Iheb Ennachet — also written Iheb Nachet — is a full-stack software engineer, mobile & web developer and penetration tester from Sousse, Tunisia. He founded Evosec Consulting in 2019 to build web and mobile products the way an attacker would want them built — properly — for clients in France, the United States and beyond.
"I write the code and I break the code. If you've only ever done one of those, you don't really understand the other." — IHEB ENNACHET · CEO, EVOSEC CONSULTING
Iheb Ennachet founded Evosec Consulting on a simple conviction: the people who build your software should be the same people who know how to break it — without the consultant theater.
From Sousse, Tunisia. Iheb started coding as a kid, shipped his first production web apps as a teenager, and got into security the way most developers do — by finding out how badly his own early code could be broken. Two decades later he still does both, every week: building web applications and mobile apps for clients, and attacking them before release.
As a developer, his day-to-day stack is Laravel and Next.js on the web, React Native and Flutter on mobile — with Swift and Kotlin when a product needs to go native. He has architected multi-tenant SaaS platforms, fintech onboarding apps, B2B marketplaces and e-commerce storefronts, and he cares as much about a clean data model and a 95+ Lighthouse score as he does about a clean pentest report.
As a penetration tester, known in the security community as 0xdeadbeef and 0xslayer, he covers the full offensive stack: web and mobile application testing, API security, wireless, reverse engineering, malware analysis and red team operations. That combination — an engineer who understands the attacker's mindset — is the whole reason Evosec exists.
You'll see his name written both ways — Iheb Ennachet on official documents, Iheb Nachet on many profiles and among French-speaking colleagues. Same person. Today he runs Evosec Consulting, leads product builds for clients in France and the USA, performs hands-on security engagements, and contributes to open-source projects. He's a strong believer in data privacy, individual data ownership, and the Free & Open-Source Software (FOSS) movement. The majority of his personal setup runs on open-source software.
Want to chat or discuss a project? Reach him directly at iheb.ennachet@devsolve-agency.com or on WhatsApp at +216 55 737 390.
Built a web & mobile development agency with an in-house offensive security team — shipping Laravel, Next.js and React Native products for clients in France and the USA, pentested before launch.
Vulnerability research, malware analysis, open-source contributions. Known as 0xdeadbeef and 0xslayer in the security community.
Laravel, Next.js, React Native, Flutter, Swift, Kotlin. SaaS platforms, fintech apps, marketplaces and e-commerce shipped to production for clients in France and the USA.
Both. "Ennachet" is the spelling on my passport; "Nachet" is the shorter form I've used on profiles, handles and with French-speaking colleagues for years. Search either one — you'll find me.
I build them. I've been a developer longer than I've been a pentester. On most Evosec projects I'm in the architecture decisions and in the pull requests — Laravel and Next.js on the web, React Native or Flutter on mobile. The security work is what makes the builds better, not a separate business.
Started as handles in the security community during my early hacking years. They stuck. They're a reminder of where I came from — learning to break things to understand how to build them better.
I kept seeing the gap between what security vendors promised and what they delivered. Most firms were selling dashboards and compliance theatre, not real security. I started Evosec to do it differently — hands-on testing, honest reporting, actionable remediation.
Yes — both sides. I still write production code and I'm still the primary operator on most security engagements. If you stop doing the work, you stop being qualified to run the company.
I report vulnerabilities to vendors first, give reasonable time for patching, then publish. I've contributed to the security of multiple platforms this way. Security improves when researchers and vendors work together instead of against each other.
The technical challenge, honestly. Security is one of the few fields where you have to think like a criminal to build effective defences. That adversarial mindset is what gets me out of bed. The fact that it protects real people and organisations is what keeps me doing it.
Web app, mobile app, or penetration test — one call with the engineer who'll actually do the work. Clients in France and the USA, in English or French.