cyb-sec:~$ whoami
Ersin Uyanik
Cybersecurity Analyst · SOC Operations · Blue TeamCybersecurity Analyst · SOC Operations · Blue Team
CompTIA A+, Security+ and CySA+ certified cybersecurity professional based in Germany, currently completing an intensive Cybersecurity Weiterbildung at Masterschool. I build practical experience through documented Blue Team labs focused on SIEM monitoring, network traffic analysis, threat detection, vulnerability management and incident response. My goal is to bring this foundation into a SOC environment, contribute as an entry-level analyst and continue developing through real-world security operations.
Mit CompTIA A+, Security+ und CySA+ zertifizierter Cybersecurity Professional aus Deutschland, derzeit in einer intensiven Cybersecurity-Weiterbildung bei der Masterschool. Durch dokumentierte Blue-Team-Labs sammle ich praktische Erfahrung in den Bereichen SIEM-Monitoring, Netzwerkverkehrsanalyse, Bedrohungserkennung, Vulnerability Management und Incident Response. Mein Ziel ist es, dieses Fundament in ein SOC einzubringen, als Berufseinsteiger aktiv zum Security Operations Team beizutragen und mich durch praktische Erfahrung kontinuierlich weiterzuentwickeln.
CertificationsZertifizierungen
CompTIA CySA+
July 2026Juli 2026
CompTIA Security+
March 2026März 2026
CompTIA A+
January 2026Januar 2026
Security Analytics Professional
CompTIA Stackable Certification · July 2026CompTIA Stackable Certification · Juli 2026
Core SkillsKernkompetenzen
SOC & Detection
Wazuh, Suricata, SIEM monitoring, alert triage, MITRE ATT&CK mapping, detection engineering and security reporting.
Network AnalysisNetzwerkanalyse
Wireshark, nmap, TCP/IP, DNS, HTTP, TLS, ARP, host enumeration and packet-level investigation.
Security OperationsSecurity Operations
Incident response fundamentals, vulnerability management, Linux, Windows, firewalls, log analysis and technical documentation.
Home Lab ProjectsHome-Lab-Projekte
LAB_00
Network Discovery & Host Enumeration
Mapped a live multi-device home network using nmap, arp-scan and ping sweeps. Identified active hosts, open ports and running services. Lab hardware: MacBook Pro (management), iMac 12,1 Ubuntu lab server, ThinkPad Kali, Fritz!Box + TP-Link RE190 repeater discovered via MAC OUI analysis. Documented with privacy masking — OUI-only MAC addresses, anonymised hostnames.Live-Netzwerk mit mehreren Geräten mit nmap, arp-scan und Ping-Sweeps kartiert. Aktive Hosts, offene Ports und laufende Dienste identifiziert. Labor-Hardware: MacBook Pro (Management), iMac 12,1 Ubuntu-Lab-Server, ThinkPad Kali, Fritz!Box + TP-Link RE190 Repeater per MAC-OUI-Analyse entdeckt. Dokumentation mit Datenschutz-Maskierung — nur OUI-MAC-Adressen, anonymisierte Hostnamen.
LAB_01
Wireshark Traffic AnalysisWireshark-Datenverkehrsanalyse
Captured and analysed live traffic across five protocol layers: ICMP (echo/reply, TTL), DNS (query/response, A records), HTTP (cleartext headers, response codes), ARP (who-has, is-at, gratuitous ARP), TLS/QUIC (handshake, certificate exchange). JA3 fingerprinting applied. Cross-lab finding: passive traffic identified unknown device as Amazon Fire Stick via UPnP + Spotify Connect signatures.Live-Datenverkehr auf fünf Protokollebenen erfasst und analysiert: ICMP (Echo/Reply, TTL), DNS (Anfrage/Antwort, A-Records), HTTP (Klartext-Header, Antwortcodes), ARP (who-has, is-at, gratuitous ARP), TLS/QUIC (Handshake, Zertifikataustausch). JA3-Fingerprinting angewendet. Lab-übergreifender Fund: Passiver Datenverkehr identifizierte unbekanntes Geraet als Amazon Fire Stick via UPnP + Spotify-Connect-Signaturen.
