Skip to content
View Den-Sec's full-sized avatar

Block or report Den-Sec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Den-Sec/README.md

Dennis Sepede

Defense is built by those who know how to attack.

I think like an attacker, I build like an engineer.

Portfolio  LinkedIn  Securitix Solutions


A researcher before a manager. Co-Founder & CTO of Securitix Solutions, CTO of Vulneralt, and the sole Cybersecurity Operations & Engineering lead for an industrial group. Trained in the US on critical infrastructure. I find the flaws, write the exploits, then build from scratch the defense that holds them.

Security research

3 Critical CVEs  ·  10 published advisories  ·  4 pending at MITRE  ·  40+ targets

Manual source-code review and coordinated disclosure, with a growing focus on AI/LLM security.

CVE Target Class Severity
CVE-2026-38595 im3x/Scriptables OS Command Injection Critical 9.8
CVE-2026-38600 gohttpserver Zip Slip → RCE Critical 9.1
CVE-2026-38601 gohttpserver Hardcoded session secret Critical 9.1

Plus "6 libraries, one leak" - the same cross-origin auth-header leak found across undici, node-fetch, follow-redirects, gorequest, req and go-resty. → Full archive: security-research

Built, not bought

Proprietary platforms I designed end-to-end and run in production. Code is closed source - case studies on my site.

  • Presidio - multi-tenant XDR/MDR SOC platform
  • Valta - AI-powered Cyber Threat Intelligence
  • Mirage - deception network with intelligent honeypots
  • Argus - AIOps dashboard for SMB / MSP
  • Forge - security awareness & training LMS
  • and more: Sign, Cipher, Tempest, PhishSim

Open source

Project What it is
security-research CVEs & responsible disclosures
PasswordFilterDLL Active Directory LSA password filter - offline HIBP via Bloom filter, GPO-ready
burp-mcp Burp Suite MCP server - 61 tools to drive Burp from an AI agent
Wordlist-Forger Customizable wordlist generator for pentesters
USBBlocker Block USB mass storage on Windows - endpoint hardening
glublm A 36M-param browser language model + pixel-art desk pet

Arsenal

  • Offensive  ·  Web / Mobile / AI pentest, Red Teaming, Malware Analysis, Vulnerability Research
  • Defensive  ·  XDR/EDR, SIEM, SOAR, Zero Trust, Hardening, M365 / AD
  • Governance  ·  ISO 27001, NIS2, GDPR, Risk Management, Threat Intelligence
  • Engineering  ·  Python, Go, TypeScript, Docker, Proxmox, AWS, Next.js

CompTIA Security+ · Cisco CCNA · AWS Cloud Practitioner · A.A.S. Cyber Security (High Honors) · NCL Top 6% · Anthropic Cyber Verification Program

Connect

dennis.d-enterprise.cc  ·  LinkedIn  ·  securitixsolutions.com  ·  dennis@securitixsolutions.com

Pinned Loading

  1. security-research security-research Public

    Security vulnerability research and responsible disclosures by Dennis Sepede - Securitix Solutions

  2. burp-mcp burp-mcp Public

    Burp Suite Professional MCP server - 61 tools to drive Burp from an AI agent (Claude Code) for authorized security testing.

    Java

  3. PasswordFilterDLL PasswordFilterDLL Public

    LSA password filter for Active Directory (C++): offline HIBP breach-list via Bloom filter, custom complexity rules, company blacklist, Event Log, GPO-friendly deployment.

    C++

  4. Wordlist-Forger Wordlist-Forger Public

    A powerful and customizable wordlist generator designed for cybersecurity professionals, penetration testers, and ethical hackers. This tool helps create tailored wordlists for use in password crac…

    Python 2 1

  5. ESP32-AI-Chatbot ESP32-AI-Chatbot Public

    Simple LLM Assistant Chatbot using Ollama API For ESP32

    C++ 16 4

  6. glublm glublm Public

    A 36M-parameter goldfish language model with a 10-second memory + pixel-art PWA desk pet. Runs in your browser, fully offline. Adopt it at den-sec.github.io/glublm/desk-pet/

    JavaScript 1