Skip to content
berkan.fr
Lire en français
Open to freelance work

Security researcher & software engineer

Berkan YILDIZ

I take software apart to understand how it really works — and I build what runs beneath the operating system.

Founder of Swayor. Security audits of software, games and Windows; UEFI firmware, bootloaders, kernel drivers and hypervisors.

  • Paris, France · Remote
  • Coding since age 11
  • C · C++ · C# · PHP
  • Reverse engineering
  • Security research
  • Windows internals
  • Kernel drivers
  • UEFI firmware
  • Bootloaders
  • Intel VT-x hypervisors
  • Hyper-V internals
  • Hardware fingerprinting
  • Game security
  • Game server emulation
  • Backend & infrastructure

What I do

I break things to understand them — and build things that are hard to break.

Two sides of the same craft: reading systems down to the byte, and engineering the low-level software everything else depends on.

Audit & research

In-depth, independent analysis of the software you ship or rely on.

  • Security audits

    Source and binary review of applications and services, with clear, actionable findings.

  • Game security

    Game clients, network protocols and protections like anti-cheat and anti-tamper — I’ve been reversing games since 2016.

  • Windows internals

    Assessment of drivers, services and the operating-system attack surface on Windows.

  • Reverse engineering

    Binaries, protocols and protections taken apart — no source code required.

Low-level engineering

Software that runs where most software can’t.

  • UEFI firmware & bootloaders

    EDK2 DXE drivers and pre-OS code that runs before Windows boots.

  • Kernel drivers

    Windows kernel drivers built with the WDK and KMDF, and their user-mode communication layers.

  • Hypervisors

    Intel VT-x hypervisors: VMX, VMCS, Extended Page Tables, MSR and exception interception.

  • Products & infrastructure

    Complete products — dashboards, licensing, payments, APIs — and the Debian servers they run on.

Across the stack

From user mode down to the firmware.

Most security work stops at the operating system. Mine keeps going — through every privilege level, down to the code that runs before Windows even boots.

Hover or tap a layer

Projects

From game servers to hypervisors.

A decade of projects across every layer — from reverse-engineered mobile games to a hypervisor loaded by the firmware.

EfiKekPkg

Since 2020

UEFI-based Intel VT-x hypervisor

A thin virtualization layer that starts from an EDK2 DXE driver, before Windows boots. It enables VMX, configures the VMCS and launches the operating system as a guest in VMX non-root mode — observing execution, memory accesses and CPU events from underneath, independently of Windows APIs and drivers.

  • Extended Page Tables: dynamic permissions, large-page splitting and violation handling
  • MSR, exception and NMI-window interception
  • Per-core hypervisor state across every logical processor
  • Hyper-V internals, synthetic MSRs and guest OS identification
  • Firmware-level logging and hardware-assisted debugging
C/C++ UEFI / EDK2 VMX EPT x86-64 assembly

HwidSpoofer

Since 2019

Windows hardware identity research & spoofing suite

A kernel driver, a WPF client, service libraries and a Discord-based orchestration system. It controls the identifiers used to fingerprint a machine — storage, network adapters, SMBIOS and other firmware-exposed values — from a privileged layer, so that Windows presents a consistent alternate hardware profile.

  • Windows kernel driver with IOCTL communication to user mode
  • Research into hardware identifiers and fingerprinting surfaces
  • Pre-OS setup through EfiKekPkg
  • WPF client, licensing, Discord automation and deployment pipeline
C/C++ C# .NET 10 WPF WDK

Private game servers

Since 2016

Mobile game reverse engineering

My first big reverse-engineering playground. I took Supercell’s mobile games apart — Clash of Clans and Boom Beach, then Clash Royale and Brawl Stars as soon as they launched — and rebuilt their servers so that the original clients could connect to mine.

  • Reverse engineering of the game clients and their network protocols
  • Server emulation for Clash of Clans, Boom Beach, Clash Royale and Brawl Stars
  • Clash Royale server, client and proxy, published as open source
  • PUBG lobby backend emulation, also open source
Clash of Clans Boom Beach Clash Royale Brawl Stars

Also: BadPing, and a range of backend, automation and infrastructure tools running in production.

About

Old school, by choice.

I’m Berkan, a 27-year-old self-taught software engineer and low-level systems developer. I started programming at 11 and built my first PHP websites around 13 — since then, I’ve worked across the whole stack, from web platforms and databases to Windows drivers, firmware and hypervisor research.

Games were my first reverse-engineering playground: around 2016, I took apart Clash of Clans and Boom Beach and built private servers for them, then did the same with Clash Royale and Brawl Stars when they launched.

My strongest area is low-level Windows and systems engineering: C, C++ and C#, Windows kernel development with KMDF, UEFI/EDK2, Intel VT-x and EPT, Hyper-V internals, memory management and hardware identifiers. I enjoy problems that require understanding what happens underneath the APIs, the drivers and the user-mode software.

As the founder and sole engineer behind Swayor, I also build complete products end to end — customer dashboards, licensing, payment flows, APIs, automation — and run the infrastructure behind them myself: Debian servers, DNS, SSL, firewalls, backups and monitoring.

I’m comfortable owning hard technical problems alone, from research and architecture to deployment and support.

Toolbox

Languages
C C++ C# x86-64 assembly PHP
Low level
WDK KMDF UEFI / EDK2 Intel VT-x EPT Hyper-V
Backend & apps
Laravel .NET WPF MariaDB / MySQL Visual Studio
Infrastructure
Debian Proxmox Networking DNS SSL Firewalls

My company

Swayor

Cybersecurity & software engineering, made in France.

Since 2015 · Paris, France · Remote

I founded Swayor in 2015 and have been its sole engineer ever since. We audit and examine software, games and Windows systems, design low-level software — UEFI firmware, bootloaders, kernel drivers and hypervisors — and build complete products, from customer dashboards and licensing to the infrastructure they run on.

  • Security audits

  • Reverse engineering

  • Game security

  • Firmware & kernel drivers

  • Hypervisors

  • Products & infrastructure

Contact

Let’s talk.

I’m open to freelance work on Windows internals, kernel development, reverse engineering, UEFI and firmware, hypervisor research, backend systems and infrastructure — or anything technically complex. Tell me about it.

Your details are only used to reply to you. Read the privacy policy.