Gyuho Lee
DFIR Specialist โ€ข Frontend Developer
github iidx โ€ƒ email extr3.0@gmail.com โ€ƒ linkedin Gyuho Lee

About Me

Nick Name

ยป extr
Interested In

ยป Cyber Threat Intelligence
ยป Web Service Development
ยป Tea & Whisky
Skills
Security x64dbg IDA X-Way Forensics EnCase FTK ...
Development Nest.js Next.js Turborepo FastAPI Django ...
Operation vSphere DBMS API GW FW SIEM EDR ...
CTF & Research Groups
2019- HypwnLab, South Korea
ยป Nondisclosure 1-day & 0-day Research Group
2015-2017 DCUA, Multinational
ยป CTF Team (dcua & some Penthackon members)
2014-2015 Penthackon, Multinational
ยป CTF Team (Penthackon & some WOWHACKER members)
2013- WOWHACKER, South Korea
ยป Research Group
2012-2013 TeamTMP, South Korea
ยป CTF Team (4th & factorial)
2011-2012 4th, South Korea
ยป CTF Team

Experience

CERT, KakaoBank
Gyeonggi, South Korea
May 2026 - Present
-

ยป -
CERT, Bithumb
Seoul, South Korea
Feb 2025 - Apr 2026
-

ยป Leveraged AI-driven CTI analysis to produce internal threat intelligence reports, and implemented SOAR integrations and custom actions to streamline response workflows.
ยป Conducted continuous EDR event analysis to strengthen incident prevention and response, and developed SIEM detections/use-cases.
ยป Established and operated SCA/OSS supply-chain security policies to block vulnerable or malicious components from entering the SDLC.
ยป Planned and ran monthly phishing simulations and biannual crisis response drills (DDoS/phishing) to improve organizational readiness.
Security Service Developer, NCSOFT
Gyeonggi, South Korea
May 2021 - Dec 2024
3 years, 8 months

ยป Developed an internal security policy lookup portal for the security center and company-wide users.
ยป Designed and implemented a security review management system for game, web, and API service deployments.
ยป Built a Security Appliance API Gateway to streamline secure development and standardize security controls.
ยป Developed malicious network traffic detection modules and supported ongoing event analysis and monitoring.
DFIR Specialist, Plainbit Co., Ltd.
Gyeonggi, South Korea
Aug 2019 - May 2021
1 year, 10 months

ยป Supported digital evidence acquisition and forensic analysis across multiple small-to-mid scale incidents, including ransomware and APT intrusions.
ยป Built automation tools to accelerate triage and analysis workflows in time- and resource-constrained investigations.
Senior Researcher, Culture Makers
Seoul, South Korea
Nov 2018 - Jul 2019
8 months

ยป Military Service (Skilled Industrial Personnel)
ยป Organized information security competitions and produced infosec training/educational content.
ยป Managed virtual lab networks using VMware vSphere and developed supporting administration/management tools.
Security Researcher, SEWorks Inc.
Seoul, South Korea / CA, United States
Feb 2017 - Nov 2018
1 year, 10 months

ยป Military Service (Skilled Industrial Personnel)
ยป Developed automation tools to support product operations and backend server administration.
ยป Built analysis modules for detecting and analyzing malicious Android APKs.
ยป Contributed to the development of a game engine obfuscation module based on LLVM Obfuscator.
Software Vulnerability Analyst, WINS Co., LTD.
Gyeonggi, South Korea
Jan 2016 - Jan 2017
1 year

ยป Conducted vulnerability research and analyzed 1-day vulnerabilities.
ยป Actively participated in incident response engagements as a CERT analyst, performing root-cause analysis and impact assessment.
Security Researcher, Divine Security
Gyeonggi, South Korea
Jan 2015 - Jun 2015
6 months

ยป Developed a malicious APK analysis module for malware triage and behavioral analysis.
Security Consultant, *****
Seoul, South Korea
Mar 2013 - Aug 2013
6 months

ยป Performed black-box and white-box penetration testing across web and application targets.
ยป Supported G-ISMS/ISMS compliance initiatives, including security assessments and documentation.

Achievement/Awards

Only showing the results of top 3 places and finalists of memorable CTFs,
International
2020 1st place, InterKosen CTF Japan
2020 1st place, Defenit CTF South Korea
2019 1st place, Harekaze CTF Japan
2019 3rd place, DFRWS IoT Forensic Challenge, write-up United States
2018 2nd place, Digital Forensic Challenge 2018 South Korea
2017 2nd place, ASIS CTF Finals Iran
2017 3rd place, Volga CTF Russia
2016 Finalist, TrendMicro CTF Japan
2016 2nd place, EKOPARTY CTF 2016 Argentina
2016 1st place, ASIS CTF Finals Iran
2016 1st place, Volga CTF Russia
2014 Finalist, DEFCON 22 CTF United States
Domestic
2022 Finalist, Cyber Conflict Exercise Daegu, South Korea
2019 Finalist, Cyber Conflict Exercise Busan, South Korea
2015 1st place, 14th HUST Hacking Festival Seoul, South Korea
2015 1st place, Find the Digital Culprit Seoul, South Korea
2015 1st place, Inc0gnito Hacking Competition Seoul, South Korea
2014 3rd place, Find the Digital Culprit Seoul, South Korea
2013 3rd place, Whitehat Contest Seoul, South Korea
2013 3rd place, Find the Digital Culprit Seoul, South Korea
2011 Bronze Prize, Soonchunhyang University 'Y.I.S.F.' Asan, South Korea
2011 Bronze Prize, Tongmyong University 'Information Science Olympiad' Busan, South Korea

Portfolio

Software Vulnerability Reports
CVE-2022-41156 Remote Code Execution, Ondisk Player Agent
CVE-2022-23766 Arbitrary File Execution, BigFile Agent
CVE-2020-7881 Remote Code Execution, AfreecaTV streamer service
CVE-2019-12808 Local Privilege Escalation, ALTOOLS update service
RIDI Bug Bountry Remote Code Execution, Ridibooks Qt Viewer
KVE-2018-1470 Remote Code Execution, Infoleak NDA
KVE-2018-0128 Remote Code Execution, NDA
KVE-2018-0058 Heap Buffer Overflow, NDA
KVE-2017-0226 Remote Code Execution, NDA
KVE-2017-0129 Arbitrary File Read, NDA
CTF Organizer and Challenge Author
2021 Organizer and Challenge author, ACSC
ยป Challenge write-up: NYONG Coin & BitLocker Artifact
2021 Challenge author, ๅผบ็ฝ‘ๆฏๅ…จๅ›ฝ็ฝ‘็ปœๅฎ‰ๅ…จๆŒ‘ๆˆ˜่ต›
2020 Challenge author, PBCTF
ยป Challenge write-up: Vaccine Stealer
2020 Organizer and Challenge author, Bingo CTF
ยป Challenge write-up: ISO & Disassembed
2018 Challenge author, Cyber Conflict Exercise & Contest
2015-2016 Organizer and Challenge author, Christmas CTF
2015 Challenge author BoB CTF
2013-2016 Organizer and Challenge author, KAIST and POSTECH Science War (Hacking)
2012-2013 Organizer and Challenge author, Hoseo Information Security Challenge
Presentation
2019 Memory forensics using volatility, Supreme Prosecutors' Office
ยป SPO training course
2014 WOWHACKER OFFSET open hacking seminar - 1st., WOWHACKER
ยป Analyze and demonstrate ADD(Attention Deficit Disorder) technology of memory anti-forensics.