Skip to content
View franc205's full-sized avatar

Highlights

  • Pro

Block or report franc205

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
franc205/README.md

Hi 👋, I'm Fran Canteli

Senior Security Engineer · Application Security & Offensive Security · Buenos Aires, Argentina 🇦🇷

I work at the intersection of offensive security and application security, helping teams identify exploitable vulnerabilities, understand real-world impact, prioritize remediation, and reduce risk across web, mobile, cloud, and infrastructure environments.

🧑‍💻 About me

📍 Buenos Aires, Argentina
🛠️ Senior Security Engineer with a strong Offensive Security background
🎯 Focused on Application Security, vulnerability management, cloud security, and practical remediation
🔍 7+ years of hands-on experience across web, mobile, internal, external, and cloud security assessments
🧠 I like turning offensive findings into clear risk, actionable recommendations, and security improvements that technical teams can actually use

🚀 What I do

📱 Application Security: Web and mobile application testing, vulnerability analysis, remediation guidance, and secure coding discussions.
☁️ Cloud & Infrastructure Security: Cloud, internal, external, and infrastructure security assessments.
🧠 Vulnerability Management: Exploitability validation, impact analysis, prioritization, false-positive reduction, and remediation follow-up.
🧰 Offensive Security: Penetration testing, attack path discovery, privilege escalation, post-exploitation, and realistic risk demonstration.
⚙️ Security Automation: Scripts and workflows to reduce repetitive work, improve consistency, and support security assessment processes.

🧭 Current focus

I’m currently focused on applying my offensive security background to Application Security Engineering: vulnerability triage, secure SDLC practices, AppSec testing, cloud security, automation, and collaboration with development teams.

I approach SAST, DAST, SCA, and CI/CD security workflows as part of a broader AppSec process: validating findings, reducing noise, prioritizing exploitable issues, and helping teams move from detection to remediation.

📫 Connect with me

LinkedIn X Email

🏆 Certifications

CRTL

CRTO

BSCP

OSCP

CEH

eJPT

💻 Security Skills & Tooling

Application Security

AppSec & DevSecOps Tooling

Offensive Security

Cloud, Infrastructure & Automation

Also worked with

PowerShell · JavaScript · Node.js · n8n · Wireshark · Frida · jadx · MobSF · Checkov · Prowler · Terraform · Kubernetes

🎤 Talks & Workshops

2025

  • CodeBlue: From Network to Network: Hands-On Pivoting Techniques in Internal Environments | 🎥 Video | 📊 Slides
  • Ekoparty: Red Team Space: Breaking the Cover: Advanced TOR Deanonymization Techniques and Real-World Attacks | 🎥 Video | 📊 Slides

2024

  • Ekoparty: Red Team Space: From Network to Network: Hands-On Pivoting Techniques in Internal Environments | 📊 Slides
  • DEFCON: Red Team Village: From Network to Network: Hands-On Pivoting Techniques in Internal Environments | 📊 Slides

2023

  • Ekoparty: Red Team Space: From Network to Network: Hands-On Pivoting Techniques in Internal Environments | 📊 Slides

2021

2020

Pinned Loading

  1. dvpe dvpe Public

    An immersive, multi-container environment designed to practice network pivoting and lateral movement techniques.

    Shell 47 7

  2. Echo433 Echo433 Public

    A powerful, Arduino-based 433MHz signal sniffer and cloner.

    C++ 40 1

  3. ArduinoDucky ArduinoDucky Public

    Make your own Rubber Ducky With an Arduino UNO!

    Arduino 17 5

  4. AD-workshop AD-workshop Public

    Recursos del Workshop de Active Directory

    8 2