Skip to content
View dvdknaap's full-sized avatar
💭
👨‍💻
💭
👨‍💻

Organizations

@PureGeneticLifestyle

Block or report dvdknaap

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 250 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Dvdknaap/README.md

Danny van der Knaap — Senior Software Engineer & Pentester

Experience Role Focus Location Cert Cert

I execute end-to-end penetration testing across Web, API, and AD/Enterprise surfaces, with targeted coverage of cloud attack paths and DevSecOps pipelines. Delivery is mapped to OWASP (ASVS/WSTG/MSTG), PTES, NIST 800-115, and MITRE ATT&CK for defensible findings, measurable risk reduction, and rapid developer remediation. Toolchain spans Burp Suite Pro, Nmap/Masscan, ffuf/feroxbuster, sqlmap, nuclei, gobuster, jwt-tool, and AD tradecraft (BloodHound/SharpHound, Impacket, CrackMapExec, Rubeus, Kerberoasting/AS-REP, ADCS abuse).


Impact Highlights

  • Password/Hash Opsgitea-crack-passwords: PBKDF2-SHA256 dictionary cracking at scale.
  • Recon/Deobfuscationdownload_js_map_files: automated .js.map discovery & extraction.
  • Payload Engineeringsqlmap-temper-scripts: evasive SQLi tamper pipelines (WAF-aware).
  • Binary/Algo ExplorationXOR-key-bruteforce: brute-force XOR key/message search.
  • CTF Workflowadd-creds-rofi: high-velocity credential ops for engagements.
  • AppSec R&Djava-STTI (Spring SSTI file exfil) and eos (Enemies Of Symfony tooling).
  • Legacy OpsDirectadminAudit: pragmatic operational automation.

Explore the repos for full delivery details.


Core Tech Footprint

Python · JavaScript/Node.js · PHP/Symfony · Shell/Bash · C++ · SCSS/CSS · Solidity · Perl


Pentest Coverage Map

  • Web & API Pentesting: AuthN/AuthZ bypass, IDOR, SSRF, deserialization, template injection, GraphQL abuse, JWT/crypto flaws, rate-limit evasion.
  • AD/Enterprise: Enumeration → lateral movement → privilege escalation; Kerberos attacks, constrained/unconstrained delegation, ADCS, ACL abuse.
  • Cloud & CI/CD: IAM misconfig, metadata pivots, secret sprawl, artifact poisoning, supply-chain hardening.
  • Detection & Reporting: ATT&CK mapping, reproducible PoCs, prioritized remediation with developer-ready guidance.

Certifications & Community

  • Hack The Box: CPTS (Certified Penetration Testing Specialist) · CBBH (Certified Bug Bounty Hunter)
  • Profiles

    TryHackMe Profile Badge

    Hack The Box Profile Badge


Operating Dashboards (auto-updating)

Top Languages

GitHub Streak

Contribution Graph


Pinned Deliverables


Popular repositories Loading

  1. NodeJS-download NodeJS-download Public

    A small NodeJS module to download remote files to local, works with triggers

    JavaScript 4 1

  2. Twig-extensions Twig-extensions Public

    Forked from twigphp/Twig-extensions

    Twig extensions

    PHP 2

  3. startVirtualBox startVirtualBox Public

    Start a virtualbox on the background and start an ssh connection to that box

    Shell 1

  4. NodeJS-realtime-Chat NodeJS-realtime-Chat Public

    My First NodeJS app an realtime ChatBox, username required to enter

    JavaScript 1 1

  5. NodeJS-cluster NodeJS-cluster Public

    Cluster with proxy so you can set multiple domain names on port 80

    JavaScript 1

  6. DirectadminAudit DirectadminAudit Public

    Old script that i have created for loggin directadmin and saving passwords

    PHP 1 1