Personnel File · 001

IHEB
ENNACHET.

▌ AKA IHEB NACHET · FOUNDER & CEO · 0xdeadbeef · 0xslayer
SOFTWARE ENGINEER · MOBILE & WEB DEVELOPER · PENETRATION TESTER

Iheb Ennachet — also written Iheb Nachet — is a full-stack software engineer, mobile & web developer and penetration tester from Sousse, Tunisia. He founded Evosec Consulting in 2019 to build web and mobile products the way an attacker would want them built — properly — for clients in France, the United States and beyond.

► Work with Iheb Read Full Bio
Based In
Sousse, Tunisia · clients FR / US
Also known as
Iheb Nachet · 0xdeadbeef · 0xslayer
Languages
EN · AR · FR
Availability
24/7 Emergency · By appointment
Primary Contact
+216 55 737 390
Stack
Laravel · Next.js · React Native · Flutter
"I write the code and I break the code. If you've only ever done one of those, you don't really understand the other." — IHEB ENNACHET · CEO, EVOSEC CONSULTING
Biography

THE RECORD.

Written by Iheb himself — no PR polish, no exec bio ghost-written by a committee.

Iheb Ennachet founded Evosec Consulting on a simple conviction: the people who build your software should be the same people who know how to break it — without the consultant theater.

From Sousse, Tunisia. Iheb started coding as a kid, shipped his first production web apps as a teenager, and got into security the way most developers do — by finding out how badly his own early code could be broken. Two decades later he still does both, every week: building web applications and mobile apps for clients, and attacking them before release.

As a developer, his day-to-day stack is Laravel and Next.js on the web, React Native and Flutter on mobile — with Swift and Kotlin when a product needs to go native. He has architected multi-tenant SaaS platforms, fintech onboarding apps, B2B marketplaces and e-commerce storefronts, and he cares as much about a clean data model and a 95+ Lighthouse score as he does about a clean pentest report.

As a penetration tester, known in the security community as 0xdeadbeef and 0xslayer, he covers the full offensive stack: web and mobile application testing, API security, wireless, reverse engineering, malware analysis and red team operations. That combination — an engineer who understands the attacker's mindset — is the whole reason Evosec exists.

You'll see his name written both ways — Iheb Ennachet on official documents, Iheb Nachet on many profiles and among French-speaking colleagues. Same person. Today he runs Evosec Consulting, leads product builds for clients in France and the USA, performs hands-on security engagements, and contributes to open-source projects. He's a strong believer in data privacy, individual data ownership, and the Free & Open-Source Software (FOSS) movement. The majority of his personal setup runs on open-source software.

Want to chat or discuss a project? Reach him directly at iheb.ennachet@devsolve-agency.com or on WhatsApp at +216 55 737 390.

Experience Record

THE TRACK RECORD.

Two decades of building and breaking software — all still active.
2019 — present

Evosec Consulting

FOUNDER · CEO

Built a web & mobile development agency with an in-house offensive security team — shipping Laravel, Next.js and React Native products for clients in France and the USA, pentested before launch.

Ongoing

Security Research

INDEPENDENT RESEARCHER

Vulnerability research, malware analysis, open-source contributions. Known as 0xdeadbeef and 0xslayer in the security community.

Throughout career

Web & Mobile Engineering

FULL-STACK · MOBILE DEVELOPER

Laravel, Next.js, React Native, Flutter, Swift, Kotlin. SaaS platforms, fintech apps, marketplaces and e-commerce shipped to production for clients in France and the USA.

Capabilities

FULL STACK.

Development first, security second, never one without the other — non-exhaustive.
▌ Web Development
  • Laravel / PHP — APIs, multi-tenant SaaS, queues, billing
  • Next.js / React / TypeScript — SSR, app router, design systems
  • Node.js services · REST & GraphQL APIs
  • PostgreSQL · MySQL · Redis — schema design & performance
  • Headless e-commerce · Stripe payments · webhooks
  • Performance: Core Web Vitals, 95+ Lighthouse targets
▌ Mobile Development
  • React Native & Expo — iOS + Android from one codebase
  • Flutter — custom, animation-heavy UI
  • Swift / SwiftUI & Kotlin / Compose for native modules
  • Secure storage (Keychain / Keystore), biometrics, pinning
  • Offline sync, push notifications, deep links
  • App Store & Google Play submission, EAS / Fastlane CI
▌ Offensive Security
  • Wireless security testing & manual packet inspection
  • Manual and automated web application testing (OWASP)
  • Vulnerability assessment & penetration testing (VAPT)
  • Red Team as a Service (RTaaS)
  • Reverse engineering & binary analysis
  • Malware analysis & threat intelligence
▌ DevSecOps & Infrastructure
  • AWS · Vercel · Docker · GitHub Actions
  • Secure SDLC — threat modelling & secure design reviews
  • SAST / dependency auditing in CI (Semgrep, npm/composer audit)
  • Python — tooling, automation, security scripts
  • C++ — systems programming & binary work
  • Open-source contributions
▌ Security Operations
  • Threat detection & incident response
  • ASV-approved vulnerability scanning (PCI DSS)
  • SIEM implementation & tuning
  • Security monitoring & alerting
  • Forensics & root cause analysis
  • Compliance readiness (PCI DSS, ISO 27001)
▌ Beliefs & Values
  • Data privacy & individual data ownership
  • Free & Open-Source Software (FOSS)
  • Decentralised cryptography & security
  • Transparency in security research
  • Education-first approach to security
  • No vendor bingo — results over marketing
Q & A

ASKED & ANSWERED.

Questions Iheb gets on every call, answered once so he can stop repeating himself.

Iheb Nachet or Iheb Ennachet?

Both. "Ennachet" is the spelling on my passport; "Nachet" is the shorter form I've used on profiles, handles and with French-speaking colleagues for years. Search either one — you'll find me.

Do you actually build the apps, or just secure them?

I build them. I've been a developer longer than I've been a pentester. On most Evosec projects I'm in the architecture decisions and in the pull requests — Laravel and Next.js on the web, React Native or Flutter on mobile. The security work is what makes the builds better, not a separate business.

Why 0xdeadbeef and 0xslayer?

Started as handles in the security community during my early hacking years. They stuck. They're a reminder of where I came from — learning to break things to understand how to build them better.

Why did you start Evosec Consulting?

I kept seeing the gap between what security vendors promised and what they delivered. Most firms were selling dashboards and compliance theatre, not real security. I started Evosec to do it differently — hands-on testing, honest reporting, actionable remediation.

Do you still do hands-on work yourself?

Yes — both sides. I still write production code and I'm still the primary operator on most security engagements. If you stop doing the work, you stop being qualified to run the company.

What's your approach to responsible disclosure?

I report vulnerabilities to vendors first, give reasonable time for patching, then publish. I've contributed to the security of multiple platforms this way. Security improves when researchers and vendors work together instead of against each other.

What keeps you going?

The technical challenge, honestly. Security is one of the few fields where you have to think like a criminal to build effective defences. That adversarial mindset is what gets me out of bed. The fact that it protects real people and organisations is what keeps me doing it.

WORK WITH IHEB DIRECTLY.

Web app, mobile app, or penetration test — one call with the engineer who'll actually do the work. Clients in France and the USA, in English or French.

► Book a Free Call