MGMohamedGhoniem
  • Work
  • Services
  • Experience
  • Blog
Available
CV
Open to opportunities
WorkServicesExperienceBlogDownload CV
MG

© 2024 Mohamed Ghoniem. All rights reserved.

TwitterGitHubLinkedIn

Case Study

CYBER.COM — Security Suite

Cybersecurity Platform

SaaS ProductLiveFull-stack2024
Live Demo Source Code
CYBER.COM — Security Suite
Threat intelligence dashboardCore Feature
Attack surface scanner screenVulnerability
Incident response playbook runnerIncident Response
PreviewPreview

Project Purpose

A next-generation cybersecurity platform built to give security teams complete, real-time visibility across their entire attack surface. The goal was to consolidate threat detection, vulnerability scanning, and incident response into one unified, intelligent workspace — cutting mean time-to-response from hours to minutes.

My RoleLead Frontend+ UI/UX Design
DurationMar – May 20202 months
Team Size3 PeopleCross-functional
StatusLiveIn Production

Collaborators

AM

Ahmed Mostafa

(Backend Engineer)

SR

Sara Rashed

(UI/UX Designer)

Tools & Technologies

HTML5
CSS3
JavaScript
Figma
Git
Vercel

Key Features

1

Real-time Telemetry Stream

Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.

2

Real-time Telemetry Stream

Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.

3

Real-time Telemetry Stream

Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.

4

Real-time Telemetry Stream

Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.

5

Real-time Telemetry Stream

Sub-second event streaming via WebSockets with automatic fallback to HTTP polling for constrained networks.

6

Zero-Trust DB Policies

Row-Level Security enforced at the PostgreSQL driver layer ensuring multi-tenant data boundaries.

7

High-Density Charting

Custom D3-based rendering pipeline built for token-level visual styling and 60fps interaction speed.

App Screens

Threat intelligence dashboard01

Core Feature

Threat Intelligence Dashboard

The command centre — every active threat visible at a glance. Data refreshes every 3 seconds via WebSocket without a full page reload, keeping the UI snappy even under heavy load. Charts are built with a custom renderer for full token-level control over colours and spacing.

WebSocketReal-timeD3.js
Attack surface scanner screen02

Vulnerability

Attack Surface Scanner

Drill into any asset across any time range with a filtering system that composes like code — stack filters, compare exposure windows, and export to CSV without leaving the view. The query engine behind it was the single hardest engineering problem on this project.

CVE LookupCSV exportFilter composer
Incident response playbook runner03

Incident Response

Automated Playbook Runner

Teams configure YAML-based playbooks and the platform auto-triggers actions on alert conditions — isolating endpoints, revoking tokens, notifying Slack. Built on a serverless edge runtime for sub-200ms trigger latency.

YAML playbooksAuto-remediationEdge runtime

Problems & How We Solved Them

Real-time alerts causing UI jank at high event rates

At peak load (~600 events/sec) the UI was re-rendering on every WebSocket message, causing visible frame drops. We moved all data aggregation to a Web Worker off the main thread, batched updates into 300ms windows, and switched chart renders to requestAnimationFrame — dropping jank from 38% of frames to under 2%.

Frame jank reduced from 38% → 2% of frames

CVE database queries timing out on large date ranges

Queries spanning 90+ days were hitting 7–10 second response times. We introduced a TimescaleDB hypertable for time-series data, added composite indexes on (tenant_id, timestamp), and pre-computed hourly rollups in a background job. Most queries now return in under 350ms.

Query time: 7–10s → under 350ms

Multi-tenant data isolation at the query level

Early implementation used application-level filtering — one missed WHERE clause could leak data across tenants. We switched to PostgreSQL Row Level Security policies enforced at the DB driver level, so isolation is guaranteed regardless of what the application layer does.

Tenant isolation moved to DB-level — no application trust required

Outcomes

0

Threat detection time

0

Lighthouse score

0

Active users at launch

0

Client satisfaction

Next Project

FLIXIFY — Entertainment Hub