Open to security internships

Ahmed Limam

Network engineering student at INSAT, Tunis. Penetration tester at SmartSkills.

I study how networks are supposed to work, and spend most of my time learning how they fail. That currently means web application and Active Directory penetration tests for real clients, CTFs on weekends, and writing up what I learn on my blog.

Experience

Penetration Tester & Security Auditor — SmartSkills

Tunis, July 2025 – present

  • Run security engagements for client organizations — 30+ this year across web application tests and Active Directory assessments, with 70% of them turning up high-severity findings or worse: RCE, IDOR, authentication bypass, AD privilege escalation paths.
  • Assess client infrastructure systematically and triage findings by exploitability and business impact, so the loudest bug is not automatically the first fix.
  • Write the client-facing reports: full exploitation chains translated into remediation steps the owning team can act on.

Projects

Autonomous pentesting agent

Python, LangGraph — 2026

A LangGraph tool-calling agent that chains offensive tooling through a recon, exploitation, and reporting pipeline, with a registry-driven catalog that injects whatever tools are installed straight into the agent's prompts.

15+ deterministic exploit modules — SQL and NoSQL injection, XSS, SSTI, XXE, SSRF, path traversal, command injection, JWT forging, TOTP — driven by declarative payload libraries, with evidence-verified findings auto-rendered into markdown and HTML reports.

Self-hosted VPN mesh

Headscale, Tailscale, Python, Azure — 2025

A private VPN mesh with no third-party coordination server: Headscale as a self-hosted Tailscale control plane, exit nodes on Azure VMs across several regions, and a Python backend for switching exit nodes on demand.

A Linux Electron client replaces the usual CLI setup with a one-click connect. It is what I use every day.

Related code on GitHub

Smaller experiments live on GitHub: DLL sideloading in C++, a Rust multiplayer server, and others.

Achievements

Securinets Tunisia — technical team

2025 – 2026

Member of the national technical team: helping organize CTF competitions and building challenges for the digital forensics and OSINT categories across multiple CTFs.

Education

Network Engineering — INSAT

Institut National des Sciences Appliquées et de Technologie, Tunis, 2022 – 2027

Five-year engineering degree, network engineering major.

Skills

Networking

TCP/IP, UDP, DNS, DHCP, VPN, NAT, subnetting, VLANs

Security

Web application penetration testing (SQLi, XSS, CSRF, IDOR, SSRF, auth bypass, business-logic flaws), Active Directory attack paths, reverse engineering, digital forensics

Tools

Burp Suite, Nmap, Wireshark, Ghidra, IDA, Autopsy, Volatility

Programming

Python, Java, JavaScript, PHP, C, C++, Rust, SQL, Bash

Contact

Email is the fastest way to reach me. I graduate in 2027 and am open to internships in security.