cyb-sec:~$ whoami

Ersin Uyanik

Cybersecurity Analyst  ·  SOC Operations  ·  Blue TeamCybersecurity Analyst  ·  SOC Operations  ·  Blue Team

CompTIA A+, Security+ and CySA+ certified cybersecurity professional based in Germany, currently completing an intensive Cybersecurity Weiterbildung at Masterschool. I build practical experience through documented Blue Team labs focused on SIEM monitoring, network traffic analysis, threat detection, vulnerability management and incident response. My goal is to bring this foundation into a SOC environment, contribute as an entry-level analyst and continue developing through real-world security operations.

Mit CompTIA A+, Security+ und CySA+ zertifizierter Cybersecurity Professional aus Deutschland, derzeit in einer intensiven Cybersecurity-Weiterbildung bei der Masterschool. Durch dokumentierte Blue-Team-Labs sammle ich praktische Erfahrung in den Bereichen SIEM-Monitoring, Netzwerkverkehrsanalyse, Bedrohungserkennung, Vulnerability Management und Incident Response. Mein Ziel ist es, dieses Fundament in ein SOC einzubringen, als Berufseinsteiger aktiv zum Security Operations Team beizutragen und mich durch praktische Erfahrung kontinuierlich weiterzuentwickeln.

Actively applying for SOC / Cybersecurity Analyst roles — available from mid-November 2026Aktive Bewerbung auf SOC- und Cybersecurity-Analyst-Stellen — verfügbar ab Mitte November 2026

CompTIA CySA+

July 2026Juli 2026

CompTIA Security+

March 2026März 2026

CompTIA A+

January 2026Januar 2026

Security Analytics Professional

CompTIA Stackable Certification · July 2026CompTIA Stackable Certification · Juli 2026

SOC & Detection

Wazuh, Suricata, SIEM monitoring, alert triage, MITRE ATT&CK mapping, detection engineering and security reporting.

Network AnalysisNetzwerkanalyse

Wireshark, nmap, TCP/IP, DNS, HTTP, TLS, ARP, host enumeration and packet-level investigation.

Security OperationsSecurity Operations

Incident response fundamentals, vulnerability management, Linux, Windows, firewalls, log analysis and technical documentation.

homelab-foundation 4 / 4 completed4 / 4 abgeschlossen → GitHub

LAB_00

Network Discovery & Host Enumeration

Mapped a live multi-device home network using nmap, arp-scan and ping sweeps. Identified active hosts, open ports and running services. Lab hardware: MacBook Pro (management), iMac 12,1 Ubuntu lab server, ThinkPad Kali, Fritz!Box + TP-Link RE190 repeater discovered via MAC OUI analysis. Documented with privacy masking — OUI-only MAC addresses, anonymised hostnames.Live-Netzwerk mit mehreren Geräten mit nmap, arp-scan und Ping-Sweeps kartiert. Aktive Hosts, offene Ports und laufende Dienste identifiziert. Labor-Hardware: MacBook Pro (Management), iMac 12,1 Ubuntu-Lab-Server, ThinkPad Kali, Fritz!Box + TP-Link RE190 Repeater per MAC-OUI-Analyse entdeckt. Dokumentation mit Datenschutz-Maskierung — nur OUI-MAC-Adressen, anonymisierte Hostnamen.

nmaparp-scanping sweepifconfigHost EnumerationMAC Analysis

LAB_01

Wireshark Traffic AnalysisWireshark-Datenverkehrsanalyse

Captured and analysed live traffic across five protocol layers: ICMP (echo/reply, TTL), DNS (query/response, A records), HTTP (cleartext headers, response codes), ARP (who-has, is-at, gratuitous ARP), TLS/QUIC (handshake, certificate exchange). JA3 fingerprinting applied. Cross-lab finding: passive traffic identified unknown device as Amazon Fire Stick via UPnP + Spotify Connect signatures.Live-Datenverkehr auf fünf Protokollebenen erfasst und analysiert: ICMP (Echo/Reply, TTL), DNS (Anfrage/Antwort, A-Records), HTTP (Klartext-Header, Antwortcodes), ARP (who-has, is-at, gratuitous ARP), TLS/QUIC (Handshake, Zertifikataustausch). JA3-Fingerprinting angewendet. Lab-übergreifender Fund: Passiver Datenverkehr identifizierte unbekanntes Geraet als Amazon Fire Stick via UPnP + Spotify-Connect-Signaturen.

