batuhan@security:~$ whoami
Batuhan Tekin — Entry-Level SOC Analyst
batuhan@security:~$ cat core_skills.txt
SIEM Investigation | Splunk | Elastic Security
Threat Hunting | Sigma Rules | MITRE ATT&CK
Phishing Analysis | Incident Response
Windows | Active Directory | Sysmon
batuhan@security:~$ echo $MISSION
Turn security telemetry into clear and actionable findings.
batuhan@security:~$ ./status
Investigating. Detecting. Documenting. Improving.Junior SOC Analyst candidate focused on blue team operations, SIEM investigations, threat hunting, phishing analysis, detection engineering, and incident response.
I use this profile to document my hands-on training, investigation process, and the lessons I learn while working through security labs. My current goal is to build the practical skills required for an entry-level SOC Analyst role.
- SIEM investigation with Splunk and Elastic Security
- Detection engineering and Sigma rules
- Incident response workflows
- Phishing email analysis and IOC enrichment
- Windows and Active Directory security monitoring
Hands-on investigations covering multi-stage attacks, Active Directory lateral movement, PsExec, RDP, credential access, DCSync, and ransomware activity using Splunk and Elastic Security.
My detection engineering learning path, including detection fundamentals, threat intelligence, Sigma rules, IOC-based hunting, Aurora EDR, and SOAR workflows.
Phishing investigations covering email headers, SPF, DKIM, DMARC, IOC collection, OSINT enrichment, MITRE ATT&CK mapping, and phishing-to-ransomware analysis.
An incident response project covering preparation, identification, analysis, containment, eradication, recovery, evidence handling, and lessons learned. This project is currently in progress.
Notes and practical studies on firewall technologies, network traffic filtering, evasion techniques, and firewall telemetry from a SOC analyst perspective.
- Splunk and SPL
- Elastic Security and Kibana
- Sigma
- Wireshark
- Burp Suite
- Linux
- Windows Event Logs
- MITRE ATT&CK
- Threat hunting
- Incident response
- Phishing and email analysis
- Log and network traffic analysis
Completed training paths and hands-on labs include:
- TryHackMe Pre Security
- TryHackMe SOC Level 1
- TryHackMe AI Security
- TryHackMe Jr Penetration Tester
- LetsDefend SOC labs
- TryHackMe Cyber Security 101
Currently working toward:
- CompTIA Security+
- TryHackMe SOC Level 2