Skip to main content

About Me

Ifraheem Hassan

Cybersecurity Researcher

About

I work where intelligence meets security.

I'm a cybersecurity professional operating at the intersection of threat intelligence, OSINT, and offensive security. My work spans leading analyst teams, conducting penetration tests for government organizations, and building automation tools that turn raw intelligence into actionable insight.

I've delivered OSINT workshops for the Ministry of Foreign Affairs, guest lectures at leading universities, and hands-on training on dark web investigations, wireless attacks, and ISO 27001 compliance. My master's research focuses on integrating large language models into OSINT workflows for attack surface mapping and threat correlation.

What drives my work is a practical question: how do we find what adversaries expose, understand what it means, and respond before it becomes an incident?

Expertise

What I Do

Threat Intelligence

Collecting, analyzing, and disseminating intelligence on cyber threats to support proactive defense and strategic decision-making.

  • Cyber threat analysis
  • Intelligence collection & dissemination
  • Threat trend monitoring
  • Executive reporting

OSINT & Investigations

Gathering and analyzing open-source data from social media, forums, dark web channels, and public records to uncover risks and attribute threats.

  • OSINT collection & analysis
  • SOCMINT & WEBINT
  • Dark web monitoring
  • Attack surface mapping
  • Workshop delivery & training

Offensive Security

Conducting penetration tests and red team operations using automated and manual techniques to identify vulnerabilities before adversaries do.

  • Penetration testing
  • Red team operations
  • Vulnerability assessment
  • Network exploitation
  • Executive reporting

Security Research

Designing and building security tools, AI-powered intelligence frameworks, and novel approaches to automated threat analysis.

  • Security tool development
  • LLM/AI integration for OSINT
  • Vulnerability research
  • Academic research & thesis work

Cybersecurity Engineering

Building automated tools for log analysis, vulnerability tracking, reconnaissance, and threat monitoring that integrate into security operations.

  • Tool development & automation
  • Log extraction & forensics
  • Real-time monitoring systems
  • CVE tracking & mitigation

Governance & Compliance

Implementing security frameworks, conducting risk assessments, and ensuring compliance with international standards.

  • ISO 27001 compliance
  • Risk assessment & treatment
  • NIST & PCI-DSS frameworks
  • Security auditing
  • ISMS implementation

Education

Academic Background

20232025

Master's in Information Security

NUST

Coursework Completed

Focus: OSINT frameworks, threat intelligence, AI/LLM integration

A Novel Integrated OSINT Framework Using Advanced LLM

Thesis research on an AI-powered OSINT framework leveraging LLMs for attack surface mapping, intelligence correlation with CTI/SOC/red team workflows, and automated reporting.

20192023

Bachelor's in Cyber Security

Air University

ISO27k1 Toolkit for Auditing

AI-based risk mitigation chatbot that automates Statement of Applicability and Gap Analysis report generation for ISO 27001 compliance auditing.

Teaching

Guest Lectures & Training

Air University

OSINT and Threat Intelligence

MS & PhD Cyber Security students

Air University

Dark Web Investigations

MS & PhD Cyber Security students

Air University

ISMS and ISO 27001 Compliance

MS Cyber Security students

NUST

Wireless Attacks

MS & PhD students specializing in network security

Mentorship

Student Supervision

Integrated Offensive OSINT Framework

Supervising BS Cyber Security students in developing an integrated offensive OSINT framework, providing guidance on attack surface mapping and intelligence gathering techniques.

IPDR Analysis for Threat Intelligence

Supervising a final year project on Internet Protocol Detail Record (IPDR) analysis, focusing on cyber threat intelligence and anomaly detection.

Stack

Tools & Technologies

Organized by domain — expertise over tool lists.

Intelligence

OSINTSOCMINTIMINTWEBINTCyber IntelligenceDark Web IntelligenceSpiderfootSeekerGreconCensys

Offensive Security

Penetration TestingVulnerability AssessmentRed TeamingNmapNucleiInvictiNessusSqlmapNiktoHashcat

Engineering

PythonAutomationLLM IntegrationLog AnalysisForensics

Governance

ISO 27001NISTPCI-DSSCTDISRRisk ManagementISMS