer vision integration.
Python OpenCV Arduino Embedded
0xmrerror@terminal:~$ ls -lt ~/writeups/ | head -20
01.
Blue — EternalBlue (MS17-010) Root
Easy TryHackMe ⏱ 8 min read
02.
Pickle Rick — Web App LFI & Command Injection
Easy TryHackMe ⏱ 6 min read
03.
LFI to RCE via Apache Log Poisoning
Medium Hack The Box ⏱ 18 min read
04.
Reversing ELF — Ghidra + GDB + XOR Decode
Medium TryHackMe ⏱ 15 min read
05.
Malware Sandbox Anti-Analysis Bypass Techniques
Hard Original Research ⏱ 25 min read
→ click any writeup to read inline  ·  more writeups published regularly
0xmrerror@terminal:~$ cat ~/certs/verified.json | jq .
TryHackMe
Jr Penetration Tester
2025
Verified
TryHackMe
SOC Level 1
2026
Verified
TryHackMe
DevSecOps
2026
Verified
Cisco Networking Academy
CCNA: Introduction to Networks
2025
Verified
0xmrerror@terminal:~$ cat /etc/contact.conf
PGP key available on request  ·  Response time < 24h