Skip to content
View yatuk's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report yatuk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
yatuk/README.md

Fatih Serdar Çakmak

SOC Analyst Intern · Blue Team · Detection & Incident Response

typing

linkedin portfolio location

~/whoami

name:         Fatih Serdar Çakmak
role:         SOC Analyst Intern  ·  Computer Engineering Student
focus:        [ SOC Operations, Alert Triage, Incident Response, Detection ]
currently:    SOC Intern @ Fibabanka (BDDK-regulated banking SOC)
building:     [ Tamga - LLM security proxy, SOC n8n playbooks, MCPRadar - MCP scanner ]
education:    B.Sc. Computer Engineering @ ITU (expected 2027)
learning:     Detection-as-Code · AI/LLM Security · Threat Hunting
philosophy:   "Most alerts are noise. The interesting part is the few that aren't."
ask_me_about: [ SIEM, MITRE ATTACK, SOAR, Blue Team, LLM Security, Go, Python ]

I'm a Computer Engineering student who spends most of his time inside a SOC. Day to day that means triaging alerts, killing false positives, and tweaking SOAR playbooks so the signal surfaces faster. Mostly I'm learning what incidents actually look like before they reach an analyst, and how much of a working SOC quietly runs on automation.

Off the clock I build security tooling for AI systems: a proxy that sits in front of LLM traffic, a scanner for MCP servers, and n8n playbooks that handle the repetitive half of SOC work. Everything is open source and linked below.

~/experience

[ Mar 2026 -> Present ]  Fibabanka          ·  Cybersecurity Operations (SOC) Intern
                         └─ SIEM/EDR alert triage · CTI review · incident docs · AI-assisted triage

[ Jul 2025 -> Mar 2026 ]  Doğuş Teknoloji   ·  Cybersecurity and Incident Response Intern
                         └─ SIEM/SOAR/EDR/NDR triage · phishing playbooks · L1 IR · AD and log monitoring

~/tech-stack

🛡️ Security · SOC · Detection

SIEM Cortex XSOAR EDR / NDR MITRE ATT&CK Wireshark n8n

💻 Languages

Python Go C C++ SQL

🧰 Infrastructure and Tooling

Docker FastAPI Next.js PostgreSQL Linux Active Directory Git

📋 Compliance and Frameworks

BDDK ISO 27001

~/projects

Project What it does Stack
🛡️ Tamga ⭐26 Self-hosted proxy that redacts PII, blocks leaked secrets, and catches prompt injection before it hits your LLM provider. Sub-millisecond scanning, KVKK/BDDK/GDPR/PCI-DSS mappings. Go Python Next.js
⚙️ SOC n8n Workflows ⭐8 Ten import-ready n8n playbooks for alert triage, phishing analysis, IOC enrichment, and CVE watch. No secrets baked in. n8n JSON
🎓 İTÜ MCP ⭐6 MCP server that connects İTÜ's Ninova and OBS to Claude, Cursor, and other AI clients. Course files, grades, deadlines, transcript, all queryable in plain language. Python FastMCP
🗂️ İTÜ Archive ⭐1 OBS only keeps the current term online, so this pulls the course schedule and academic calendar daily and keeps it. 27 terms, 64k+ section records since 2016. Go JSON/CSV
🎯 SOC Simulation ⭐3 A simulated SOC shift: 127 alerts, 126 false positives, 1 real threat, 6 coffees. SIEM/SOAR/EDR triage with MITRE ATT&CK mapping. Live demo. Python
📡 MCPRadar ⭐1 Scans MCP servers for tool poisoning, prompt injection, and supply-chain rug pulls before your agent runs them. SARIF output, public leaderboard. Python

~/github-stats

stats top langs
contribution snake

"Security is a process, not a product." · Bruce Schneier

Pinned Loading

  1. tamga tamga Public

    Self-hosted LLM security proxy. PII redaction, prompt injection defense, KVKK/GDPR/PCI-DSS compliance. Sub-millisecond latency

    Go 33 1

  2. soc-n8n-workflows soc-n8n-workflows Public

    🛡️ 10 production-shaped SOC automation playbooks for n8n LLM-assisted alert triage, phishing analysis, IOC enrichment, human-approved containment, CVE watch & SOC reporting. Import-ready JSON, zero…

    JavaScript 8

  3. mcpradar mcpradar Public

    Security scanner for Model Context Protocol servers. Catch tool poisoning, prompt injection, and supply-chain attacks before your AI agent runs them.

    Python 2

  4. itu-mcp itu-mcp Public

    İTÜ Ninova + OBS’yi Claude, Cursor ve Codex’e bağlayan yerel MCP sunucusu. Ders, ödev, not, transkript ve daha fazlası.

    Python 6

  5. soc-simulation soc-simulation Public

    SOC Analyst portfolyo projesi | 127 alert, 126 false positive, 1 gerçek tehdit, 6 kahve | SIEM/SOAR/EDR simülasyonu

    Python 3

  6. kick-bulk-mod kick-bulk-mod Public

    Bulk ban/timeout/unban Kick chat users via a simple web UI, wrapping Kick's single-user moderation API.

    TypeScript 1