> For the complete documentation index, see [llms.txt](https://moe-3.gitbook.io/moex0-blog/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://moe-3.gitbook.io/moex0-blog/whoami/root-usr-moex0.md).

# /root/usr/moex0

<figure><img src="/files/EybNd0Syf59clCU3PdUV" alt=""><figcaption></figcaption></figure>

I’m Mo’men Mahmoud (aka Moe), a cybersecurity professional specializing in threat hunting and detection. My ultimate goal is to make a meaningful difference in the world through cybersecurity, so I’m always seeking new ways to learn and teach people and organizations how to understand, fight, and ultimately win against modern adversaries.

I didn’t start with a formal background in cybersecurity. In fact, my journey began in electronics and communications engineering, where I earned my bachelor’s degree, before I gradually transitioned into cybersecurity. Over the years, I’ve come to believe that knowledge and experience are most valuable when shared. That’s why I document my learning process here; to help others achieve (and perhaps even surpass) the same level of contributions to the field.

Beyond security, I love running, studying human psychology, and reading books/articles in different fields, such as self-improvement, career development, leadership, management, and business.

#### **Key highlights about my journey so far:**

* **BlackHat MEA Trainer (2024):** I had the privilege of delivering threat hunting training at BlackHat in Riyadh, teaching participants practical methodologies and tools to combat sophisticated cyber threats and nation-state actors.
* **Designing Real-World APT Scenarios:** I designed and executed an end-to-end emulation of APT29, a project that took two months of diligent planning, configuration, and execution. I wrote a detailed analysis report investigating this scenario as an incident responder. This experience deepened my understanding of APT29's TTPs and how to defend against them. You can find the report at "[Investigating APT29 Exploiting TeamCity CVE-2024-27198](https://moe-3.gitbook.io/moex0-blog/articles/investigating-apt29-exploiting-teamcity-cve-2024-27198)".&#x20;

{% hint style="info" %}
**Socials**:

<img src="/files/xEx6XK1AT8U5SkQv6CLL" alt="" data-size="line"> : [moemen.mahmoud00@gmail.com](mailto:undefined)

<img src="/files/LUhNhX120XsGolm9OKCv" alt="" data-size="line"> : <https://www.linkedin.com/in/moemenmahmoud/>

<img src="/files/Taa9oToZvO30RBeA0p0I" alt="" data-size="line"> : <https://x.com/moex0_1>
{% endhint %}

***

I’m always open to feedback and discussions about the content here. Feel free to reach out to me anytime through my socials.&#x20;
