Azizcan Dastan
Cyber Threat Intelligence Engineer @ SOCRadar® Extended Threat Intelligence
About
As I step into my fifth year in cybersecurity, my focus has consistently been on crafting sophisticated, real-world attack scenarios. I’ve specialized deeply in Red Teaming and Web3 Security, with a strong emphasis on staying covert in complex infrastructures and pushing systems beyond their intended limits. In Red Team operations, I concentrate on advanced post-exploitation techniques, such as Active Directory misconfigurations, ADCS abuse, cross-forest pivoting, Kerberos golden/silver ticket forgery, and Resource-Based Constrained Delegation (RBCD) attacks. I leverage frameworks like Cobalt Strike, Mythic, and Sliver, while developing custom C2 implants and post-exploitation tooling in Python, Go, and C when needed. My work frequently involves EDR evasion, sandbox bypass, custom shellcode injection, and building covert C2 channels (DNS over HTTPS, Slack API, GitHub Gist-based C2) to execute stealthy and complex Red Team campaigns. On the Web3 side, I focus on smart contract vulnerabilities (reentrancy, delegatecall injection, uninitialized proxy takeover), DeFi flash loan exploits, oracle manipulation, cross-chain bridge vulnerabilities, MEV exploitation, and EVM bytecode reverse engineering. I utilize tools like Slither, Mythril, Echidna, and Foundry (forge) to perform both offensive and defensive smart contract analysis. Additionally, I research areas such as validator node security, cross-chain bridge abuse, and private key leakage hunting in blockchain ecosystems. In Cloud Security (AWS, Azure, GCP), I’ve worked on IAM privilege escalation, metadata abuse, Lambda exploitation, misconfigured storage discovery, and Azure Managed Identity abuse, always approaching them with a Red Team mindset. With my Network Security background, I’m experienced in L2/L3 pivoting, VPN split tunneling abuse, DNS tunneling, and 802.1x/NAC bypass techniques. I develop and extend my tooling primarily in Python, Go, C, PHP, JavaScript, Bash, and Ruby, applying them effectively in Red Team, Web3, and Cloud offensive security projects. For me, cybersecurity has always been about pushing beyond known boundaries — continuously exploring more sophisticated, more covert, and more effective attack paths.
Türkiye
Ankara
Computer & Network Security
Sosyal Mühendislik, Siber istihbarat, Red Teaming, Takedown, Linux Çekirdek, eBPF, Offensive Security, Web3 Security, Analitik Beceriler, İşe Alma, İş Analizi, Piyasa Araştırması, Güvenlik Politikası, Bulut Uygulamaları, Uygulama Güvenliği, Amazon Web Hizmetleri (AWS), Kimlik Tanımlama ve Erişim Yönetimi (IAM), Cloud Security, Cloud Architecture, Network Security
Experience

Red Team Lead
Skydrift
Valensiya, Valensiya, İspanya
Cloud, Web, Mobil, IoT Security, Pentesting Blue/RedTeam Secure Code Developing JS Python C

Sr Security Engineer
Up-Consulting
Köln, Kuzey Ren-Vestfalya, Almanya
Cloud Security, Cloud Arch, Cloud Pentesting, Network, Web Pentesting, Arch Secure Code Developing JS Python C

Security Engineer
Big-A Yazılım
Türkiye
High competence in the field of Web Applications, Mobile applications, and cloud. Architectural designing. Secure Full Stack Developing
Azizcan Dastan's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.






