Skip to content
View zer0dayf's full-sized avatar
🩻
Focusing
🩻
Focusing

Highlights

  • Pro

Block or report zer0dayf

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
zer0dayf/README.md

Typing SVG

🕵️‍♂️ Who Am I?

I'm Öner Efe Güngör, an offensive-security focused Penetration Tester & Vulnerability Researcher based in Ankara, Türkiye.

I started programming at a young age and eventually moved into cybersecurity through game modding, Kali Linux, and security tooling. Today, my main focus is:

  • Web & API Penetration Testing
  • Vulnerability Research
  • Exploit / PoC Development
  • Application Security
  • CVE / N-day Analysis
  • Reverse Engineering

I currently work on security assessments, vulnerability validation, technical reporting, and remediation verification.


🔬 Vulnerability Research

  • CVE-2026-19532 — HAVELSAN Liman MYS
    Credited finder of a CWE-22 Path Traversal vulnerability. Developed a reproducible PoC and supported remediation validation.

  • CVE-2026-15013 — miniOrange SAML SSO Auth Bypass
    Independent PoC published on Exploit-DB — EDB-52668.

  • CVE-2026-65008 — Grav CMS Authenticated RCE
    Python exploit / PoC published on Exploit-DB — EDB-52669.

I also work on CVE reproduction, N-day analysis, validation tooling, and controlled security research.


🛠️ Projects

SecTestGen — Security regression-testing platform combining static analysis, SBOM data, reachability analysis, and automated vulnerability tests.

Flipper_Jam — Wireless-security research tooling for controlled lab environments.

Ghost-Audit — BadUSB / HID attack-surface research for controlled Windows security testing.


🎯 Certifications

  • eWPTX — Web Application Penetration Tester eXtreme
  • Blue Team Junior Analyst
  • Google Cybersecurity Professional Certificate
  • IBM Cybersecurity Analyst Professional Certificate

🏴 CTFs

  • 🥈 ADS'26 CTF — 2nd Place
  • SAS CTF 2026 — Kaspersky
    • Türkiye: 4th
    • Regional: 11th / 362
    • Global: 54th / 1,662

⚙️ Tech

Python Bash SQL PHP Linux Docker

Burp Suite Nmap Nessus ffuf Wireshark

Semgrep Bandit CodeQL CycloneDX


🧠 Outside Security

Game development, reading, music production and gaming.


📊 Overall GitHub Presence

Profile Stats
Overview Stats
Language Stats


👁️ Watching You!

followers

🚀 Open to connecting with security researchers, penetration testers, and developers.

Pinned Loading

  1. Ghost-Audit Ghost-Audit Public

    The ultimate BadUSB recon payload designed for Flipper Zero, Rubber Ducky, and Digispark targeting Windows.

    C++ 12 2

  2. AceTrack-AI AceTrack-AI Public

    A high-performance Blackjack analytics engine powered by YOLOv11 and Temporal Majority Voting for real-time card tracking.

    Python

  3. Student-Depression-Classification-DL Student-Depression-Classification-DL Public

    Binary classification model for Student Depression Analysis. Featuring ANN architecture, dropout regularization, and 85% test accuracy. 💻🚀

    Jupyter Notebook

  4. Flipper_Jam Flipper_Jam Public

    WiFi security research tool for Flipper Zero + ESP32. Deauth, beacon spam, evil twin, targeted & beacon portal attacks (Google, Instagram, Facebook, Telegram, Starbucks, McDonald's) with captive po…

    C++ 15 1

  5. nexus-sdlc nexus-sdlc Public

    AI-powered SDLC orchestration — multi-agent workflows on a visual canvas with tiered LLM routing, human-in-the-loop approvals, and real-time cost tracking

    TypeScript 2