Penetration Testing (VAPT)
Manual, high-impact assessments of web apps, mobile apps, APIs, and infrastructure — against OWASP Top 10, API Top 10, and MASVS.
Adversarial Security Engineer // Offsec Researcher
I break things responsibly — end-to-end penetration testing across web, mobile, APIs, and enterprise infrastructure, red team operations, and vulnerability research that turns findings into published CVEs and real business impact.
Hi, I'm Danang Avan Maulana — also known as Dalpan or Van Lyubov. I'm an Adversarial Security Engineer and Offensive Security Researcher specializing in high-impact security assessments across web applications, mobile apps, APIs, and enterprise infrastructure.
My work goes beyond automated scanning: authentication and authorization bypass, business logic flaws, insecure cryptography, and server- and client-side weaknesses — validated with working proof-of-concept exploits. I've published multiple CVEs, contributed to the disclosure programs of dozens of companies and government institutions, authored the book Hack The Human, and presented Pretexta at DEF CON Demo Labs in Singapore.
Outside of engagements I run Tegalsec, a cybersecurity community I founded to teach, mentor, and grow the next generation of Indonesian security researchers.
Offensive security services grounded in manual testing, adversary emulation, and hands-on research.
Manual, high-impact assessments of web apps, mobile apps, APIs, and infrastructure — against OWASP Top 10, API Top 10, and MASVS.
Full-scope adversary emulation and social engineering that model how real attackers move through an organization.
Reverse engineering, Frida runtime instrumentation, and responsible disclosure — turning findings into published CVEs and tooling.
Workshops, bootcamps, seminars, and conference talks — from community meetups to the DEF CON Demo Labs stage.
Lead and execute pentests across web, mobile, API, and infrastructure. Manual testing of auth, business logic, and cryptography; red team & adversary simulation; custom offensive tooling; Android reverse engineering with Frida; technical reports and executive summaries.
Penetration testing of web applications and internal systems. Assessed authentication, authorization, privilege escalation, and business logic controls; explored blockchain and Web3 security.
Vulnerability assessments and penetration testing for clients from the government sector to overseas companies. Validated remediation through security retesting.
Founded and lead a cybersecurity community focused on offensive research, technical education, and knowledge sharing — workshops, published research, and mentoring aspiring penetration testers.
Technical support for network and computer systems; assisted in system maintenance and troubleshooting.
Informatics engineering with a focus on software and network security.
Graduated with strong grades and a range of technical certifications.
Human-layer exploitation, social engineering frameworks, attacker mindset modeling, and defensive counter-strategies.
Published vulnerabilities in widely used software, disclosed responsibly.
Open-source offensive tooling, research labs, and applications.

Social engineering simulation lab presented at DEF CON Demo Labs.

Burp Suite HTTP traffic exporter extension.

Passive frontend secret scanner.

Cross-Site Scripting (XSS) training labs.

Jeopardy-style CTF platform.

Hack The Br0wser — browser exploitation toolkit.

Simple backdoor / shell manager.
17+ offensive-security certifications across web, mobile, cloud, and red team.
Public Hall of Fame acknowledgements, bug bounty & responsible disclosures, speaking, and community work.
Security Center — Security Thanks / Hall of Fame acknowledgement.
Indonesian Military Cyber Security Incident Response Team Hall of Fame.
Security Responsible Disclosure acknowledgement.
Beyond the public acknowledgements above, 100+ additional vulnerabilities have been disclosed responsibly through private bug-bounty programs — kept confidential under NDA.
Selected national coverage and video features.
Dari korban phishing akun game hingga peneliti keamanan.
Liputan riset Pretexta di panggung keamanan siber internasional.
Satu-satunya peserta Indonesia yang lolos seleksi sesi Demo Labs.
Profil praktisi keamanan siber asal Tegal.


Write-ups and research on blog.tegalsec.org.
Interested in a penetration test, red team engagement, training, or a talk? Reach out.
I'm open to security engagements, research collaborations, and speaking sessions. Drop a message or reach me directly.