Hi, my name is Youssef Ourgous, a 29 year old Cybersecurity Specialist with two Bachelor's degrees in Cybersecurity, currently pursuing a Master's degree in Systems Engineering & Cybersecurity in Casablanca, Morocco!

Youssef Ourgous
Youssef working at a multi-screen setup during a CTF
About

Self-driven, with a strong interest in Cyber Security

Hi, I am Youssef, located in Casablanca, Morocco. My interest has always been in Cyber Security. I want to ensure that security is a top priority in our quickly developing world, and I would like to contribute to a more secure environment for the organisations and people who rely on it.

I keep myself relevant by solving Capture The Flags, most recently at the national final of the Morocco Academia Cyber Competition 2026, by building and breaking my own SOC homelab, and by following the latest IT developments. I always keep a close eye on newly discovered vulnerabilities and like to turn them into detection rules. I hold two Bachelor's degrees in Cybersecurity, I'm CCNA & CCNA Security certified, and I'm now pursuing a Master's degree in Systems Engineering & Cybersecurity. I am someone who wants to make the world a more secure place for the next generation, even if it goes unnoticed.

Achievements

Competing at national level

28 March 2026

16th place: Morocco Academia Cyber Competition 2026

Grande Finale Nationale · organised by the DGSSI

Representing EST Casablanca, our team finished 16th out of 38 finalist teams from all 12 regions of Morocco in the national final, a 15-hour online CTF with 10 labs on IT and industrial machines, from basic to expert level.

16thof 38 teams
456points
4labs completed
Events

Learning from the community

ESTC · 40th anniversary seminar series

Séminaire Cybersécurité à l'ESTC : des constats qui interpellent 🔐

Ce matin, à l'École Supérieure de Technologie de Casablanca, le Pr. Yassine Maleh nous a livré une analyse complète du paysage cyber marocain.

Quelques points qui m'ont marqué :

  • Le cyber-espionnage est devenu un risque stratégique réel, avec des groupes comme APT21 qui collectent massivement des données auprès d'entreprises marocaines.
  • L'infiltration de données reste la brèche n°1 au niveau mondial, avec un coût moyen estimé à 4,4 M$ par incident en 2025.
  • L'internationalisation de la cybercriminalité rend la lutte encore plus complexe : on ne parle plus d'attaques isolées, mais d'une industrie organisée.

Au-delà des chiffres, ce qui ressort, c'est l'urgence de structurer une véritable stratégie nationale de cybersécurité, adaptée à notre contexte. Les échanges avec les participants ont également souligné l'importance de former davantage de profils spécialisés pour faire face à ces menaces.

Merci au Pr. Maleh pour cette intervention concrète et documentée. Et félicitations à l'ESTC pour ce cycle de séminaires dans le cadre de son 40ᵉ anniversaire — des initiatives qui contribuent réellement à élever le niveau de maturité cyber au Maroc.

24 July 2025 · Hassan II University of Casablanca

2nd Annual Meeting for Excellence in Parallel Student Activities

Proud to have taken part in the 2nd Annual Meeting for Excellence in Parallel Student Activities, organized by Hassan II University of Casablanca.

An inspiring event that celebrated the achievements of over 300 students from 17 institutions, highlighting the power of extracurricular engagement in shaping well-rounded university life.

Grateful to be part of this dynamic and innovative academic community.

Portfolio

Projects built to sharpen the defense

SOC Infrastructure – ELK & Wazuh SIEM

Full SOC build: 3-node Elasticsearch cluster across dual networks, Logstash pipelines normalizing firewall/auth/syslog events, Wazuh SIEM with UEBA and active response, and Kibana dashboards for geo-attack maps, brute-force heatmaps and IOC timelines.

SOC Alerting Pipeline – Elastic + n8n AI

End-to-end detection and response chain: an ES|QL rule in Elastic and an ElastAlert monitor detect SSH brute-force attempts, then a webhook triggers an n8n workflow where an AI agent enriches and formats the alert and notifies the team instantly on WhatsApp and Gmail.

High-Availability Homelab – Proxmox + Synology

2-node Proxmox VE 9 cluster with Synology DS420 shared NFS storage and HA Manager: pfSense, Ubuntu Server and FortiGate fail over automatically in under 3 minutes, with live migration and no network cut — downtime reduced by 95% vs a standalone setup.

Personal Homelab – SOC Training Environment

VLAN-segmented home lab on Proxmox (pfSense, FortiGate, Kali, Wazuh, ELK) with a low-interaction honeypot capturing real attacker TTPs, red-team attack scenarios mapped to MITRE ATT&CK, and a Wazuh/ELK detection stack correlating telemetry into threat intelligence.

