Skip to content
View AGL2304's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report AGL2304

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AGL2304/README.md
Purple Team banner

Georges Lionel ANANI

Purple Team Engineer | Red + Blue | DevSecOps | GRC

Typing SVG

LinkedIn GitHub TryHackMe Email Portfolio

Profile views GitHub followers


identity:
  name:        Georges Lionel ANANI
  role:        Purple Team Engineer (in training)
  school:      Ecole-IT, Amiens, Mastere Architectures Systemes, Reseaux & Securite
  current:     Stagiaire Transformation Numerique & Conformite @ IRFA-APISUP
  location:    Ile-de-France (mobile), ecole a Amiens
  target:      Alternance Purple Team / GRC, septembre 2026
  rhythm:      3 semaines entreprise / 1 semaine ecole
  english:     C1 (certifie Gymglish)
  tryhackme:   agl23 | Top 1% mondial | 185 salles | 5 parcours certifies
  portfolio:   https://mon-portfolio-mocha-ten.vercel.app/

🟣 Purple Team : une posture a 360 degres

Etudiant en Mastere Expert Architectures Systemes, Reseaux & Securite a l'Ecole-IT.

Le Purple Team n'est pas un compromis entre l'attaque et la defense : c'est une vision unifiee de la securite. Je construis des competences a la fois en Red Team (penetration, exploitation, simulation adverse) et en Blue Team (detection, monitoring, reponse a incident), avec une couche GRC (audit, conformite, gestion des risques) pour traduire le technique en gouvernance.

"To defeat an attacker, you must think like one, then build defenses that stop yourself."


πŸŸ₯ Red Team : Offensive Security

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  RECONNAISSANCE      β”‚  Nmap, Gobuster, OSINT, enumeration       β”‚
β”‚  EXPLOITATION WEB    β”‚  SQLi, XSS, SSRF, LFI, IDOR (OWASP Top 10)β”‚
β”‚  EXPLOITATION RESEAU β”‚  Pivoting, lateral movement, AD attacks   β”‚
β”‚  POST-EXPLOITATION   β”‚  Persistance, privilege escalation        β”‚
β”‚  REPORTING           β”‚  CVSS scoring, plan d'action priorise     β”‚
β”‚  LABS                β”‚  TryHackMe Top 1%, HackTheBox, RootMe     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Burp Suite Metasploit Nmap sqlmap Gobuster John the Ripper Hydra MITRE ATT&CK


🟦 Blue Team : Defense & Detection

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  MONITORING          β”‚  SIEM, analyse de logs, detection anomalieβ”‚
β”‚  RESPONSE            β”‚  Triage, containment, investigation       β”‚
β”‚  CVE INTELLIGENCE    β”‚  Veille NVD, scoring, priorisation        β”‚
β”‚  HARDENING           β”‚  Durcissement systemes, PSSI, hygiene SI  β”‚
β”‚  APPSEC              β”‚  SAST, DAST, audit de code, threat model  β”‚
β”‚  CONFORMITE          β”‚  ISO 27001, RGPD, NIS 2, DORA, HDS, CRA   β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Wireshark Trivy Snyk Splunk OWASP ZAP Nessus OpenVAS EBIOS RM


βš™οΈ DevSecOps : securite dans le cycle CI/CD

               Commit
                 β”‚
                 β–Ό
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  GitHub Actions / GitLab CI                             β”‚
  β”‚  β”œβ”€ SAST (analyse statique : Semgrep, Bandit, Sonar)    β”‚
  β”‚  β”œβ”€ Dependency scan (Snyk / Dependabot)                 β”‚
  β”‚  └─ Secret scanning (Gitleaks)                          β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                 β–Ό
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  Build & Package                                        β”‚
  β”‚  β”œβ”€ Docker build multi-stage                            β”‚
  β”‚  └─ Trivy : scan image CVE                              β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                 β–Ό
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  Deploy (K8s / AWS / GCP / OVH)                         β”‚
  β”‚  β”œβ”€ DAST automatise (OWASP ZAP)                         β”‚
  β”‚  └─ Monitoring & alerting                               β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Docker Kubernetes GitHub Actions GitLab CI Ansible GCP AWS


πŸ’» Stack technique

Langages

Python TypeScript JavaScript PHP Java C/C++ Bash SQL

Frameworks

FastAPI Django Laravel Symfony React Vue.js Node.js


πŸ’Ό Experience pro

Stagiaire Transformation Numerique & Conformite | IRFA-APISUP, Amiens, depuis 01/2026

  • Cartographie des usages Microsoft 365 sur ~150 utilisateurs et 8 entites, puis matrice de risques RGPD priorisee en 3 vagues
  • Audit de ~200 comptes SharePoint / Teams, soit 12 ecarts au moindre privilege et un plan de remediation 90 jours aligne PSSI
  • Production de 4 livrables d'audit et animation de 3 sessions de sensibilisation cyber / RGPD pour publics non-tech
  • Pilotage de la conduite du changement sur ~40 collaborateurs (fiches reflexes, FAQ, dashboard KPI/KRI hebdomadaire)

Stages precedents : DevOps & Dev Web (METIO ex Iteracode, 04-08/2025) | Cybersecurite Audit & Pentest (WildCode-Solutions, 02-04/2025)


πŸ—‚οΈ Projets

⭐ Projet phare : honeypot-m1spro : honeypot medium-interaction multi-services (SSH, HTTP, FTP, Telnet) conteneurise, avec une chaine complete collecte, classification comportementale (4 profils), enrichissement (GeoIP, AbuseIPDB) et dashboard Grafana. Exports defensifs (Sigma, STIX 2.1, blocklist iptables), scripts d'auto-attaque (Hydra, Nikto) et CI/CD durcie (ruff, bandit, semgrep, pytest, Trivy). Conteneurs non-root, read-only, cap-drop ALL, alignes NIST SP 800-190.

