Author Image

Hi, I am Phantomn

Phantomn

Security Engineer at CoreSecurity

I am a passionate Vulnerability Researcher and Developer with experience in cybersecurity automation and AI system design. I built OSS tools and fuzzers for embedded systems (e.g., PLCs, HMIs) aligned with IEC 62443-4-2. I also design automation workflows with n8n, build custom RAG pipelines. Sometimes, I work on fun projects like reverse engineering obfuscated scripts or creating structured knowledge systems.

Leadership
Team Work
Hard Working

Skills

Experiences

1
CoreSecurity

Jun 2021 - Present

South Korea

As a specialist in OT/ICS and IoT security, we develop vulnerability analysis and response technologies for various smart infrastructure environments.

Vulnerability Researcher

Jun 2021 - Present

Responsibilities:
  • Performing N-day exploitation of embedded devices in an IoT smart building environment
  • Developing vulnerability detection technology for smart building IoT devices
  • Developing exploit and information gathering tools targeting routers, NAS, and CCTV
  • Developing incident scenarios in OT/ICS environments and conducting on-site penetration tests
  • Analysis of IEC 62443, an industrial control system security standard
  • Conducted numerous on-site penetration tests for various companies

A3Security

Jun 2020 - Jun 2021

South Korea

An information security specialist company that performed penetration testing.

Web/Mobile Penetration Tester

Jun 2020 - Jun 2021

Responsibilities:
  • Performed web/mobile penetration testing on a total of 12 sites, including financial institutions
2

Education

Bachelor of Science in Computer Science

Projects

CCDCOE Locked Shields 2025 6th
CCDCOE Locked Shields 2025 6th
Blue Team Member Apr 2025

Participated as a member of the South Korea-Canada joint team in the world’s largest live-fire cyber defense exercise, achieving 6th place while defending national IT systems and critical infrastructure against thousands of simulated attacks.

Achilles Level 2 Certification & Testing
Lead Security Consultant Jul 2024 - Mar 2025

Executed Achilles Level 2 certification tests for OT devices, validating protocol robustness and compliance.

Medical Device Security Certification Consulting
Principal Consultant Jun 2024 - Mar 2025

Provided end-to-end cyber-safety consulting for medical devices, including threat modeling and regulatory documentation.

Medical Device FDA Security Consulting
Security Consultant Mar 2024 - Dec 2024

Assisted manufacturers in meeting FDA cyber-security guidance for connected medical devices.

Smart Ship Infrastructure Vulnerability Analysis & Security Tech Development
OT/ICS Researcher Jul 2024 - Nov 2024

Performed vulnerability analysis of maritime OT networks and developed tailored defensive technologies.

HW Supply-Chain Security & Chip Integrity Verification Tech Development
Research Engineer Jun 2024 - Dec 2024

Researched side-channel and invasive analysis techniques to verify semiconductor integrity across the supply chain.

Cloud-based Cyber Training Ground Construction & K-SDL Development
Technical Lead Jun 2024 - Dec 2024

Built a scalable cloud cyber-range and developed the Korean Secure Development Lifecycle (K-SDL) curriculum.

IoT Embedded Device Bug Hunting (5 CVEs)
Vulnerability Researcher Apr 2024 - May 2024

Discovered and responsibly disclosed 5 CVEs in commercial IoT devices through protocol fuzzing.

LS Electric Threat Modeling Consulting for Automation Equipment
Threat Modeling Lead Mar 2023 - Nov 2023

Developed STRIDE-based threat models and mitigation matrices for PLC & HMI product lines.

IoT Incident Investigation Tool Development
Software Engineer Aug 2022 - Dec 2022

Built a Python-based toolkit to acquire, parse, and analyze artefacts from compromised IoT devices.

Smart Building IoT Device Vulnerability Detection Tech Development (2nd Year)
Lead Researcher Jan 2022 - Oct 2022

Enhanced ML-driven fingerprinting and anomaly detection engines for smart-building IoT networks.

KEPCO Practical Cyber-Security Training System Enhancement
OT Security Engineer Jun 2021 - Mar 2025

Upgraded an ICS cyber-range for KEPCO, adding realistic attack/defense scenarios and automated scoring.

C2021 Event Hosting
Organizer May 2021 - Dec 2021

Planned and hosted Korea’s premier convergence-security conference, featuring live CTF and workshops.

SBI Savings Bank Digital Platform & Open Banking Security Review
Pentester Mar 2021 - May 2021

Conducted web/mobile pentesting and secure-coding review for the bank’s open-banking APIs.

HKMC Business System Continuous Penetration Testing
Pentester Jan 2021 - Feb 2021

Delivered continuous penetration testing service for HKMC’s enterprise systems.

KOFIA Electronic-Finance Infra Vulnerability Assessment
Security Analyst Nov 2020 - Dec 2020

Performed network, web, and mobile assessments across critical trading infrastructure.

KT Giga Genie Terminal Penetration Testing
IoT Pentester Oct 2020

Identified firmware and API vulnerabilities in smart-speaker terminals.

KTH Daekyo Integrated Education Platform Penetration Testing
Web Pentester Sep 2020

Assessed authentication and business-logic flaws in an ed-tech SaaS platform.

UNTAC Security Review & Penetration Testing
Security Consultant Jul 2020 - Sep 2020

Provided holistic security assessment for UN Technology & Communication Agency infrastructure.

Finding Vulnerabilities Using CodeQL (Stealien Security Leader 1st)
Research Trainee Sep 2020 - Dec 2020

Automated static-analysis queries to uncover zero-days with GitHub CodeQL.

Kernel Exploit with FileSystem Fuzzer (16 CVEs)
Lead Fuzzer Jul 2019 - Mar 2020

Developed a coverage-guided filesystem-driver fuzzer for Linux kernel; disclosed 16 CVE-class vulnerabilities.

KNU Notification Crawler Development
Full-Stack Developer Sep 2019 - Nov 2019

Created a crawler and web dashboard to aggregate university notices in real-time.

Keyword-Based News Crawler Development
Developer Jul 2018

Built a Python crawler that delivers keyword-filtered news via chatbot notifications.

Featured Posts

Recent Posts

Achievements

16 CVEs about Kernel Exploit with FileSystem Fuzzer Best of the Best 8th (Jul 2019 ~ Mar 2020)

5 CVEs about IoT Embedded Device Bug Hunting Coresecurity (Apr 2024 ~ May 2024)

Achilles Level 2 Certification & Testing (Jul 2024 ~ Mar 2025)