Junior Penetration Tester
Practical offensive-security foundation
Umut Can Yurdayardım · Penetration Tester
I’m a penetration tester and vulnerability researcher with a genuine passion for security. I assess systems, validate vulnerabilities, and report findings clearly so they can be understood and fixed.
01 · Certifications
eJPT, eWPTX, and CEH mark different stages of my development in offensive security, supported by the hands-on work I continue to do.
Practical offensive-security foundation
Advanced web exploitation and assessment
Broad attack-surface and security methodology
02 · Vulnerability research
Two CVE records assigned through independent vulnerability research and responsible coordination with the affected vendors.
Published through the CVE Program following independent research and responsible disclosure.
Published through the CVE Program following independent research and responsible disclosure.
03 · Selected projects
Open-source security tooling shaped around practical assessment workflows, local control, and useful output.
WIRELESS · LINUX
A local-first wireless penetration testing dashboard that brings Wi-Fi analysis, handshake capture, rogue AP, and authorized lab workflows into one real-time interface.
ANDROID · STATIC ANALYSIS
A fast, fully offline APK analyzer for triaging secrets, weak cryptography, unsafe manifests, network security issues, and other mobile risks.
04 · Attack surface
My main focus is web application and API security, alongside practical experience in network and mobile penetration testing.
Deep manual assessment of authorization, authentication, business logic, injection paths, and client-server trust.
Object- and function-level authorization, token handling, workflow abuse, schema behavior, and data exposure.
Infrastructure discovery, service enumeration, segmentation review, and configuration testing.
Android application assessment across storage, transport, platform configuration, and backend interaction.
05 · Security contributions
Selected organizations whose security I’ve contributed to by identifying and responsibly reporting vulnerabilities.



A selected view—not the full list.
06 · Contact
For penetration testing, collaboration, or responsible disclosure, email is the best way to reach me. You can also find my work and updates through the channels below.