FalehSec Penetration testing · Riyadh, Saudi Arabia

Mohammed Al-Faleh

Penetration tester — web applications and APIs

Riyadh, Saudi Arabia · reports in English or Arabic · remote worldwide

I test web applications and APIs by hand, and I write up what I find in enough detail that your engineers can fix it without a follow-up call. Five hands-on offensive security certifications, including CompTIA Security+ (CE) and three dedicated penetration testing qualifications.

You work with me directly. There is no sales layer between you and the person testing your code.

How I work

The method matters more than the tool, so this is the whole of it rather than a list of acronyms.

Scope firstWe agree exactly what is in scope, what authentication roles exist, and what "sensitive" means for your business, before anything is tested. Most disappointing reports come from a scope argument, not a technical one.
Manual firstAutomated scanners are useful for coverage and terrible for judgement. They find what is there; they do not tell you whether it is reachable, and they cannot chain two findings into a real attack path. I use scanners for enumeration and do the testing myself.
Business logic, specificallyAccess control, IDOR, broken authentication, excessive data exposure, mass assignment, workflow abuse. These are where real breaches come from, and they are the findings a scanner will not produce.
Proof, not assertionsEvery finding ships with reproduction steps and evidence, not "an attacker could potentially". If I cannot demonstrate it, it does not go in the report as a confirmed issue.
Ranked by business riskNot by CVSS. The finding that exposes other tenants' data outranks the authenticated reflected XSS that only you can trigger.
Retest includedAfter you fix things, I retest every finding to confirm it is resolved and that the fix did not introduce a regression. Available within 3 months at 30% of the original engagement fee.

What you get

Credentials

Public work

Claims about security work are worth very little without something to check, so here is something checkable.

I built an exploited-vulnerability triage corpus that joins CISA's Known Exploited Vulnerabilities catalog with CVSS vectors and EPSS exploitation probabilities — 545 pages, one per vulnerability, each figure linked to the source it came from. Two findings from it: 1,181 of CISA's 1,726 entries have been exploited for more than two years, and only 49 are genuinely urgent on any given day.

It is documented in full, including which figures are copied, which are arithmetic, and what none of it tells you. If you intend to use it, you should be able to check my arithmetic rather than take it on trust.

What I am not

I am not a scanner reseller. If you want a report generated by a tool, this is the wrong engagement and I will say so.

I do not do compliance paperwork as a deliverable. PCI, SOC 2 and ISO 27001 evidence collection is a documentation exercise with a testing component, not a penetration test. I will help where testing is genuinely required, but I will not sell you a checkbox.

I do not promise you will not be breached. Nobody can. A test is a snapshot of one system on one day, and it is evidence of diligence, not a guarantee.

Getting in touch

m45faleh@falehsec.dev · +966 56 215 5628
LinkedIn · NDA available before any detail is exchanged · fixed quote and clear timeline before anything starts

If you are not sure which engagement you need, the exposure check takes a few minutes, and the threat feed shows what is being exploited this week.