WiresharkICMPDNSHTTPARPTLSQUICJA3

LAB_02

Wi-Fi Security — WPA2 Assessment (Own Network)WLAN-Sicherheit — WPA2-Bewertung (Eigenes Netzwerk)

Controlled wireless assessment against own Fritz!Box. WPA2 4-way handshake capture, PMKID attack, deauthentication, MAC spoofing, offline dictionary attack with rockyou.txt. Key finding: strong passphrase not found in dictionary — positive security confirmation. BSSID filter applied throughout — no third-party networks captured.Kontrollierte WLAN-Sicherheitsprüfung am eigenen Fritz!Box-Router. WPA2-4-Wege-Handshake-Erfassung, PMKID-Angriff, Deauthentifizierung, MAC-Spoofing, Offline-Wörterbuch-Angriff mit rockyou.txt. Ergebnis: Starke Passphrase nicht im Wörterbuch gefunden — positive Sicherheitsbestätigung. BSSID-Filter durchgehend aktiv — keine fremden Netzwerke erfasst.

aircrack-nghcxdumptoolhashcatmacchangerWPA2PMKIDDeauth

LAB_03

Firewall & Network Segmentation

Host firewall rules designed and implemented using ufw and iptables. Zone-based segmentation across lab network, rules validated via nmap, brute force detection tested using Hydra against SSH. ufw log analysis confirmed block effectiveness. Cross-lab finding: brute force packet patterns from Wireshark lab confirmed in firewall logs.

ufwiptablesnmapHydraZone SegmentationLog Analysis
homelab_AEGIS 2 / 7 completed2 / 7 abgeschlossen → GitHub

CH_01

IDS Deployment & First Detection

Deployed Suricata IDS 7.0.3 + Wazuh SIEM 4.14.4 across a 4-node lab: MacBook Pro management (172.20.10.4), Wazuh OVA via VirtualBox SIEM server (172.20.10.9), Kali laptop attacker (172.20.10.8), aegis-sentinel Ubuntu VM sensor (172.20.10.6). Full pipeline: Suricata eve.json → Wazuh Agent → Manager → Dashboard. Two attack simulations validated: nmap -sS -A -T4 recon detected as ICMP anomaly (T1595), Hydra SSH brute force triggered rule 40112 at level-12 critical (T1078 + T1110). Full MITRE ATT&CK mapping confirmed on Dashboard.

Suricata 7.0.3Wazuh 4.14.4Hydranmapeve.jsonMITRE ATT&CKT1595T1110

CH_02

Active Defense & Detection Engineering

Transitioned aegis-sentinel from passive detection to active defense. Three independent layers deployed and tested against live Hydra SSH brute force: (1) Wazuh Active Response — firewall-drop on rule 5763, attacker IP auto-blocked via iptables DROP within seconds; (2) Custom Suricata rule sid:9000001 — lab-specific SSH brute force signature; (3) fail2ban integration — syslog → Wazuh Agent → Manager → Dashboard, rule 100100, T1110 confirmed. Core Ch.01 finding ("passive detection only") fully resolved.aegis-sentinel von passiver Erkennung auf aktive Verteidigung umgestellt. Drei unabhängige Schichten gegen live Hydra-SSH-Brute-Force getestet: (1) Wazuh Active Response — firewall-drop auf Regel 5763, Angreifer-IP per iptables DROP innerhalb von Sekunden gesperrt; (2) Benutzerdefinierte Suricata-Regel sid:9000001 — lab-spezifische SSH-Brute-Force-Signatur; (3) fail2ban-Integration — syslog → Wazuh Agent → Manager → Dashboard, Regel 100100, T1110 bestätigt. Kernbefund aus Ch.01 vollständig behoben.

Wazuh Active Responsefirewall-dropiptablesfail2banCustom Suricata RulesDetection EngineeringT1110

CH_03 → CH_07

Upcoming: PCAP Forensics · Exploitation · Lateral Movement · Rule Writing · Incident Response

Advanced SOC scenarios in progress — offline network forensics and timeline reconstruction, offensive simulation, lateral movement detection, custom detection rule engineering, and full incident response playbook execution.Fortgeschrittene SOC-Szenarien in Bearbeitung — Offline-Netzwerkforensik und Zeitachsenrekonstruktion, Angriffssimulation, Lateral-Movement-Erkennung, benutzerdefinierte Erkennungsregeln und vollständige Incident-Response-Playbook-Ausführung.

PCAP ForensicsExploitationLateral MovementRule WritingIncident Response

I am currently applying for entry-level SOC and Cybersecurity Analyst roles in Germany — on-site, hybrid or remote.
Feel free to contact me regarding opportunities, projects or professional exchange.

Ich bewerbe mich aktuell auf Einstiegspositionen als SOC Analyst oder Cybersecurity Analyst in Deutschland — vor Ort, hybrid oder remote.
Kontaktieren Sie mich gerne zu Stellenangeboten, Projekten oder zum fachlichen Austausch.

location Lutherstadt Wittenberg, GermanyLutherstadt Wittenberg, Deutschland