Skip to content
View f23783's full-sized avatar
  • Ankara

Block or report f23783

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
f23783/README.md

Arda Fidancı — Blue Team / SOC

Software Engineering student (3rd year) at Ostim Technical University, Ankara. I build and break my own infrastructure to learn how attacks show up in logs and how networks are defended.

  • 🛡️ Experience: Network Security intern at Türk Telekom (Jun 2026)
  • 🔭 Now: running a segmented home network (OPNsense, 5 VLANs, MFA VPN). Next up: Wazuh, Suricata and Zeek on top of it
  • 🤖 Interested in: AI-assisted detection. Correlated alerts go in, an LLM proposes severity and ATT&CK mapping, and a human decides. The model never acts on its own
  • 🧰 Tools: Wazuh · Splunk · Sysmon · Suricata · Zeek · OPNsense · Proxmox · Linux · Python · Bash

Featured work

Project What it shows
segmented-soc-homelab Network design from scratch: VLAN segmentation, default-deny firewall, a management plane reachable only through VPN, a tested break-glass path, and write-ups of real incidents
atlas-live · atlas-ios Speech-to-speech voice agent on the Gemini Live API (desktop and native iPhone). Tool calling, a 34-case Turkish evaluation set (97% end-to-end), and design decisions made from measurements
wazuh-soc-homelab Wazuh SIEM/EDR watching a cloud VPS over Tailscale. It caught and blocked a real brute-force attack
edr-detection-lab Sysmon + Splunk + Atomic Red Team: simulate a technique, find it in the logs, write the detection (MITRE ATT&CK mapped)
security-writeups HackTheBox Sherlock investigations (DFIR, phishing, log analysis), focused on how I got to the answer, not just the flag

LinkedIn · HackTheBox · TryHackMe

Pinned Loading

  1. edr-detection-lab edr-detection-lab Public

    Endpoint detection pipeline using Sysmon, Splunk, and Atomic Red Team. Learning detection engineering hands-on.

  2. soc-homelab soc-homelab Public archive

    Enterprise-simulated home lab with pfSense, Zeek, Suricata, and Splunk. Network security monitoring playground.

  3. security-writeups security-writeups Public

    CTF solutions and forensic investigations. HackTheBox Sherlocks, machines, and more.

  4. zte-signal-monitor zte-signal-monitor Public

    Real-time LTE signal monitoring dashboard & band locking tool for ZTE routers. Browser bookmarklet with RSRP/RSRQ/SINR tracking, carrier aggregation display, and DNS configuration.

  5. wazuh-soc-homelab wazuh-soc-homelab Public

    Practical Blue Team homelab environment featuring a distributed Wazuh SIEM/EDR setup over Tailscale. Includes strict system hardening, automated IP banning, and a documented real-world brute-force …

  6. segmented-soc-homelab segmented-soc-homelab Public

    Segmented home network built as a SOC lab foundation: OPNsense, VLANs, default-deny firewall, MFA VPN-only management plane, tested break-glass.