Skip to content
View cyb-ersin's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report cyb-ersin

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cyb-ersin/README.md

Hi, I'm Ersin 👋

SOC Operations · Detection Engineering · Incident Response

Blue Team–focused cybersecurity practitioner building hands-on experience in
security monitoring, detection, investigation and incident response.

I turn theory into evidence through hands-on labs: collecting telemetry, investigating suspicious activity, validating detections and documenting analyst decisions.


CompTIA CSAP CompTIA CySA+ CompTIA Security+ CompTIA A+

🔐 Core Skills

SOC Monitoring SIEM Detection Engineering Threat Hunting Incident Response Log Analysis PCAP Forensics Network Security MITRE ATT&CK

🛠️ Technical Stack

SIEM · Detection · Monitoring

Splunk Wazuh Suricata IDS Syslog

Network · Forensics

Wireshark tcpdump Nmap pfSense Greenbone GVM

Systems · Identity

Linux Ubuntu Kali Linux Windows Windows Server Active Directory

Scripting · Security Engineering

Python Bash PowerShell UFW iptables Hydra

Networking Fundamentals

TCP/IP DNS DHCP HTTP/S TLS VLANs Subnetting Network Segmentation


🛡️ Featured Projects

Project Aegis — SOC Operations & Detection Engineering

Personal Blue Team lab focused on the full security-analysis lifecycle.

Telemetry → Detection → Validation → Investigation → Response

  • Deployed Suricata IDS and Wazuh SIEM for centralized security monitoring
  • Built and validated detection logic for reconnaissance and authentication attacks
  • Implemented automated response with Wazuh Active Response and fail2ban
  • Reconstructed reconnaissance, brute-force activity and successful access from an 8,936-packet PCAP
  • Documented detection gaps, evidence and lessons learned from each investigation

Current direction: Detection Engineering · Threat Hunting · Incident Investigation · Security Automation

➡️ Explore Project Aegis


🏭 KRANOTECH — IT/OT Security & SOC Capstone

Four-segment capstone: Design → Build → Secure & Monitor → Validate & Recover

  • Designed an 8-zone Default-Deny IT/OT architecture with separate Employee/Vendor VPN pools
  • Implemented the PoC with KVM/libvirt, pfSense, Windows Server/AD, Windows and Linux DMZ/OT systems
  • Centralized network, Windows and Linux telemetry in Splunk Enterprise and integrated Suricata EVE JSON
  • Built 3 baseline SPL detections, 2 SOC dashboards and 7 final alerts
  • Validated 4 controlled scenarios; a disposable DMZ compromise succeeded while the attempted OT TCP/502 pivot was blocked
  • Completed incident preservation → containment → restore → re-test and vulnerability remediation
  • Documented troubleshooting, lessons learned, design decisions, evidence and four final technical reports

➡️ Explore KRANOTECH


📘 HomeLab Foundation — Network & Security Fundamentals

Foundation work behind Aegis and KRANOTECH.

Network Discovery · Wireshark Traffic Analysis · WPA2 Security Testing · Firewalling · Network Segmentation

➡️ Explore HomeLab Foundation


📌 At a Glance

4
CompTIA Certifications
3
Aegis Chapters Completed
8,936
Packets Investigated
4 Segments
KRANOTECH Capstone

📜 Certifications

CompTIA CSAP CompTIA CySA+ CompTIA Security+ CompTIA A+


🎯 Current Focus

Building Project Aegis into a deeper SOC and Detection Engineering portfolio.

Detection Engineering · Threat Hunting · Incident Investigation · Detection Validation · Security Automation

Target roles: Junior SOC Analyst · Cybersecurity Analyst · Security Operations


🔗 Connect

LinkedIn Portfolio Project Aegis KRANOTECH

Build visibility. Detect behavior. Investigate evidence. Improve the detection.

Popular repositories Loading

  1. HomeLab_Project_Aegis HomeLab_Project_Aegis Public

    Attack/Defense SOC lab series — Suricata IDS + Wazuh SIEM with MITRE ATT&CK mapping. Built on HomeLab_Foundation.

    1

  2. HomeLab_Foundation HomeLab_Foundation Public

    Hands-on networking and security foundation labs — Wireshark, nmap, aircrack-ng, firewall hardening. Built alongside CompTIA studies.

  3. cyb-ersin cyb-ersin Public

    My GitHub profile — certifications, home lab projects, and my journey into SOC Operations & Detection Engineering.

  4. KRANOTECH-Security-Capstone KRANOTECH-Security-Capstone Public

    IT/OT security capstone featuring pfSense segmentation, Splunk SIEM, Suricata IDS, detection engineering and incident response.

    Shell