Istanbul, Türkiye
I am a seasoned cybersecurity professional with over 10 years of experience specializing in incident response and threat hunting. I've developed a deep understanding of complex security systems, leveraging cutting-edge technologies to identify and remediate threats. My career began in penetration testing, where I cultivated a strong foundation in exploiting vulnerabilities and testing system defenses. This hands-on experience with attack methodologies provided a unique perspective when transitioning into the roles of incident response and threat hunting. It is this perspective that allows me to think like an attacker and proactively identify hidden threats. As a Senior Incident Responder and Threat Hunter, I've been leading a dedicated team in safeguarding corporate assets against a broad spectrum of cybersecurity threats. My work primarily involves managing incident response efforts, proactive threat hunting, forensic analysis, and developing and implementing strategic countermeasures. Detail-oriented and proactive, I'm known for my ability to identify hidden threats and suspicious activities in their infancy, thereby minimizing potential damage. Additionally, my experience collaborating with cross-functional teams and stakeholders at all levels of an organization has equipped me with excellent communication skills, enabling me to translate complex security issues into understandable and actionable insights. I aim to continue contributing to the cybersecurity field, fostering a security-conscious culture within organizations while staying updated with the latest cyber threats and trends. I am always open to connecting with like-minded professionals in the industry and welcome opportunities for collaboration and knowledge sharing. Webinars ----------------- ChatGPT for SOC Teams: https://www.youtube.com/watch?v=G6xjPziKmJA Usage of Windows Binaries by Attackers Perspective https://www.youtube.com/watch?v=1Ri9-vDjKks Top 10 Alert Type and Analysis Fundamentals https://www.youtube.com/watch?v=rRaMjv3uu6Q ----------------- Self Education - Readings -----‐---------- 2020 - Practical Malware Analysis: The Hands-on Guide to Dissecting Malicious Software 2019 - Applied Network Security Monitoring: Collection, Detection, and Analysis 2019 - Advance Linux
- Lead a team of MDR analysts in monitoring and responding to security incidents and threats. - Analyzes security alerts to prioritize escalation to Threat Hunters who interact with customers. - Utilizes knowledge of current cyber threats and their associated tactics, techniques, and methods for breaching computer networks to proactively search for malicious activity on customer networks. - Skillfully interprets and assesses unprocessed network traffic and alerts based on network activity to identify potential data breaches and suspicious file downloads. - Shares detailed analysis and findings at various stages of the workflow to contribute to collective defense efforts and produce Threat Intelligence reports. - Engages in collaborative efforts with interdisciplinary teams to achieve common goals and ensure overall success. - Demonstrates efficient and effective performance while operating in a remote or virtual environment. - Provide reports on the status of the MDR to management and other stakeholders peridiocally. - Constructs queries and conducts hunting activities using EDR/SIEM to delve deeper into potentially malicious alerts. - Provided briefings and training sessions to acquaint individuals with our team's methodologies and recommended tools. - Analyze and report training needs and provide training to analysts - Conducts research and validates Threat Intelligence to maintain the product's efficacy. - Work collaboratively with IT and Red/Pentest teams to address action points - Represent MDR team within customer and internal meetings - Ensure that all incidents are properly analyzed and documented on SOAR.
Proactively identifies weaknesses that may go undetected by automated security tools, or detected but not alerted. To find these potential security weaknesses cyber threat hunting involves monitoring network traffic, endpoints logs and activities not look like incidents that might otherwise go undetected.
• Create, configure and fine tune correlation rules for Wazuh/ELK according to customer environment and requirements. • Review, analyze, escalate and respond to security events triggered through the Wazuh/ELK - EDR according to internal security procedures of the customer. • Create, manage and run reports, queries for managers by using SIEM.
• Create, configure and fine tune correlation rules for SIEM according to customer environment and requirements. • Review, analyze, escalate and respond to security events triggered through the SIEM according to internal security procedures of the customer. • Create, manage and run reports, queries for managers by using SIEM. • Document procedures for other analysts. • Provide a technical support for L1 and investigate escalated incidents. • Perform incident analysis. • Providing Network Security Solutions over 80+ location (IPS/IDS, SIEM, Log Management, Netflow, Threat Intelligence, Honeypot) • Designing, optimizing and maintaining open-source cybersecurity solutions (Snort/Suricata, ELK Stack, Ossec etc.) • Log management (Analysis, correlation, timestamps and archiving) • Defining, hardening and auditing the security policies • Providing enterprise trainings for the available courses
• Incident Response (HvKK-CERT) • Cyber Threat Intelligence • Network Security Monitoring and Attack Analysis • Penetration Test • Web Applications Security Testing • Turkish Air Force - Cyber Shield Exercise 2013, 2015 • In-house Capture the Flag Competitions