Available for engagements & talks

Danang Avan M

Adversarial Security Engineer // Offsec Researcher

I break things responsibly — end-to-end penetration testing across web, mobile, APIs, and enterprise infrastructure, red team operations, and vulnerability research that turns findings into published CVEs and real business impact.

~/whoami — zsh
whoami
danang_avan_maulana (aka dalpan / van_lyubov)
cat role.txt
Adversarial Security Engineer @ Punggawa Cyber
location --now
Tegal, Central Java, Indonesia
ls ./focus
web/  mobile/  api/  red-team/  reversing/
git log --oneline --stat
4+ CVEs · 100+ responsible disclosures · secure code review
01 // whoami

About me

4+
Published CVEs
100+
Responsible disclosures
17+
Security certifications
7+
Years in offensive security
Danang Avan Maulana
dalpan@tegalsec

Hi, I'm Danang Avan Maulana — also known as Dalpan or Van Lyubov. I'm an Adversarial Security Engineer and Offensive Security Researcher specializing in high-impact security assessments across web applications, mobile apps, APIs, and enterprise infrastructure.

My work goes beyond automated scanning: authentication and authorization bypass, business logic flaws, insecure cryptography, and server- and client-side weaknesses — validated with working proof-of-concept exploits. I've published multiple CVEs, contributed to the disclosure programs of dozens of companies and government institutions, authored the book Hack The Human, and presented Pretexta at DEF CON Demo Labs in Singapore.

Outside of engagements I run Tegalsec, a cybersecurity community I founded to teach, mentor, and grow the next generation of Indonesian security researchers.

  • nameDanang Avan Maulana
  • roleAdversarial Security Engineer
  • basedTegal, Indonesia
  • emailvan@tegalsec.org
  • focusVAPT · Red Team · Research
  • communityFounder, Tegalsec
02 // capabilities

What I do

Offensive security services grounded in manual testing, adversary emulation, and hands-on research.

Penetration Testing (VAPT)

Manual, high-impact assessments of web apps, mobile apps, APIs, and infrastructure — against OWASP Top 10, API Top 10, and MASVS.

Red Team & Adversary Simulation

Full-scope adversary emulation and social engineering that model how real attackers move through an organization.

Vulnerability & CVE Research

Reverse engineering, Frida runtime instrumentation, and responsible disclosure — turning findings into published CVEs and tooling.

Training & Public Speaking

Workshops, bootcamps, seminars, and conference talks — from community meetups to the DEF CON Demo Labs stage.

Web & API Penetration Testing95%
CVE Research & Responsible Disclosure90%
Mobile Application Security85%
Red Team & Adversary Simulation85%
Reverse Engineering & Frida80%
Secure Code Review80%

Tools & Tech

Burp Suite Nmap ffuf sqlmap Nuclei Metasploit Frida Objection Drozer MobSF OWASP MASVS Android RE Wireshark Python Bash Go Custom scripts Private tools & more
03 // career.log

Experience & Education

Experience
  1. Nov 2022 — Present

    Adversarial Security Engineer

    Punggawa Cyber (formerly Juke Solutions)

    Lead and execute pentests across web, mobile, API, and infrastructure. Manual testing of auth, business logic, and cryptography; red team & adversary simulation; custom offensive tooling; Android reverse engineering with Frida; technical reports and executive summaries.

  2. Feb 2022 — Jul 2022

    Penetration Tester

    Tokocrypto

    Penetration testing of web applications and internal systems. Assessed authentication, authorization, privilege escalation, and business logic controls; explored blockchain and Web3 security.

  3. Jul 2021 — Jan 2022

    Penetration Tester

    Xai Syndicate Company

    Vulnerability assessments and penetration testing for clients from the government sector to overseas companies. Validated remediation through security retesting.

  4. Jul 2018 — Present

    Founder & Security Research Contributor

    Tegalsec Community

    Founded and lead a cybersecurity community focused on offensive research, technical education, and knowledge sharing — workshops, published research, and mentoring aspiring penetration testers.

  5. Apr 2017 — Oct 2017

    IT Support Technician (Intern)

    Politeknik Negeri Ujung Pandang

    Technical support for network and computer systems; assisted in system maintenance and troubleshooting.

Education
  1. 2018 — 2022

    Bachelor of Informatics (S.Kom)

    Universitas Teknologi Yogyakarta

    Informatics engineering with a focus on software and network security.

  2. 2016 — 2018

    Computer & Network Engineering (TKJ)

    SMK Yapmi Makassar

    Graduated with strong grades and a range of technical certifications.

Author
Hack The Human
Book · 2026

Hack The Human

Human-layer exploitation, social engineering frameworks, attacker mindset modeling, and defensive counter-strategies.

04 // disclosures

CVE Research & Publications

Published vulnerabilities in widely used software, disclosed responsibly.

CVE-2024-35659
Authorization Bypass in KiviCare (≤ 3.6.2)
Auth Bypass
CVE-2024-33940
Stored XSS in EventON (≤ 2.2.14)
Stored XSS
CVE-2024-30513
Authorization Bypass in ProfileGrid (≤ 5.7.2)
Auth Bypass
CVE-2024-27995
Stored XSS in ARMember Plugin (≤ 4.0.23)
Stored XSS
06 // credentials

Certifications

17+ offensive-security certifications across web, mobile, cloud, and red team.

Certified Associate Penetration Tester (CAPT)
Hackviser
Certified Red Team Analyst (CRTA)
CyberWarFare Labs
Certified Cyber Security Engineer (CCSE)
CyberWarFare Labs
Web & API Red Team Analyst (WEB-RTA / API-RTA)
CyberWarFare Labs
Certified Cyber Security Analyst (C3SA)
CyberWarFare Labs
Multi-Cloud Red Team Analyst (MCRTA)
CyberWarFare Labs
Process Injection & Purple Teaming (CPIA / CPTF)
CyberWarFare Labs
Red Team — CredOps Infiltrator (CRT-COI)
CyberWarFare Labs
AppSec Practitioner & Pentester (CAP / CAPen)
The SecOps Group
Certified Mobile Pentester (CMPen — Android)
The SecOps Group
Network Security Practitioner (CNSP)
The SecOps Group
Social Engineering Defense Practitioner (CSEDP)
The SecOps Group
Red Team Operations Management (CRTOM)
Red Team Leaders
Cybersecurity Educator Professional (CCEP)
Red Team Leaders
07 // trophies

Recognition

Public Hall of Fame acknowledgements, bug bounty & responsible disclosures, speaking, and community work.

Published Hall of Fame

Beyond the public acknowledgements above, 100+ additional vulnerabilities have been disclosed responsibly through private bug-bounty programs — kept confidential under NDA.

Speaking & Community

Speaker · 2026
DEF CON Demo Labs (Singapore) — presenting Pretexta
Speaker
National Seminar — UNIBI, Cyber Security Awareness
Speaker
National Seminar — Politeknik Baja Tegal, Cyber Security
Trainer
Cybersecurity Bootcamp — Punggawa
Trainer
Information Security Workshop — Kominfo Tegal Regency
Trainer
Cybersecurity Workshop — Universitas Harkat Negeri
Founder
Tegalsec Community — active contributor & speaker
09 // ~/writeups

From the Blog

Write-ups and research on blog.tegalsec.org.

fetching latest write-ups…
10 // ./contact

Let's work together

Interested in a penetration test, red team engagement, training, or a talk? Reach out.

I'm open to security engagements, research collaborations, and speaking sessions. Drop a message or reach me directly.