haitam lazaar / lazaarsec
Security & Vulnerability Researcher

Haitam Lazaar

Vulnerability Discovery · Linux Kernel & Systems · Security Architecture · Rabat, Morocco

01 // Background & Profile

OVERVIEW

Hi, I'm Haitam! I love security research and I actively do bug bounty. I focus on auditing complex software, finding zero-days and logic bugs, digging into memory corruption and Linux kernel systems, and responsibly disclosing security issues to vendors.

My work spans proactive vulnerability research, low-level Linux systems programming, and high-assurance security engineering:

Vulnerability Research & Auditing

Conducting source-code reviews, capability verification audits, and business logic analysis. Disclosed 15 CVE advisories across enterprise web platforms and systems libraries (including GNU libextractor).

Linux Kernel & Systems Engineering

Developing high-performance C Linux kernel modules using Netfilter hooks for stateful deep packet inspection, dynamic stealth port-knocking, and designing zero-trust database architectures.

02 // Academic Education & Credentials

QUALIFICATIONS
INPT — Institut National des Postes et Télécommunications2025 – 2028 (In Progress)
State Engineering Degree candidate — Cybersecurity and Digital Trust (ICCN)
Rabat, Morocco · Advanced Cryptography, Network Protocols & Operating Systems Security
CPGE Ibn Ghazi (MPSI / MP)2023 – 2025
Classes Préparatoires aux Grandes Écoles — Mathematics, Physics & Engineering Sciences
Rabat, Morocco · Intensive preparation in analysis, linear algebra, and discrete computation

Industry Certifications:

03 // Responsible Vulnerability Disclosure Policy

ETHICS & STANDARDS

I follow ethical and coordinated vulnerability disclosure standards (aligned with ISO/IEC 29147 guidelines). When auditing software and third-party vendors:

1. Direct Vendor Notification

Disclosures are sent confidentially to security teams with detailed reproduction steps.

2. 60–90 Day Remediation

Vendors are provided an industry-standard window to develop and distribute patches.

3. Fix Verification

Patches are independently validated against reproduction cases to confirm complete fixes.

4. Coordinated Publication

Advisories and CVE IDs are coordinated with CNAs before public release.

04 // Contact & Professional Profiles

CONNECT

Whether you are reaching out regarding recruitment opportunities, research collaboration, or security inquiries, feel free to connect through any of the channels below:

Direct & Disclosures
Open-Source Code & Labs
Professional Network
Looking for encrypted reporting keys?