Skip to main content

Blog-0xahmetcan

SOC • BLUE TEAM • SECURITY RESEARCH

Detection.
Investigation.
Defense.

A technical cybersecurity knowledge base focused on Security Operations, network forensics, incident investigation, threat detection, detection engineering, SIEM analysis and hands-on Blue Team research.

SOC Analysis Network Forensics Detection Engineering Incident Response Threat Hunting SIEM
analyst@0xahmetcan
$ whoami
SOC / Blue Team Analyst

$ cat focus.txt
Network Forensics
Detection Engineering
Incident Investigation
Threat Hunting
SIEM Analysis

$ ls investigations/
AgentTesla/
Suricata-Detection/
PCAP-Analysis/
IOC-Research/

$ cat current-case.txt
Case: AgentTesla-style Infection
Status: TRUE POSITIVE
Protocol: FTP
Technique: T1048.003
Detection: Suricata

$ echo "Analyze. Detect. Defend."
Analyze. Detect. Defend.

SECURITY RESEARCH

Research & Practice Areas

Practical cybersecurity research focused on detection, investigation, network visibility and defensive security operations.

01

Network Forensics

PCAP investigation, protocol analysis, traffic reconstruction and identification of suspicious network behavior.

Wireshark TShark PCAP
02

Detection Engineering

Developing, validating and tuning network detection logic based on observed attacker behavior.

Suricata IDS Signatures
03

SOC & Alert Investigation

Alert triage, event correlation, IOC investigation and validation of suspicious security events.

SIEM Triage Correlation
04

Incident Response

Reconstructing attack activity, identifying affected assets and determining appropriate containment and response actions.

IR Timeline IOC
05

Threat Hunting

Investigating suspicious patterns, attacker infrastructure and behavioral indicators across available telemetry.

Hunting IOC Telemetry
06
>_

Security Labs

Hands-on cybersecurity practice through controlled labs, CTF environments and offensive techniques used to strengthen defensive understanding.

HTB TryHackMe PortSwigger
FEATURED INVESTIGATION

Latest Security Research

Hands-on investigations documenting the complete process from raw evidence to detection and incident assessment.

MORE RESEARCH

Technical Write-ups

Building and Tuning Suricata Detection Rules

Translating suspicious network behavior into practical IDS detection logic, testing signatures and reducing false-positive potential.

PCAP Investigation Methodology

A structured workflow for moving from high-level traffic triage to protocol analysis, stream reconstruction and incident validation.

From IDS Alert to Validated Incident

Understanding why an IDS alert should be treated as the beginning of an investigation rather than final proof of malicious activity.