Skip to content
View dragonked2's full-sized avatar
:octocat:
Top 1%
:octocat:
Top 1%

Block or report dragonked2

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dragonked2/README.md
Ali Essam β€” Cybersecurity Expert & Penetration Tester banner

Ali Essam

Cybersecurity Expert Β· Penetration Tester Β· Bug Bounty Hunter Β· Founder & CEO, DragonMeta


8+ years experience Focus areas Location



LinkedIn Website Email X YouTube



πŸš€ About Me

I'm Ali Essam, a cybersecurity professional with 8+ years of hands-on experience finding and closing security gaps in web applications, APIs, and cloud infrastructure.

I'm the Founder & CEO of DragonMeta, where I lead penetration testing, vulnerability research, and red-team engagements for organizations that need real, evidence-based security work β€” not a checkbox audit. My reports have earned Hall of Fame recognition on multiple bug bounty platforms.

I split my time between offensive security engagements, building open-source security tooling, and mentoring newer researchers through my bug bounty roadmap.


πŸ” What I Do

πŸ’» Penetration Testing

  • Web & API security β€” deep assessments surfacing critical vulnerabilities (SQLi, XSS, CSRF, RCE, SSRF, IDOR, and more)
  • Cloud security β€” auditing AWS and Azure environments for misconfigurations and exposure
  • Red teaming β€” simulating real attacker behavior to test detection and response, not just find bugs

🎯 Bug Bounty Hunting

  • Active researcher on HackerOne, Bugcrowd, and private programs
  • Multiple Hall of Fame placements for responsibly disclosed vulnerabilities
  • Focus on developing original exploitation methodologies rather than relying on scanners alone

πŸ›  Security Research & Tooling

  • Building and maintaining open-source security tools used by the bug bounty community
  • WAF bypass research and detection-evasion techniques
  • Automation of recon and vulnerability discovery in Python

🌟 Projects

Egyscan Dons

Misr metax

Project What it does
Egyscan A web vulnerability scanner built to find critical issues across web applications quickly and reliably.
Roadmap A structured guide for people starting out in bug bounty hunting β€” methodology, mindset, and resources.
Dons A command-line tool that scans JavaScript files for exposed API keys, credentials, and secrets.
Misr A vulnerability scanner covering SQLi, XSS, RCE, LFI, and SSRF, with subdomain enumeration and secrets detection.
metax An advanced XSS vulnerability detector.
Alphacode A terminal-native AI coding agent β€” multi-model orchestration, parallel agent swarms, 40+ tools.

πŸ† Certifications

Certification Issued
AWS Certified Security – Specialty Sep 2023
Google Cybersecurity Professional Certificate Feb 2024
Certified Cloud Security Professional (INE) Oct 2024
eLearnSecurity Web Application Penetration Tester eXtreme (eWPTXv2) Jun 2024
Certified Threat Hunting Professional Jul 2024
Certified Digital Forensics Professional Jun 2024
Certified Incident Responder May 2024
Certified OPSWAT Cybersecurity Professional Apr 2024
Certified OPSWAT WebApp Exploitation Expert May 2024
Certified Cybersecurity Analyst Jul 2023
eLearnSecurity Junior Penetration Tester (eJPT) Jun 2024
Certified OWASP API Security Top 10 Jul 2024

πŸ“ Skills & Tools

Penetration Testing Web applications Β· APIs Β· Cloud environments Β· Network security

Bug Bounty Platforms HackerOne Β· Bugcrowd Β· Cobalt

Exploitation & Analysis Tools Burp Suite Β· Metasploit Β· Wireshark Β· Nmap Β· OWASP ZAP

Programming & Scripting Python Β· PHP Β· JavaScript Β· SQL

Cloud Security AWS Β· Azure

Vulnerability Management Nessus Β· Qualys Β· OpenVAS


πŸ“Š GitHub Stats

Ali Essam's GitHub stats Ali Essam's GitHub streak

πŸ“« Connect With Me

🌐 Website dmeta.me
πŸ“© Email support@dmeta.me
πŸ”— LinkedIn linkedin.com/in/dragonked2
πŸ™ GitHub github.com/dragonked2
🐦 X (Twitter) @3lyy313
πŸ“Ί YouTube @3ly313

πŸ“œ License

All code and documentation in my repositories are released under the MIT License unless otherwise noted.


"Stay curious, stay secure, and always be one step ahead of the threat."


Thanks for stopping by. Always open to collaborating on security research, bug bounty work, or open-source tooling. πŸš€


Pinned Loading

  1. Egyscan Egyscan Public

    Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious threats. Let's delve into the tasks and functions tha…

    Python 301 59

  2. Roadmap Roadmap Public

    Bug Bounty Roadmap

    38 7

  3. Dons Dons Public

    Dons Js Scanner is a sleek command-line tool that hunts for hidden treasuresβ€”API keys, credentials, and secretsβ€”lurking in the JavaScript of websites. Its vibrant ASCII art logo welcomes users to a…

    Python 89 24

  4. Misr Misr Public

    Misr: The Ultimate Vulnerability Scanner

    Python 16 4

  5. metax metax Public

    MetaX - Advanced XSS Vulnerability Detector

    Python 15 4

  6. alphacode alphacode Public

    Possibly the greatest coding agent ever built. Blazing-fast terminal UI, multi-model orchestration, swarm coordination, and 40+ tools.

    Rust 38 4