pen test
✓
ozzy
özgün kültekin. but they call me that.
these days, mostly securityAIresearcher.
what i do
I do computer crimes, legally. After years of pure offensive security — red teaming, pentests, tricking SIEMs — now it leans hard into AI: tools that break apps, and tools that catch the ones poisoning yours.
p.s. — I also collect certificates, for sport. They prove far less than the things below, but they’re oddly fun to earn: OSCP · OSWE · eWPTX.
building
AOBTD — an LLM that pentests a web app like an operator, not a scanner. DEF CON 34 Demo Labs.
unrelabel — finds poisoned training data and turns it into a CI gate. Black Hat.
also made
enumerAIte — AI-powered web attack-surface enumeration.
log-slapper — slips fake logs past Splunk to confuse the blue team.
coming up
unrelabel — catching poisoned training data, live. Black Hat USA · Arsenal · Vegas, Aug 2026
AOBTD — the LLM pentester, first live run. DEF CON 34 · Demo Labs · Vegas, Aug 2026
if you’re in vegas, come heckle.
talks
writing
The Phisher’s Playbook — how to build a 10/10 phishing mail.
SysmonForLinux — logging file-create events on Linux.
Crypto from scratch — roll your own Base64, and Fixed XOR.
more on medium.
say hi
email · github · twitter · linkedin
wanna coffee / beer / poker? just email.previous life → hacker.ozgunkultekin.com — an old fake-desktop site. it still boots.