I'm Ali Essam, a cybersecurity professional with 8+ years of hands-on experience finding and closing security gaps in web applications, APIs, and cloud infrastructure.
I'm the Founder & CEO of DragonMeta, where I lead penetration testing, vulnerability research, and red-team engagements for organizations that need real, evidence-based security work β not a checkbox audit. My reports have earned Hall of Fame recognition on multiple bug bounty platforms.
I split my time between offensive security engagements, building open-source security tooling, and mentoring newer researchers through my bug bounty roadmap.
|
|
|
| Project | What it does |
|---|---|
| Egyscan | A web vulnerability scanner built to find critical issues across web applications quickly and reliably. |
| Roadmap | A structured guide for people starting out in bug bounty hunting β methodology, mindset, and resources. |
| Dons | A command-line tool that scans JavaScript files for exposed API keys, credentials, and secrets. |
| Misr | A vulnerability scanner covering SQLi, XSS, RCE, LFI, and SSRF, with subdomain enumeration and secrets detection. |
| metax | An advanced XSS vulnerability detector. |
| Alphacode | A terminal-native AI coding agent β multi-model orchestration, parallel agent swarms, 40+ tools. |
| Certification | Issued |
|---|---|
| AWS Certified Security β Specialty | Sep 2023 |
| Google Cybersecurity Professional Certificate | Feb 2024 |
| Certified Cloud Security Professional (INE) | Oct 2024 |
| eLearnSecurity Web Application Penetration Tester eXtreme (eWPTXv2) | Jun 2024 |
| Certified Threat Hunting Professional | Jul 2024 |
| Certified Digital Forensics Professional | Jun 2024 |
| Certified Incident Responder | May 2024 |
| Certified OPSWAT Cybersecurity Professional | Apr 2024 |
| Certified OPSWAT WebApp Exploitation Expert | May 2024 |
| Certified Cybersecurity Analyst | Jul 2023 |
| eLearnSecurity Junior Penetration Tester (eJPT) | Jun 2024 |
| Certified OWASP API Security Top 10 | Jul 2024 |
|
Penetration Testing Web applications Β· APIs Β· Cloud environments Β· Network security Bug Bounty Platforms HackerOne Β· Bugcrowd Β· Cobalt Exploitation & Analysis Tools Burp Suite Β· Metasploit Β· Wireshark Β· Nmap Β· OWASP ZAP |
Programming & Scripting Python Β· PHP Β· JavaScript Β· SQL Cloud Security AWS Β· Azure Vulnerability Management Nessus Β· Qualys Β· OpenVAS |
| π Website | dmeta.me |
| π© Email | support@dmeta.me |
| π LinkedIn | linkedin.com/in/dragonked2 |
| π GitHub | github.com/dragonked2 |
| π¦ X (Twitter) | @3lyy313 |
| πΊ YouTube | @3ly313 |
All code and documentation in my repositories are released under the MIT License unless otherwise noted.
"Stay curious, stay secure, and always be one step ahead of the threat."
Thanks for stopping by. Always open to collaborating on security research, bug bounty work, or open-source tooling. π





