Above the Cloudline
To defend a system you must first learn to take it apart. Offense is not the opposite of safety — it is its rehearsal.
Kernel-level offense, cloud-native defense — I build systems that live on the boundary between creation and destruction.
I'm Mohammed Yasin — a security engineer & digital architect. Five years shipping cloud-native platforms across Golang, Rust, Kubernetes, and eBPF, from kernel-level research to enterprise architecture.
I build systems that are not just functional, but extraordinary — where security meets elegance and infrastructure becomes invisible.
With five years engineering cloud-native platforms at scale, I work fluently across Golang, Rust, Kubernetes, and eBPF. My range runs from kernel-level security research to enterprise cloud architecture — and I design every system to push the boundary of what's possible without ever losing sight of the people who depend on it.
To defend a system you must first learn to take it apart. Offense is not the opposite of safety — it is its rehearsal.
The best infrastructure disappears. When the kernel, the network, and the runtime all hold, the work that remains is the only work that ever mattered.
Location & geospatial services for Kroger's delivery network — real-time routing and zone optimization with haversine math over a distributed PostgreSQL/PostGIS + YugabyteDB store and Redis caching.
AI-driven video analytics platform — real-time visual pattern detection across media and surveillance feeds, built on Kafka ingestion and Golang consumer services with a PostgreSQL analytics layer.
Self-service cloud provisioning platform letting internal banking teams deploy containerized workloads on a secure microservices architecture, with compliance guardrails baked into every deployment path.
Runtime security enforcement for the AccuKnox SaaS platform and the open-source KubeArmor engine — workload hardening, sandboxing, and least-permissive policies via LSMs (BPF-LSM, AppArmor).
An MCP server exposing offensive-security tooling to AI agents — autonomous reconnaissance, exploitation, and reporting through a standardized protocol interface.
A dual-module eBPF research framework demonstrating offensive rootkit techniques alongside defensive runtime auditing — a controlled environment for Linux-kernel exploration.
An eBPF-based offensive toolkit for network discovery, process hiding, and container breakouts — built for stealthy red-team assessments of Kubernetes environments.
Kernel-level behavioral containment for AI agents using eBPF and LSM — monitoring and restricting autonomous actions at the syscall layer before they touch the system.
A Ring-4-to-Ring-0 firmware research platform that pairs real-world bootkit techniques with matching detection engines — a closed loop modeling threats like BlackLotus, LogoFAIL, and CosmicStrand so every attack is both reproducible and detectable.
A security enforcer pairing eBPF syscall monitoring with WebAssembly-based policies — kernel-level observability and portable, cross-platform workload protection in one engine.
An eBPF-based telecom security research framework spanning 2G through 5G — intercepting and analyzing cellular protocols with paired offensive tooling and defensive detection for rogue towers, downgrade attacks, and IMSI catchers.