Alert triage and rule tuning
Enterprise monitoring with SIEM/SOAR, EDR/XDR, threat intelligence, IoC analysis, and false positive reduction.
SOC analyst / purple team mindset / Ankara - Istanbul
Junior Cyber Security Analyst and Computer Engineer focused on alert analysis, detection validation, incident follow-up, and threat-informed defense.
THREAT HUNT
IoC correlationLive security architecture
Enterprise monitoring with SIEM/SOAR, EDR/XDR, threat intelligence, IoC analysis, and false positive reduction.
Penetration testing labs, AD attack simulations, privilege escalation, web exploitation, and Burp-driven traffic review.
Experience log
SOC monitoring, security alert analysis, malware and log investigations, customer communication, detection validation, and Purple Team support.
Cybersecurity webinars, community communication, practical knowledge sharing, and technical content facilitation.
Firewall configuration, network segmentation, secure infrastructure deployment, routers, switches, and access points.
Ostim Technical University, English program, with a cybersecurity-focused engineering path.
Featured build
End-to-end web intrusion detection platform using Snort 3, Docker Compose, FastAPI, Redis, PostgreSQL, and a live React dashboard for real-time alert monitoring.
Embedded product screens
A read-only product showcase based on the actual dashboard pages: Overview, Intrusions, Detection Rules, and Threat Intelligence. Visitors see the IDS experience without getting access to the running system.
GET /etc/passwd HTTP/1.1 | Host: app.example.com | source: 185.22.91.44Gateway access log and Snort JSON were correlated, then retained for analyst review.
alert tcp any any -> any 80 ( msg:"LOCAL LynxGate custom admin probe"; http_uri; content:"/lg-custom-trigger"; classtype:web-application-attack; sid:1000001; rev:1; )
Attack type distribution, protocol mix, severity split, and daily trend analysis from retained IDS telemetry.
The Defense screen shows the response layer that turns IDS alerts into operational follow-up: blacklist checks, notification flow, and response state.
The Management screen summarizes how protected web origins connect through the gateway into Snort and backend telemetry.
Black Rabbit arcade
A tiny offline-runner inspired arcade mode: jump over packets, collect pixel carrots, and keep the signal alive.
Tooling and tactics
Contact
Available for cybersecurity collaboration, SOC analysis, defensive research, and security-focused engineering work.