exec_iq
إنّ الأمورَ لها ربٌّ يدبّرها 🤍
The profile behind the handle.
exec_iq
ALI AL-AKBAR · Iraq · since May 2023
Elite, top-ranked researcher with a multi-year disclosure streak. Open to private invitations and collaborative engagements.
“One of our most impactful and reliable researchers. Dozens of valid findings across web, API, mobile, and cloud — including several high-severity issues that drove real fixes. Excellent, reproducible write-ups.”
“Researcher has been a valuable asset with the discovery of many vulnerabilities successfully reported to the organization. We look forward to working with them again.”
“Good report — clear, accurate, and easy-to-follow reproduction steps. This made it straightforward to validate the issue. Nice work.”
“Hacker was very thorough and tested many different facilities of the program. Communicated well and easy to work with.”
ALI AL-AKBAR, hunting the edges of trust.
Cybersecurity Researcher · Offensive Security Specialist
My approach blends hands-on exploitation with strategic risk assessment — ensuring discovered weaknesses translate into measurable security improvements.
1,126 validated vulnerabilities uncovered across 115 organizations, delivering actionable intelligence across finance, tech, and government sectors.
- #1 — Iraq National Leaderboard (2024 · 2025 · 2026)
- #1 Worldwide — OWASP XSS
- #1 Globally — VDP 2025 Q1
- #9 Worldwide — Q3 Global Leaderboard
- Team Iraq — Arab World Cyber (AWC 2024)
ExecHawk — A self-built, fully autonomous AI bug-bounty operator.
Reasoning-first. Tools are its hands; the model is the mind. It hunts, proves, and reports — end to end.
Autonomous Hunting
Runs the full loop unattended — recon to disclosure — with human-grade judgement at each gate.
DeepSeek Reasoning Core
A deep-think model drives every decision. No rigid pipelines — the mind leads, tools follow.
179 Pentest Tools via MCP
Burp · nuclei · ffuf · sqlmap · katana · subfinder · httpx · amass — orchestrated over 7 MCP servers.
703 Tradecraft Skills
A curated skill library: per-class playbooks, payloads, bypass tables, disclosed-report patterns.
Deep-Think Escalation
Escalates to max reasoning on hard targets, then de-escalates to stay cost-aware.
Per-Domain Memory
389+ learned facts in persistent, per-target memory — every probe, trap and win is remembered.
Auto PoC + Direct Submit
Generates reproducible PoCs and writes HackerOne-style reports straight to disk.
Cost-Aware Routing
Routes each step to the right model tier — flash for scale, pro-think for the kill.
The model is the mind; the tools are its hands. No rigid, hardcoded pipelines — ExecHawk reasons about each target and reaches for the right capability, escalating to deep-think only when a target fights back.
Every probe, trap, and win is written to per-domain memory, so it gets sharper on a target the longer it hunts.
Recon to disclosure, unattended.
- 01Recon
Map the attack surface — subdomains, hosts, JS, endpoints, secrets.
- 02Map
Model auth, roles, tenants, and object graphs. Find the trust boundaries.
- 03Exploit
Probe IDOR/BOLA, SSRF, authz, injection — model-guided, not brute-forced.
- 04Prove
Build a clean, reproducible PoC. Confirm impact. Kill false positives.
- 05Report
Write the disclosure, attach evidence, submit to HackerOne.
Tools I build & open-source.
Battle-tested extensions born from real bug-bounty work — free and open on GitHub.
Disclosed work & resolved reports.
A selection of resolved findings — the concept is shown, while titles, targets and PoCs stay withheld under private disclosure.
The numbers, verified.
All-time impact, straight from HackerOne.