LAB_02
Wi-Fi Security — WPA2 Assessment (Own Network)WLAN-Sicherheit — WPA2-Bewertung (Eigenes Netzwerk)
Controlled wireless assessment against own Fritz!Box. WPA2 4-way handshake capture, PMKID attack, deauthentication, MAC spoofing, offline dictionary attack with rockyou.txt. Key finding: strong passphrase not found in dictionary — positive security confirmation. BSSID filter applied throughout — no third-party networks captured.Kontrollierte WLAN-Sicherheitsprüfung am eigenen Fritz!Box-Router. WPA2-4-Wege-Handshake-Erfassung, PMKID-Angriff, Deauthentifizierung, MAC-Spoofing, Offline-Wörterbuch-Angriff mit rockyou.txt. Ergebnis: Starke Passphrase nicht im Wörterbuch gefunden — positive Sicherheitsbestätigung. BSSID-Filter durchgehend aktiv — keine fremden Netzwerke erfasst.
LAB_03
Firewall & Network Segmentation
Host firewall rules designed and implemented using ufw and iptables. Zone-based segmentation across lab network, rules validated via nmap, brute force detection tested using Hydra against SSH. ufw log analysis confirmed block effectiveness. Cross-lab finding: brute force packet patterns from Wireshark lab confirmed in firewall logs.
CH_01
IDS Deployment & First Detection
Deployed Suricata IDS 7.0.3 + Wazuh SIEM 4.14.4 across a 4-node lab: MacBook Pro management (172.20.10.4), Wazuh OVA via VirtualBox SIEM server (172.20.10.9), Kali laptop attacker (172.20.10.8), aegis-sentinel Ubuntu VM sensor (172.20.10.6). Full pipeline: Suricata eve.json → Wazuh Agent → Manager → Dashboard. Two attack simulations validated: nmap -sS -A -T4 recon detected as ICMP anomaly (T1595), Hydra SSH brute force triggered rule 40112 at level-12 critical (T1078 + T1110). Full MITRE ATT&CK mapping confirmed on Dashboard.
CH_02
Active Defense & Detection Engineering
Transitioned aegis-sentinel from passive detection to active defense. Three independent layers deployed and tested against live Hydra SSH brute force: (1) Wazuh Active Response — firewall-drop on rule 5763, attacker IP auto-blocked via iptables DROP within seconds; (2) Custom Suricata rule sid:9000001 — lab-specific SSH brute force signature; (3) fail2ban integration — syslog → Wazuh Agent → Manager → Dashboard, rule 100100, T1110 confirmed. Core Ch.01 finding ("passive detection only") fully resolved.aegis-sentinel von passiver Erkennung auf aktive Verteidigung umgestellt. Drei unabhängige Schichten gegen live Hydra-SSH-Brute-Force getestet: (1) Wazuh Active Response — firewall-drop auf Regel 5763, Angreifer-IP per iptables DROP innerhalb von Sekunden gesperrt; (2) Benutzerdefinierte Suricata-Regel sid:9000001 — lab-spezifische SSH-Brute-Force-Signatur; (3) fail2ban-Integration — syslog → Wazuh Agent → Manager → Dashboard, Regel 100100, T1110 bestätigt. Kernbefund aus Ch.01 vollständig behoben.
CH_03 → CH_07
Upcoming: PCAP Forensics · Exploitation · Lateral Movement · Rule Writing · Incident Response
Advanced SOC scenarios in progress — offline network forensics and timeline reconstruction, offensive simulation, lateral movement detection, custom detection rule engineering, and full incident response playbook execution.Fortgeschrittene SOC-Szenarien in Bearbeitung — Offline-Netzwerkforensik und Zeitachsenrekonstruktion, Angriffssimulation, Lateral-Movement-Erkennung, benutzerdefinierte Erkennungsregeln und vollständige Incident-Response-Playbook-Ausführung.
ContactKontakt
I am currently applying for entry-level SOC and Cybersecurity Analyst roles in Germany — on-site, hybrid or remote.
Feel free to contact me regarding opportunities, projects or professional exchange.
Ich bewerbe mich aktuell auf Einstiegspositionen als SOC Analyst oder Cybersecurity Analyst in Deutschland — vor Ort, hybrid oder remote.
Kontaktieren Sie mich gerne zu Stellenangeboten, Projekten oder zum fachlichen Austausch.