Sandro Gauci

CEO Senior Penetration Tester Chief Mischief Officer

Passau, Bavaria, Germany
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
Sandro Gauci is an experienced security leader and founder with 18 years in offensive security, currently serving as CEO and Senior Penetration Tester at Enable Security in Passau, Germany. He blends hands-on expertise in VoIP, webapp and network penetration testing with strategic leadership, driving product-grade tooling and client engagements. An active open-source contributor, he has significantly enhanced widely used projects like SIPVicious and WAFW00F—adding IPv6, Python 3 compatibility and new WAF detections—demonstrating practical depth in both protocol fuzzing and web defence fingerprinting. His background as a security researcher at GFI underpins a methodical, research-driven approach to vulnerability discovery and remediation. Colleagues know him for a mischievous yet professional style that turns creative attack thinking into concrete, auditable security improvements.
code18 years of coding experience
job7 years of employment as a software developer
stackoverflow-logo

Stackoverflow

Stats
139reputation
5kreached
2answers
0questions
github-logo-circle

Github Skills (18)

web-application-firewall10
sipjs10
python10
waf10
it-security10
security10
sip10
sips10
ipv610
network-security10
sipp10
security-txt9
http-request9
security-scan9
beautifulsoup8

Programming languages (9)

TypeScriptCSSShellC++CMakefileGoHTML

Github contributions (5)

github-logo-circle
EnableSecurity/sipvicious

Jul 2007 - Nov 2022

SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking.
Role in this project:
userBack-end Developer & Security Engineer
Contributions:3 releases, 11 reviews, 354 commits in 15 years 6 months
Contributions summary:Sandro primarily contributed to the SIPVicious project by adding enhancements to existing tools such as `svmap.py` (SIP scanner) and `svwar.py` (SIP war dialer) and the addition of IPv6 support in `svcrack`. The user also made improvements to exception handling, logging, and user interface features in the tools. The commits also include the addition of new functionality, which is consistent with the project's overall goals.
security-toolsosskamailiosecurityfreeswitch
EnableSecurity/wafw00f

May 2014 - Mar 2022

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Role in this project:
userBack-end Developer
Contributions:5 releases, 1 review, 187 commits in 7 years 11 months
Contributions summary:Sandro contributed to the core functionality of the WAFW00F tool, including refactoring the code for Python 3 compatibility, integrating new WAF detection methods, and updating dependencies. They backported features from other projects and added support for new WAFs such as Cloud Flare, Secure Entry Server, and Cisco's ACE XML Gateway. The user also improved the tool by adding custom header support.
application-firewallprivacysecurityweb-applicationweb-application-firewall
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial