Skip to content
View meliht's full-sized avatar

Organizations

@distribRuted

Block or report meliht

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
meliht/README.md

👋 Hi, I'm Melih Tas

Founder @ VulnHero & Siber Ninja
Creator of Mr.SIP Pro
PhD in Computer Engineering | AI-Driven OffSec, VoIP & AppSec Expert | Speaker @ DEFCON & BlackHat


🚀 About Me

Cybersecurity researcher, entrepreneur, and offensive security expert with 15+ years of experience delivering advanced penetration testing, vulnerability intelligence, and application security solutions.
I specialize in AI-driven offensive security, VoIP/SIP attack simulation, and advanced penetration testing and red team operations.
I have developed security tools adopted by global enterprises, academia, and the open-source community; contributed to the CVE Program; and delivered talks at DEFCON, BlackHat, Offzone, and other leading security conferences worldwide.


🛡️ Core Expertise

  • Offensive Security & Penetration Testing
  • VoIP/SIP Security & Attack Simulation
  • Application Security & Secure SDLC
  • Vulnerability & Exploit Intelligence
  • Red Teaming & Adversary Simulation
  • AI/ML-Driven Security Automation

📢 Free Resource – Always Free from VulnHero

Always Free: Monthly CVE & Exploit Insights
Stay informed with monthly updates on vulnerabilities, exploits, and security trends — no registration required.

📩 Subscribe Here — Get free monthly insights on vulnerability & exploit intelligence, trends, and tips.


🏆 Featured Projects

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.
Python Stars

SIP-Based DDoS Defense Tool.
Python

Automation scripts and frameworks for penetration testing workflows.


📚 Publications & Research (SCI-Indexed)

  • (Submitted) A Deep Dive into the Anatomy of Real-World Caller-ID Spoofing Attacks in Live Financial Call Centers – SCI-Indexed Academic Paper, 2024.
  • Blockchain-Based Caller-ID Authentication (BBCA)IEEE Access, 2024. DOI
  • Efficient Mitigation Against SIP-Based DRDoS AttackMDPI Applied Sciences, 2023. DOI
  • A Novel SIP-Based DRDoS Attack & Defense MechanismIEEE Access, 2020. DOI
  • Novel SIP-Based DDoS Attacks & DefensesElsevier Computers & Security, 2016. DOI

🎤 Selected Talks & Conferences

🎤 Talks & Conferences (Full List)

  • BlackHat MEA 2024 BriefingOptimizing Port Scanning at Scale with The distribRuted Framework – Riyadh.
  • BlackHat MEA 2024 ArsenalDistribRuted – Distributed Attack Framework (Botnet-as-a-Service) – Riyadh. GitHub
  • BlackHat Europe 2024 ArsenalDistribRuted – Distributed Attack Framework (Botnet-as-a-Service) – London. GitHub
  • DEFCON 32 DemoLabs (2024)DistribRuted – Distributed Attack Framework (Botnet-as-a-Service) – Las Vegas. GitHub
  • Securi-Tay 2023 Opening KeynoteMy Journey with Mr.SIP Pro – Dundee. Video | Website
  • BlackHat USA 2023 ArsenalAppSecLens: AI-Driven Adaptive Application Risk Ranking
  • BlackHat MEA 2022 BriefingBreaking VoIP Networks and Applications using Mr.SIP Pro – Riyadh.
  • DEFCON 28 Main Stage (2020)Practical SIP Penetration Testing Using Mr.SIPVideo
  • OffZone 2019Mr.SIP – SIP-Based Offensive Security Framework – Moscow.
  • BlackHat Asia 2023 ArsenalMr.SIP – SIP-Based Offensive Security Framework – Singapore.
  • BlackHat EU 2022 ArsenalMr.SIP – SIP-Based Offensive Security Framework – London.
  • BlackHat MEA 2022 ArsenalMr.SIP – SIP-Based Offensive Security Framework – Riyadh.
  • BlackHat EU 2020 ArsenalMr.SIP – SIP-Based Offensive Security Framework – London.
  • BlackHat EU 2019 ArsenalMr.SIP – SIP-Based Offensive Security Framework – London.
  • BlackHat USA 2019 ArsenalMr.SIP – SIP-Based Offensive Security Framework – Las Vegas.
  • BlackHat Asia 2019 ArsenalMr.SIP – SIP-Based Offensive Security Framework – Singapore.

🏅 CVE Contributions

  • CVE-2020-3122 – Cisco Content Security Management Appliance – Information Disclosure
  • CVE-2020-4708 – IBM Security Trusteer Pinpoint Detect – Information Disclosure
  • CVE-2020-16283 – Software AG System Management Hub – XSS
  • CVE-2020-16284 – Software AG System Management Hub – XSS
  • CVE-2020-16285 – JAMF Pro – Information Disclosure
  • CVE-2020-16286 – QuickFIX Engine FIXT 1.1 – XSS

📊 GitHub Stats

Melih's GitHub stats Top Langs


🌐 Connect with Me

Pinned Loading

  1. Mr.SIP Mr.SIP Public

    SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

    Python 416 92

  2. TaktikselBugHunting TaktikselBugHunting Public

    Taktiksel Bug Hunting Yöntemleri

    45 9

  3. SIP-DD SIP-DD Public

    SIP-Based DDoS Defense Tool

    Python 16 3

  4. PentestAutomation PentestAutomation Public

    Python 5 4

  5. AppSecLens AppSecLens Public

    AI-Driven Adaptive Application Risk Ranking