πŸ”΄πŸ”΅ Securite

Repo Description Stack
⭐ honeypot-m1spro Honeypot multi-services (SSH, HTTP, FTP, Telnet) conteneurise : pipeline collecte, classification 4 profils, enrichissement GeoIP + AbuseIPDB, dashboard Grafana, exports Sigma / STIX / blocklist Python 3.12, FastAPI, PostgreSQL, Docker, Grafana
⭐ vulnshop TP DevSecOps : app Flask volontairement vulnerable (13 failles) + pipeline GitLab CI/CD complet (Bandit, pip-audit, Trivy, SonarQube, ZAP), remediation jusqu'a 0 CVE et quality gate Passed Python, Flask, GitLab CI, Docker
Red_Teams_VS_Blue_Teams Simulation d'affrontement Red vs Blue : scenarios d'attaque et contre-mesures defensives TypeScript, Node.js, Docker
Projet_CVE_Trackers Plateforme CTI maison : collecte et qualification de ~50 CVE/jour depuis NVD + MITRE ATT&CK Next.js 15, Prisma, Docker
Secure_Chat Messagerie chiffree bout-en-bout : cle privee navigateur, WebSockets, JWT FastAPI, WebSocket, bcrypt
securevault Gestionnaire de secrets chiffres : JWT, audit log, RBAC Python, FastAPI, PostgreSQL
πŸ”’ Keystroke Security Auditor Etude des vecteurs d'attaque entrees clavier et contre-mesures Python, Endpoint Security

βš™οΈ DevOps & Cloud

Repo Description Stack
cloudninja_agl Scripts d'automatisation cloud et CI GitHub Actions Node.js, Bash
MonProjetDevOps Stack Docker pour orchestration et environnements multi-conteneurs Dockerfile, Compose
Projet_DevOps Infrastructure DevOps complete : containerisation, orchestration, CI/CD Docker, K8s, Jenkins

🌐 Web & GRC

Repo Description Stack
Mon_Portfolio Portfolio multi-services (db + backend + frontend) et livrables GRC publics ISO 27001 / EBIOS RM. Demo live FastAPI, React, Postgres
CodeArena_EcoleIT_Pisc Plateforme de competition de code temps reel : sandbox Docker, leaderboard Socket.io Vue 3, Node.js, MongoDB
Travel_Guides Guides de voyage collaboratifs avec carte interactive Symfony, Twig, PostgreSQL
parcours_qr_code Parcours de visite via QR codes (musees, tourisme culturel) Laravel, Blade, MySQL
Reservations_AGL Systeme de reservation en ligne PHP, MySQL, Bootstrap
πŸ”’ Portail IRFA-APISUP Dashboard KPI/KRI, fiches reflexes et FAQ cyber pour 40 collaborateurs SharePoint, Power BI, React

Et 15+ autres sur mon profil GitHub.


πŸ“Š GitHub Stats

Stats Top Langs

Streak

Graphe d'activite

🐍 Le snake devore mes contributions

Snake animation des contributions GitHub

🎯 Focus actuel : apprentissages 2026

  • πŸ”΄ Red Team : preparation eJPT (eLearnSecurity Junior Penetration Tester)
  • 🟦 Blue Team : pratique sur splunk-fundamentals (TryHackMe) et IR playbooks
  • 🟣 GRC : auto-formation ISO 27001 Lead Implementer et EBIOS Risk Manager (ecole)
  • ☁️ Cloud : AWS Cloud Practitioner et bases GCP / GKE
  • 🀝 Open-source : contribution active a un projet securite (en recherche)

πŸ† Certifications & formations

Formation / Certification Organisme Statut
Mastere Expert Architectures Systemes, Reseaux & Securite Ecole-IT, Amiens πŸ”„ En cours (2025-2026)
Bachelor Informatique, specialite DevOps Ecole-IT, Amiens βœ… 2024-2025
Licence Informatique (Maths & Info) Ibn Tofail, Kenitra (Maroc) βœ… 2023-2024
TryHackMe : Top 1% mondial, 185 salles, 22 badges TryHackMe 🟒 Actif (agl23)
EBIOS Risk Manager Formation ecole, Mastere πŸ”„ En cours
ISO 27001 Lead Implementer Auto-formation πŸ”„ En cours
eJPT, Junior Penetration Tester eLearnSecurity (INE) 🎯 En preparation
AWS Cloud Practitioner AWS 🎯 En preparation
Anglais C1, certifie Gymglish Gymglish βœ… Actif

🧭 Ce que je cherche

Type Domaine Rythme Disponibilite
Alternance Purple Team, Pentest, DevSecOps, GRC 3 sem entreprise / 1 sem ecole 🟒 Septembre 2026
Projets open-source Securite, outils d'audit, CTI libre 🟒 Ouvert
CTF collaboratif Red vs Blue, challenges libre 🟒 Toujours partant

πŸ“« On echange ?

Telephone et adresse postale communiques sur demande via LinkedIn ou email.


"The best defense is a good offense, and understanding both is what makes a Purple Teamer."

TryHackMe

Popular repositories Loading

  1. Snake_game Snake_game Public

    Java

  2. Travel_Guides Travel_Guides Public

    Twig

  3. BiblioExchange BiblioExchange Public

    PHP

  4. ToDo_App ToDo_App Public

    PHP

  5. Battle_python Battle_python Public

    Python

  6. docker_twitter docker_twitter Public

    PHP