Security Research
Onurcan Genç
Offensive security researcher and AI red-teamer with experience in penetration testing across web, mobile, and API surfaces. I focus on vulnerability research in production frameworks and AI security evaluation, including LLM guardrail testing and adversarial attack methodology. Currently building an LLM Guardrails Evaluation Toolkit at HUX AI Research.
onurcan@kali:~$ cat profile.json { "name": "Onurcan Genç", "role": "Offensive Sec / AI Red Teamer", "certs": [ "eWPTXv3", "eWPT", "Sec+"], "cves": 8, // MITRE + USOM "focus": [ "LLM jailbreak", "prompt injection"], "open": true // international roles } onurcan@kali:~$
Published Vulnerabilities
Selected GitHub Work
PromptShot v1.0
Multi-phase adversarial attack pipeline for red-teaming LLMs · multi-agent jailbreak generation, system-prompt poisoning, persona hijacking.
NucAIScan
AI-assisted DAST pipeline · Subfinder, Subzy, FFUF heuristics, Nuclei with GPT-4 template selection and automated HTML reporting.
LeakCTL
Threat-intelligence platform for credential-leak monitoring. Telegram-integrated with Elasticsearch backend for automated ingestion and search.
ArchiveWraith
Stealth Wayback Machine recon with smart URL filtering. Extracts high-value endpoints from historical snapshots.
web_app_ai_scanner
Full AI-assisted web scanner: Subfinder, Httpx, FFUF, Katana, WhatWeb, Wappalyzer, Wayback, Subzy, Nuclei. Full report generation.
ai-text-humanizer
AI-generated text optimizer using BERT MLM + Q-Learning + 4-detector ensemble. Reduces AI detection scores while preserving semantic quality.
Work History
Ankara · Remote
Technical review and QA of penetration-test reports. Validated vulnerability findings, impact analysis, and remediation guidance. Alignment with MITRE ATT&CK and CVSS.
Ankara · Hybrid
Web, mobile, wireless, and LAN penetration tests against real-world targets. AI/ML red team engagements. Cyber threat intelligence including dark-web credential leak validation. Mentored junior interns.
Istanbul · Remote
Tested and validated CTF machine vulnerabilities. Published writeups ensuring correct exploit trigger paths per machine design.