Rafi Gana

Cybersecurity Specialist

Home Blog Portfolio

Security that Coexists.

Coverage

Research

Validation

Insight

Worked with

areas of expertise

Embedded & IoT

Network & RF

Linux & Android

Reverse Engineering

Exploits & Mitigations

Binary Mitigations Part 1: Don't Bother The Little Birdie

22/08/2024

Embedded Research: Bits & Pieces

03/10/2023

JS Engines Optimization: Faster Than Fast

26/09/2023

Android Apps Part 5: Going Dynamic

23/08/2023

Android Apps Part 4: Taking a Look Under The Hood

16/08/2023

Android Apps Part 3: That's Not Java! Something Smali In Here...

09/08/2023

Android Apps Part 2: Crossing Bridges, Debugging Android

02/08/2023

Android Apps Part 1: Egg? Chicken? Zygote!

26/07/2023

More Posts

Coming soon...

Professional Experience

I’m excited to introduce myself as someone with strong experience in technical management, cybersecurity, and Eloctronics.
I’ve worked on a variety of projects that involve system design, team leadership, and hands-on work.
With close communication, I’m confident that my skills and problem-solving abilities in different domains will allow me to contribute meaningfully to your team.
Below you can find ways to reach out, looking forward to discussing how I can add value to your company.

Technologies

  • Programming: Python, C, C++, C#, Bash, Assembly (x86/x64, ARM), Web (JavaScript, HTML, CSS), Databases.
  • Networking & Protocols: Wireshark, Burp Suite, WiFi, Bluetooth, CAN Bus, USB.
  • Embedded & OS Security: Android, Linux Internals, Firmware Analysis, EMMC & Flash, FPGA & VHDL.
  • Detection Engineering: Honeypots, Thresholds, DLP, Incident Response.
  • Secure Dev & DevOps: Docker, CI/CD Security, PT, Threat Modeling.
  • Electronics & Test Equipment Multi-meters, Analyzers (Logic, Spectrum, Network), Oscilloscopes, RF.
  • CAD & 3D Printing: PCB Design, FDM, OpenSCAD, SolidWorks

Working Experience

IoT Research Technical Leader – Sayfer.io (2023 – Current)

A org-wide knowledge base for IoT and advanced exploit techniques in a diverse and multi-disciplinary company:

  • Conducting and managing in-depth penetration testing projects in various attack surfaces in all vectors to uncover, exploit and report security weaknesses in proprietary systems to all levels of stakeholders ,from C-level executives all the way to development teams.
  • Participating as a tech specialist in technical sales meetings to ensure long term partnership and trust.

Embedded Systems Security Researcher – CyberToka Ltd. (2020-2022)

I brought a unique expertise in electronic engineering into a strong automotive embedded research team:

  • Conducted RE and vulnerability research on vast attack surfaces including all different layers of the network stack on various systems, leading to multiple critical findings.
  • Provided structured guidance in security related subjects to cross-functional teams, ensuring self-sufficiency and long-term knowledge retention.

Software Engineer and OS Security Researcher – Prime Minister’s Office (2016-2019)

After given the oppertunity to dive into a new field, I managed to become a focal point in application security related projects:

  • Conducted and managed Android applications vulnerability research and full-stack development projects, including exploit development incorporated with detection engineering mechanisms, while coping with modern OS security mitigations.
  • Mentored cyber-security recruits, upskilling modern exploitation techniques and countermeasures.

Electronic Warfare R&D and Maintenance Team Leader – Air Force Base 108 (2013-2016)

I was promoted into a team leader for a team in charge of some of the Israeli air-force's crucial RF systems:

  • Led a team of hardware engineers, accountable for maintenance and development in the field of RF signal generators and high-power transmitters.
  • Encouraged professional growth by crafting tailor-made training programs.

Education

  • 2016-2020: B.Sc. Computer Science, The Academic College of Tel Aviv-Yafo
  • 2011-2013: Electronics Practical Engineer, “Amal 1 Holtz”, Tel-Aviv-Yafo

Languages: Hebrew (Native), English (Full professional proficiency)

Noteable personal project

Developing an integrated dockerized multi-server ecosystem using with both open-source and proprietary services to structure and organize daily workflow, potentially helping others with ADHD unlock their potential. Designed to foster focus, time management and productivity methodologies thorugh structure.