Skip to content
View mstfknn's full-sized avatar
💭
I may be slow to respond.
💭
I may be slow to respond.

Block or report mstfknn

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mstfknn/README.md
╔══════════════════════════════════════════════════════════════╗
║  PRINCIPAL THREAT RESEARCHER  ·  BRANDEFENSE                ║
║  Bridging offensive security with intelligence-led defense   ║
╚══════════════════════════════════════════════════════════════╝

Mustafa Kaan Demirhan

Principal Threat Researcher · Digital Risk Protection · Threat Intelligence

LinkedIn Brandefense CEH RPT


◈ About

I'm a Principal Threat Researcher at Brandefense, with 7+ years of hands-on experience across offensive security, threat intelligence, and strategic cyber defense. My work sits at the intersection of deep technical research and executive-level decision-making — translating complex threat landscapes into actionable intelligence.

Previously, I served as Technical Product Manager and Head of Cyber Intelligence Services at Brandefense, and before that as Penetration Testing Team Leader and Senior Security Consultant at PRISMA CSI, working directly with enterprise clients across red team operations and vulnerability assessments.

My mission: bridge the gap between raw security research and real-world defense at scale.


◈ Focus Areas

┌─────────────────────────────────────────────────────────────┐
│  Threat Intelligence & Digital Risk Protection              │
│  Red Team Operations & Penetration Testing                  │
│  Cyber Threat Research & Attribution                        │
│  Intelligence-Led Defense Strategy                          │
│  Secure Product Development                                 │
└─────────────────────────────────────────────────────────────┘

◈ Community

Active contributor to the Turkish cybersecurity ecosystem:

Community
🔐 Canyoupwn.me CTF & security challenges platform
🎮 Game of Pwners Offensive security community
🎤 Hacktrick Conference Annual cybersecurity conference
🌙 Hack Nights Security meetups & workshops
🛡️ Octosec Cybersecurity research community

Sharing tools, vulnerability research, and threat analysis to strengthen the broader security community.


◈ GitHub Stats

GitHub Activity Graph


◈ Career Timeline

2026 ──────────────────────────────────────────────────────────
          Principal Threat Researcher @ Brandefense
2024 ──────────────────────────────────────────────────────────
          Technical Product Manager @ Brandefense
2022 ──────────────────────────────────────────────────────────
          Head of Cyber Intelligence Services @ Brandefense
2021 ──────────────────────────────────────────────────────────
          Penetration Testing Team Leader @ PRISMA CSI
2020 ──────────────────────────────────────────────────────────
          Senior Security Consultant @ PRISMA CSI
2018 ──────────────────────────────────────────────────────────
          Security Consultant @ PRISMA CSI
2017 ──────────────────────────────────────────────────────────
          Cyber Security Specialist @ Lostar
2016 ──────────────────────────────────────────────────────────

◈ Recognitions

🏆 Hall of Fame (×2)


Pinned Loading

  1. malware-sample-library malware-sample-library Public archive

    Malware sample library.

    C++ 594 175

  2. ransomware-decryptors ransomware-decryptors Public archive

    Ransomware Decryptors

    35 11

  3. android-malware-sample-library android-malware-sample-library Public archive

    Android malware sample library.

    73 15

  4. rat-collection rat-collection Public archive

    Rat Collection

    Smali 120 44

  5. tor-proxy tor-proxy Public

    This project provides a Dockerized Tor proxy server that routes your internet traffic through the Tor network using a SOCKS5 proxy with DNS support.

    Shell

  6. phishing-fasttext-model phishing-fasttext-model Public

    A lightweight FastText-based model to classify domain names as phishing or clean.

    Python