Skip to content
View yatuk's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report yatuk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
yatuk/README.md

Fatih Serdar Çakmak

SOC Analyst Intern · Blue Team · Detection & Incident Response

Triaging alerts, chasing true positives · Building open-source AI security tooling · Computer Engineering @ ITU, Class of 2027

linkedin portfolio location

~/whoami

name:         Fatih Serdar Çakmak
role:         SOC Analyst Intern  ·  Computer Engineering Student
focus:        [ SOC Operations, Alert Triage, Incident Response, Detection ]
currently:    SOC Intern @ Fibabanka (BDDK-regulated banking SOC)
building:     [ Tamga - LLM security proxy, SOC n8n playbooks, MCPRadar - MCP scanner ]
education:    B.Sc. Computer Engineering @ ITU (expected 2027)

I'm a Computer Engineering student who spends most of his time inside a SOC. Day to day that means triaging alerts, killing false positives, and tweaking SOAR playbooks so the signal surfaces faster. Mostly I'm learning what incidents actually look like before they reach an analyst, and how much of a working SOC quietly runs on automation.

Off the clock I build security tooling for AI systems: a proxy that sits in front of LLM traffic, a scanner for MCP servers, and n8n playbooks that handle the repetitive half of SOC work. Everything is open source and linked below.

~/experience

[ Mar 2026 -> Present ]  Fibabanka          ·  Cybersecurity Operations (SOC) Intern
                         └─ SIEM/EDR alert triage · CTI review · incident docs · AI-assisted triage

[ Jul 2025 -> Mar 2026 ]  Doğuş Teknoloji   ·  Cybersecurity and Incident Response Intern
                         └─ SIEM/SOAR/EDR/NDR triage · phishing playbooks · L1 IR · AD and log monitoring

~/tech-stack

SIEM SOAR EDR / NDR MITRE ATT&CK Wireshark n8n Python Go C C++ SQL Docker FastAPI Next.js PostgreSQL Linux Active Directory Git BDDK ISO 27001

~/projects

Project What it does Stack
stars 🛡️ Tamga Self-hosted proxy that redacts PII, blocks leaked secrets, and catches prompt injection before it hits your LLM provider. Sub-millisecond scanning, KVKK/BDDK/GDPR/PCI-DSS mappings. Go Python Next.js
stars ⚙️ SOC n8n Workflows Ten import-ready n8n playbooks for alert triage, phishing analysis, IOC enrichment, and CVE watch. No secrets baked in. n8n JSON
stars 🎓 İTÜ MCP MCP server that connects İTÜ's Ninova and OBS to Claude, Cursor, and other AI clients. Course files, grades, deadlines, transcript, all queryable in plain language. Python FastMCP
stars 🗂️ İTÜ Archive OBS only keeps the current term online, so this pulls the course schedule and academic calendar daily and keeps it. 27 terms, 64k+ section records since 2016. Go JSON/CSV
stars 🎯 SOC Simulation A simulated SOC shift: 127 alerts, 126 false positives, 1 real threat, 6 coffees. SIEM/SOAR/EDR triage with MITRE ATT&CK mapping. Live demo. Python
stars 📡 MCPRadar Scans MCP servers for tool poisoning, prompt injection, and supply-chain rug pulls before your agent runs them. SARIF output, public leaderboard. Python

~/github-stats

stats top langs
contribution snake

Pinned Loading

  1. tamga tamga Public

    Self-hosted LLM security proxy. PII redaction, prompt injection defense, KVKK/GDPR/PCI-DSS compliance. Sub-millisecond latency

    Go 35 1

  2. soc-n8n-workflows soc-n8n-workflows Public

    🛡️ 10 production-shaped SOC automation playbooks for n8n LLM-assisted alert triage, phishing analysis, IOC enrichment, human-approved containment, CVE watch & SOC reporting. Import-ready JSON, zero…

    JavaScript 8

  3. itu-archive itu-archive Public

    İTÜ ders programı ve akademik takvim arşivi. OBS yalnızca aktif dönemi yayınlıyor; bu depo veriyi her gün çekip kalıcılaştırıyor. 2016'dan bugüne 27 dönem, 64.309 şube kaydı. JSON + CSV, Go ile yaz…

    JavaScript 2 1

  4. itu-mcp itu-mcp Public

    İTÜ Ninova + OBS’yi Claude, Cursor ve Codex’e bağlayan yerel MCP sunucusu. Ders, ödev, not, transkript ve daha fazlası.

    Python 8 1

  5. mcpradar mcpradar Public

    Security scanner for Model Context Protocol servers. Catch tool poisoning, prompt injection, and supply-chain attacks before your AI agent runs them.

    Python 3

  6. soc-simulation soc-simulation Public

    SOC Analyst portfolyo projesi | 127 alert, 126 false positive, 1 gerçek tehdit, 6 kahve | SIEM/SOAR/EDR simülasyonu

    Python 3