AI-Based Network IDS – Machine Learning

Network intrusion detection system that classifies live traffic with Random Forest (99.89% accuracy) and Decision Tree (97.40%) models and a consensus verdict. A web dashboard shows normal vs attack traffic, lets you retrain the models, and sends automatic email alerts. Validated with a custom attack simulator (SYN port scans).

Kubernetes Security Lab

3-node Kubernetes cluster on Ubuntu 24.04 with Calico CNI, RBAC, NetworkPolicies and Prometheus/Grafana monitoring via Helm — aligned with COBIT IT governance controls and security best practices.

Guardian AI – Autonomous SOC

5-agent autonomous SOC built with Python, FastAPI, Redis Streams and LLMs to detect, correlate and automatically respond to threats through IP blocking on pfSense, with incident reports on a React dashboard — sub-second end-to-end detection and response.

Lab

Inside my homelab

The environments I build and run: a high-availability Proxmox cluster, a 3-node Elasticsearch SOC with custom detection rules, and an AI-assisted alerting pipeline. Click any image to enlarge it.

Case study · High availability

High-Availability Homelab: Proxmox VE + Synology NAS

Passionate about IT infrastructure and virtualisation, I built a complete homelab to experiment with high availability in conditions close to production.

< 3 minautomatic failover, tested
0network cuts during live migration
10+ dayscontinuous uptime
−95%downtime vs a standalone setup

Architecture

  • Proxmox VE 9.0.3 cluster (2 nodes)
  • Centralised storage on a Synology DS420 (3.7 TB over NFS)
  • HA Manager with automatic failover
  • Working live migration
  • 3 critical VMs protected by HA: pfSense, Ubuntu Server, FortiGate

Skills put into practice

  • Building a cluster and managing quorum
  • Configuring shared NFS storage
  • High availability and automatic failover
  • Live migration without interruption
  • Troubleshooting (time drift, NTP synchronisation…)

Next steps

  • Add a QDevice to strengthen 2-node quorum
  • Integrate a 3rd Proxmox node
  • Test Ceph for distributed storage
  • Monitoring with Prometheus + Grafana
  • Deploy OpenStack on an Ubuntu machine
  • Experiment with SDN (Software Defined Networking)
  • Centralise logs and network traffic in ELK (pfSense, Ubuntu…)

SOC & detection

AI-Based Network IDS

Services

What I bring to a security team

SOC & SIEM Engineering

I build and operate detection stacks with Wazuh, Suricata, Elasticsearch, Logstash and Kibana: log pipelines, correlation rules, UEBA, active response and dashboards that turn raw telemetry into alerts worth acting on.

Network Security

I design segmented networks with VLANs, pfSense and FortiGate firewalls, OpenVPN gateways and IDS/IPS (Snort, Suricata), hardening the perimeter and the paths between internal zones.

Identity & Access Management

I deploy FreeIPA and Active Directory with LDAP, Kerberos SSO and role-based access control, so every account has exactly the access it needs and nothing more.

Penetration Testing

I run vulnerability assessments and attack scenarios with Nmap, Burp Suite, Metasploit and Wireshark — from brute force to Kerberoasting and Pass-the-Hash — and deliver clear remediation reports.

Skills

The toolbox I work with every day

SIEM & Detection

WazuhSplunkElasticsearchLogstashKibanaSuricataSnort IDS/IPSFail2banMITRE ATT&CKZabbix

Offensive Security

NmapWiresharkBurp SuiteMetasploitKali Linux

Network Security

pfSenseFortiGateOpenVPNCisco IOSVLAN segmentation

Identity & Access

Active DirectoryFreeIPA / LDAPKerberos SSORBAC

Systems & Virtualization

LinuxWindows ServerVMware ESXiProxmoxDockerKubernetesNginxApache

Scripting & Automation

BashPythonPowerShellGit
Education

Academic background

Experiences

Work Experience

Jul – Aug 2021

Network Security Technician · Internship

Africa Verify · Casablanca, Morocco

  • Designed and deployed a segmented cybersecurity lab (6 network segments, pfSense firewall/IDS, vulnerable Active Directory) with Wazuh EDR, Splunk SIEM and Snort IDS mapped to MITRE ATT&CK.
  • Executed and validated 10+ attack scenarios: brute force, Kerberoasting, Pass-the-Hash, NTDS hash extraction and AD enumeration.
  • Developed "Guardian AI", a 5-agent autonomous SOC (Python, FastAPI, Redis Streams, LLMs) that detects, correlates and auto-responds to threats via pfSense IP blocking, with a React incident dashboard.