·
available for offensive security roles
I break things to understand how they hold together.
Selim Celebi, offensive security engineer and CTF competitor. Web and network pentesting, malware analysis, reverse engineering and digital forensics. Cum Laude graduate, Howest Applied Computer Science (Cyber Security Professional).

top 7%
TryHackMe Hackfinity Battle 2025, #295 / 4356
top 8%
HackTheBox Cyber Apocalypse 2025, #614 / 8129
113
players in the aviation CTF I co-engineered at EUROCONTROL
4
editions of Cyber Security Challenge Belgium, 2023-2026
// about me
Run the interview yourself
Everything you would normally read in an About page, piped through a shell. Skip ahead or replay the session at any time.
selim@portfolio:~$ whoami
Selim Celebi — Cybersecurity professional
Brussels, Belgium · available for offensive security roles
selim@portfolio:~$ cat profile.txt
I break things to understand how they hold together.
Graduated Cum Laude from Howest in Applied Computer Science –
Cyber Security Professional. I work across the full offensive stack:
web and network pentesting, malware analysis, reverse engineering
and digital forensics.
selim@portfolio:~$ ls -la experience/
EUROCONTROL — EATM-CERT trainee (Feb–May 2025, Brussels)
› Co-engineered an aviation CTF for 113 players across the
European aviation sector
› Penetration testing of aviation systems and applications
› R&D supporting aviation cybersecurity
selim@portfolio:~$ cat projects.md
Security audit full audit for a company and a pharmacy —
OSINT, pentest, phishing simulation, awareness survey
Honeypot lab honeypot servers + Kibana dashboards, red vs blue
Mobile security deliberately vulnerable Android app for pentest training
Pentest report full network and system audit with mitigation strategy
selim@portfolio:~$ ctf --stats
Hackfinity Battle 2025 TryHackMe top 7% #295 / 4356
Cyber Apocalypse 2025 HackTheBox top 8% #614 / 8129
Cyber Security Challenge Belgium 4 editions 2023–2026
Hack the Future Antwerp 2024
selim@portfolio:~$ cat skills.json
{
"offensive": ["web pentesting", "network & system pentesting"],
"analysis": ["malware analysis", "reverse engineering", "forensics"],
"code": ["Java", "C", "C++", "C#", "Kotlin", "SQL", "Bash"],
"systems": ["Linux", "Windows Server", "Git", "CCNA"],
"languages": ["FR native", "TR native", "EN C1", "NL B1"]
}
selim@portfolio:~$ contact --show
email via the contact form — no plaintext address published
linkedin /in/celebiselim
blog write-ups & event notes
Thanks for reading. Say hi.
plays as you scroll to it. With reduced motion enabled the full transcript is shown up front and the session is yours to start
// capabilities
The full offensive stack
01
Penetration testing
Web, network and system assessments: full audits for a company and a pharmacy covering OSINT, exploitation, phishing simulation and an awareness survey, delivered with mitigation strategy.
02
Malware & reverse engineering
Static and dynamic analysis, binary reversing and digital forensics. Built a deliberately vulnerable Android application used as a pentest training target.
03
Detection & deception
Honeypot servers instrumented with Kibana dashboards, run as red-versus-blue exercises. R&D supporting aviation cybersecurity at EUROCONTROL’s EATM-CERT.
// featured write-up
Latest research
security research · self-audit
What I found auditing my own website
I pointed my own toolchain at this domain and treated it like a client engagement. Three findings survived to remediation: a REST endpoint enumerating my username, a plaintext address harvestable straight from the DOM, and a listener answering on port 80. Here is the write-up, and the fix for each.
FIXED · user enumeration via /wp-json/wp/v2/users
FIXED · plaintext address exposed to scrapers
FIXED · unencrypted HTTP reachable on port 80
// recent entries
Write-ups & field notes
-
What I found auditing my own website
I pointed my own toolchain at this domain and treated it like a client engagement. Three findings survived to remediation:…
-
TryHackMe: Hackfinity Battle
Student edition of TryHackMe’s Hackfinity Battle, a capture-the-flag sprint that put me in the top 7% of 4356 competitors.
-

Cyber Apocalypse CTF 2025: Tales from Eldoria
HackTheBox’s flagship annual CTF. Tales from Eldoria ran across web, forensics and reversing categories, finishing top 8% of 8129 teams.
-

EU MITRE ATT&CK® Community Workshop 2025
Notes from the EU MITRE ATT&CK Community Workshop at EUROCONTROL: threat intelligence in action across the aviation sector.
-

Artifhacking Intelligence: When Hackers Meet AI
A live hacking show at Howest Bruges on where offensive security meets machine learning, and where the hype breaks down.
-

PR Event: Cyber Deception & Industry Insights
Professional networking evening on cyber deception and industry insights, organised with our own tech and security team at Howest.
// contact –init
Hiring, or want a second pair of eyes?
I am available for offensive security roles and engagements in Brussels and remotely. Messages route through a spam-protected form, and no address is published in this page’s source.