Simone Berni

Bologna, Emilia-Romagna, Italy
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
Simone Berni is a software engineer from Bologna with 8 years of experience specializing in security, threat intelligence, and automation. He contributes to high-impact open-source projects—most notably IntelOwl for scalable threat intelligence and enhancements to the Qiling and Speakeasy emulation frameworks—bringing practical malware analysis capabilities like XLM macro deobfuscation and Wannacry killswitch logging. Comfortable across backend engineering and security research, he focuses on robustness (fixing Postgres/integer issues, Unicode handling) and expanding emulation APIs to better reproduce real-world samples. Simone blends hands-on coding with a knack for automating investigative workflows, often tightening reliability and observability in complex security tooling.
code8 years of coding experience
languagesEnglish
stackoverflow-logo

Stackoverflow

Stats
1reputation
0reached
0answers
0questions
github-logo-circle

Github Skills (29)

python10
log-analysis10
wp-api10
it-security10
cybersecurity10
api-hook10
analyse10
winapi10
file-parsing10
text-analysis10
security10
threat-intelligence10
malware10
web-framework10
ws-api10

Programming languages (6)

JavaJavaScriptGoZeekPythonClojure

Github contributions (5)

github-logo-circle
intelowlproject/IntelOwl

Sep 2020 - Jan 2023

IntelOwl: manage your Threat Intelligence at scale
Role in this project:
userBackend & Security Engineer
Contributions:222 reviews, 45 commits, 323 PRs in 2 years 5 months
Contributions summary:Simone contributed significantly to the project by adding and integrating new file analyzers such as `Speakeasy` and `UnpacMe`, as well as deobfuscation capabilities for XLM macros. They also focused on fixing existing code to improve the resilience and reliability of the system, including Postgres errors and integer handling. Furthermore, they upgraded the Yara version and added several new Yara rules, demonstrating a focus on threat intelligence and security analysis within the project.
pythondfiripsthreat-intelligenceosint
mandiant/speakeasy

Mar 2021 - Dec 2021

Windows kernel and user mode emulation.
Role in this project:
userBack-end Developer / Security Engineer
Contributions:1 review, 10 commits, 5 PRs in 9 months
Contributions summary:Simone primarily focused on enhancing the Speakeasy emulation framework. Their contributions included implementing API hooking mechanisms with support for wildcard matching, and improving the efficiency of API searches. They added functionality to log registry and HTTP traffic, including a specific log for InternetOpenUrl to capture Wannacry's killswitch, which demonstrates their focus on malware analysis and security. They also made modifications to the code base, including changes to file read/write, and code to redirect DLLs, while fixing type mismatches.
kernelemulatorwindows-kernelwindowssandbox
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial
Simone Berni