Software Engineering student (3rd year) at Ostim Technical University, Ankara. I build and break my own infrastructure to learn how attacks show up in logs and how networks are defended.
- 🛡️ Experience: Network Security intern at Türk Telekom (Jun 2026)
- 🔭 Now: running a segmented home network (OPNsense, 5 VLANs, MFA VPN). Next up: Wazuh, Suricata and Zeek on top of it
- 🤖 Interested in: AI-assisted detection. Correlated alerts go in, an LLM proposes severity and ATT&CK mapping, and a human decides. The model never acts on its own
- 🧰 Tools: Wazuh · Splunk · Sysmon · Suricata · Zeek · OPNsense · Proxmox · Linux · Python · Bash
| Project | What it shows |
|---|---|
| segmented-soc-homelab | Network design from scratch: VLAN segmentation, default-deny firewall, a management plane reachable only through VPN, a tested break-glass path, and write-ups of real incidents |
| atlas-live · atlas-ios | Speech-to-speech voice agent on the Gemini Live API (desktop and native iPhone). Tool calling, a 34-case Turkish evaluation set (97% end-to-end), and design decisions made from measurements |
| wazuh-soc-homelab | Wazuh SIEM/EDR watching a cloud VPS over Tailscale. It caught and blocked a real brute-force attack |
| edr-detection-lab | Sysmon + Splunk + Atomic Red Team: simulate a technique, find it in the logs, write the detection (MITRE ATT&CK mapped) |
| security-writeups | HackTheBox Sherlock investigations (DFIR, phishing, log analysis), focused on how I got to the answer, not just the flag |
