Skip to content
View 00gxd14g's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report 00gxd14g

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
00gxd14g/README.md

Oğuz ALBAŞ

Threat Hunting · Detection Engineering · Cyber Threat Intelligence · OT/ICS Security

Ankara, Türkiye · GitHub · X

About

I am a security engineer focused on building practical defensive security systems, detection content, and automation. My work combines blue-team operations, controlled adversary emulation, SIEM engineering, cyber threat intelligence, and secure software development.

I am particularly interested in turning security telemetry and threat intelligence into repeatable detection, investigation, and response workflows.

Focus Areas

  • Threat hunting and detection engineering: MITRE ATT&CK, Sigma, Sysmon, Windows telemetry, detection validation
  • SIEM and security automation: Trellix/McAfee ESM, IBM QRadar, TheHive, rule lifecycle and alarm workflows
  • Cyber threat intelligence: MISP, STIX/TAXII, IOC enrichment and intelligence pipelines
  • OT/ICS security: Modbus-aware discovery, industrial asset visibility and defensive validation
  • Security product engineering: Python services, TypeScript interfaces, PowerShell and Shell automation
  • Adversary emulation: MITRE CALDERA and Atomic Red Team in authorized, controlled environments

Selected Public Projects

Project Description Stack
ics_finder Asynchronous Modbus/ICS discovery with MISP warning-list exclusions, protocol validation and structured output. Python
Windows-ADV-MITRE Windows security auditing, event generation and MITRE ATT&CK mapping for detection validation. PowerShell
cti-misp-stix-pipeline MISP-to-STIX/TAXII pipeline with STIX 1.x/2.1 support and IOC relationship handling. Python
Trellix-SIEM-RACC SIEM rule and alarm analysis tooling designed to reduce manual XML workflows and support multi-tenant operations. Python
misp-extractor MISP attribute extraction and export utility for IP addresses, URLs and hashes. Python
QRadar_Log_Forwarding Linux log-forwarding automation and validation for IBM QRadar environments. Shell
MacRecovery SwiftUI backup utility built on rsync with live logs and cancellation support. Swift

Open Source Contributions

Repository Contribution
kodzamani/DevAtlas Merged WSL2 project discovery and Explorer integration
MISP/misp-website Added misp-extractor to the MISP tools directory
coollabsio/coolify Contributions covering DNS and hostname management and IPv6 gateway handling

Technologies

Security and platforms

MITRE ATT&CK · Sigma · Sysmon · MISP · STIX/TAXII · QRadar · Trellix ESM · TheHive · CALDERA

Engineering

Python · TypeScript · PowerShell · Shell · Swift · SQL · Docker · GitHub Actions

Collaboration

I am interested in open-source work involving detection engineering, threat intelligence, SIEM automation, defensive security tooling, and OT/ICS visibility.

Security research and testing referenced here is intended for authorized and controlled environments.

Pinned Loading

  1. misp-extractor misp-extractor Public

    Extracts selected MISP attributes, including IP addresses, URLs, and hashes, into reusable output files.

    Python 16 2

  2. robots.txt_scanner robots.txt_scanner Public

    Python crawler for discovering and reviewing robots.txt entries across web targets.

    Python 1 1

  3. atomic-red-team-pandas atomic-red-team-pandas Public

    Parses Atomic Red Team Windows techniques into a Pandas dataset for analysis and detection research.

    Python 1