Alert triage and rule tuning
Enterprise monitoring with SIEM/SOAR, EDR/XDR, threat intelligence, IoC analysis, and false positive reduction.
Selam :)
Çağla Aydın
BurrowPwner
SOC analyst / purple team mindset / Ankara - Istanbul
Junior Cyber Security Analyst and Computer Engineer focused on alert analysis, detection validation, incident follow-up, and threat-informed defense.
USE TERMINAL CTF starts beloweverything is logged
THREAT HUNT
IoC correlationLive security architecture
Enterprise monitoring with SIEM/SOAR, EDR/XDR, threat intelligence, IoC analysis, and false positive reduction.
Penetration testing labs, AD attack simulations, privilege escalation, web exploitation, and Burp-driven traffic review.
Experience log
A cleaner experience board from my CV. Turkcell carries the main SOC story; the other roles stay compact and open into detail panels.
2025 - Present / İstanbul
SOC monitoring, alert analysis, malware and log investigations, customer communication, detection validation, rule tuning, false positive reduction, and Purple Team support.
Embedded product screens
LynxGate is my end-to-end Web IDS platform: Snort 3 detection, Docker Compose, FastAPI, Redis, PostgreSQL, and a React SOC dashboard for real-time alert monitoring. This read-only showcase presents the actual product screens without exposing the running system.
GET /etc/passwd HTTP/1.1 | Host: app.example.com | source: 185.22.91.44
Gateway access log and Snort JSON were correlated, then retained for analyst review.
alert tcp any any -> any 80 ( msg:"LOCAL LynxGate custom admin probe"; http_uri; content:"/lg-custom-trigger"; classtype:web-application-attack; sid:1000001; rev:1; )
Attack type distribution, protocol mix, severity split, and daily trend analysis from retained IDS telemetry.
The Defense screen shows the response layer that turns IDS alerts into operational follow-up: blacklist checks, notification flow, and response state.
An alert reached the queue. Read the context, then choose a response. Every option is defensible somewhere; only one fits this alert.
The Management screen summarizes how protected web origins connect through the gateway into Snort and backend telemetry.
Send a request at the protected origin and watch the rule engine decide. Nothing leaves your browser: matching runs locally against the same Snort rule classes LynxGate ships.
Submit this flag in the terminal to clear it.
Black Rabbit arcade
A tiny offline-runner inspired arcade mode: jump over packets, collect pixel carrots, and keep the signal alive.
Submit this flag in the terminal to clear it.
Tooling and tactics
Contact
Available for cybersecurity collaboration, SOC analysis, defensive research, and security-focused engineering work.
Signal log
A name is optional. Leave it blank and the signal is anonymous - the rabbit will not ask twice.