紫の死神

Enes Demir/ rootmancer

Cybersecurity Intern Candidate | Web Application & API Security | HTB CWES

Final-year Software Engineering student with hands-on web application pentesting experience. I assess authorized applications and APIs, document reproducible findings, and translate technical risk into actionable reports.

Iwhoami

About me

I'm Enes Demir, a final-year Software Engineering student in İstanbul focused on offensive security and application testing. My software background helps me look past visible behavior to the code, trust boundaries, and validation decisions behind it — and turn unexpected responses into reproducible findings.

That perspective shapes how I test: carefully, reproducibly, and with reporting in mind. I hold seven publicly verifiable certifications across web, network, and AI/ML security. I'm looking for a cybersecurity internship or junior pentesting role where careful testing and clear reporting matter equally.

rootmancer@portfolio:~$ whoami
Enes Demir / rootmancer profile artwork

Enes Demir

/ rootmancer

Cybersecurity Intern Candidate

Location
İstanbul · remote-ready
Languages
TR native · EN professional
Open to internship & junior rolesEmail ↗
IIfield record

Experience

Hands-on penetration testing — from authorized manual assessment to reproducible evidence and clear reporting.

İHS Teknoloji

Penetration Tester Intern

December 2025 — April 2026

Authorized assessment

Pentesting,end to end.

As a Penetration Tester Intern at İHS Teknoloji, I manually assessed authorized web apps and APIs with Burp Suite against OWASP Top 10. I documented reproducible PoCs and request evidence, scored findings with CVSS v3.1, and delivered actionable reports.

  • Assess

    Burp · OWASP

  • Prove

    PoC · Evidence

  • Report

    CVSS · Reports

IIIcredentials

Certifications

7 earned certifications across web, network and AI/ML security — every one publicly verifiable.

IVlearning log

Writeups & Walkthroughs

Beginner-to-intermediate CTF walkthroughs — I document every room I solve, from enumeration through exploitation and privilege escalation.

WebTryHackMeEasy

TryHackMe — Simple CTF

Enumeration → web exploitation via SQL injection, hash cracking, SSH access, then privilege escalation to root.

SQLiHash crackingSSHPrivesc
NetworkTryHackMeEasy

TryHackMe — Basic Pentesting

A full beginner pentest walkthrough: service enumeration, brute-forcing credentials, and privilege escalation, with notes.

EnumerationBrute-forcePrivesc
WebTryHackMeEasy

TryHackMe — RootMe

Bypassing a file-upload filter to plant a PHP web shell, then escalating privileges to root.

File uploadWeb shellPHPPrivesc
WebTryHackMeEasy

TryHackMe — Pickle Rick

A Rick-and-Morty themed web challenge: source-code recon, command execution, and hunting the three secret ingredients.

WebCommand executionRecon
ToolingCTFMedium

Hammer CTF — Brute-force Tooling

A custom Python brute-force script written to solve the Hammer challenge — automating the boring part of the attack.

PythonBrute-forceAutomation
Vvideo walkthroughs

Walkthrough Videos

Step-by-step exploitation, recorded end to end — TryHackMe rooms and PortSwigger labs on YouTube.

preview soonTryHackMe5:38

SQL Injection & Command Injection to Root — Operation Promotion

SQLiCommand InjectionPrivesc
preview soonTryHackMe1:31

JWT Privilege Escalation to Admin — TryHeartMe

JWTPrivesc
preview soonPortSwigger2:09

SQL Injection Login Bypass — Web Security Academy

SQLiAuth bypass
preview soonTryHackMe6:28

Operation Coldstart — SSRF + tar Wildcard Injection to Root

SSRFWildcard InjectionPrivesc
preview soonPortSwigger1:37

SQLi in WHERE Clause — Retrieving Hidden Data

SQLi
preview soonTryHackMe6:31

Silent Monitor — SQL Injection to Root via Command Injection

SQLiCommand InjectionPrivesc
preview soonTryHackMe6:49

JWT kid Injection to Admin — Hammer

JWTkid injectionPrivesc
preview soonTryHackMe7:34

Cracking SSH with a Custom Wordlist (CeWL + Hydra) — Checkmate

SSHHydraCeWL
VIopen a channel

Let's talk

Open to cybersecurity internships and junior penetration tester roles — Türkiye or remote. My inbox is open.

Open to work · available now

rootmancer0@gmail.com