I’m Kaan Gültekin — a software engineering student, software developer, and cybersecurity researcher based in Türkiye.

I specialise in automation-first tooling, offensive security research, and open-source projects that serve both red-team testing and defensive security awareness. Most of my work starts the same way: something is tedious, error-prone, or invisible, and it shouldn’t be.

What I work on

Offensive frameworks and red-team automation. AutoPWN-Suite is a comprehensive offensive automation framework that folds common offensive tasks into a single workflow. It’s my most widely adopted open-source contribution, cited and used across the security community.

USB and hardware exploitation. A set of BadUSB proof-of-concepts demonstrating peripheral-based attack vectors — browser interaction, Meterpreter session establishment, and lightweight VBScript techniques. All of it exists to help defenders understand threats that arrive over a physical port, and all of it is lab-only.

PowerShell tooling and research. Open-source utilities for network scanning and fast file discovery, plus private research into fileless in-memory execution used to develop detection and mitigation strategies. The fileless work is not publicly released.

Recon and OSINT. CompanyEnum automates company profiling and presents results through a clean web UI — useful for red-team recon and blue-team validation alike.

Things that just needed to exist. Çanakkale Hat & Sefer is a mobile-first PWA for my city’s bus network, and Pulsemap makes live network traffic visible as an animated force-directed graph.

Browse all projects →

Research focus

My research bridges offensive innovation and defensive application. Rather than building exploits for their own sake, I design projects that expose blind spots in detection, give blue teams something concrete to test against, and produce material worth teaching from.

  • Fileless and in-memory attacks — analysing adversary TTPs to improve EDR and SOC visibility
  • USB attack vectors — demonstrating hardware threat paths end to end
  • Offensive automation — studying how automation changes post-exploitation
  • Disclosure and collaboration — responsible vulnerability reporting, including to Discord

Recognition

  • TryHackMe — ranked #1 in Turkey, top 11 globally
  • Discord — recognised on their Security page for a reported vulnerability
  • AutoPWN-Suite — widely cited and adopted open-source offensive framework
  • Pentest Magazine — invited contributor, writing on open-source pentesting tooling
  • Google Cybersecurity Professional Certificate (v2) — 8-course program, 130+ hours
  • Google IT Automation with Python Professional Certificate (v1) — 6-course program, 130+ hours

Certifications

Google Cybersecurity Professional Certificate (v2)

Eight courses and 130+ hours of guided training through Coursera, covering incident response, network security, threat analysis, SIEM management, and Python automation, with hands-on labs throughout.

Foundations of Cybersecurity · Play It Safe: Manage Security Risks · Connect and Protect: Networks and Network Security · Tools of the Trade: Linux and SQL · Assets, Threats, and Vulnerabilities · Sound the Alarm: Detection and Response · Automate Cybersecurity Tasks with Python · Put It to Work: Prepare for Cybersecurity Jobs

View credential on Credly →

Google IT Automation with Python Professional Certificate (v1)

Six courses and 130+ hours through Coursera, covering Python programming, version control with Git, troubleshooting and debugging, configuration management, and cloud automation.

Crash Course on Python · Using Python to Interact with the Operating System · Introduction to Git and GitHub · Troubleshooting and Debugging Techniques · Configuration Management and the Cloud · Automating Real-World Tasks with Python

View credential on Credly →

Ethics

I operate under a strict ethics-first framework, and it isn’t negotiable:

  • Controlled lab testing only
  • Defensive documentation accompanying every PoC
  • Responsible vulnerability disclosure
  • Educational, transparent intent
Research published here is intended for defenders, educators, and authorised testing. Some work — notably the fileless PowerShell research — is deliberately withheld from public release.

Get in touch