~/whoami

Ahmet Payaslıoğlu

Senior Incident Responder (L3) · Threat Hunter · DFIR & Detection Engineering

I have 5+ years of hands-on experience in SOC operations, incident response, digital forensics and threat hunting. This page is a personal portfolio — a place to share my background and the consulting & training topics I can take on.

Ahmet Payaslıoğlu

Areas of Expertise

The full lifecycle of blue team operations and threat detection — collection, detection, response, hunting and reporting.

[01]

SOC & Incident Response

L1/L2/L3 incident response lifecycle: detection, triage, scoping, containment and escalation.

[02]

Digital Forensics (DFIR)

Deep forensic analysis across Windows, Linux, macOS and ESXi; root cause and compromise assessment.

[03]

Detection Engineering

Behavior-based detection rules with YARA, Sigma, OSQuery and SPL; SIEM and EDR rule development, MITRE ATT&CK mapping.

[04]

Threat Hunting

Hypothesis-driven proactive hunting; APT TTP modeling and telemetry analysis.

[05]

Malware Analysis

Static and dynamic malware analysis; family classification, IoC extraction, behavior reporting.

[06]

Purple Team

Bridge between red and blue teams; validating detection capability against real attack scenarios.

[07]

Threat Intelligence

Tracking CTI sources and translating them into actionable defensive measures.

[08]

Compromise Assessment

Deep scans of suspect environments; attack chain reconstruction and findings report.

Highlights

FBI / CISA

Published YARA Rule

A YARA detection rule I authored was referenced and published by the FBI and CISA in public threat advisories.

View CISA advisory →

NATO LOCKED SHIELDS

Locked Shields 2024 & 2025

Served as a Threat Hunter on the Turkish Armed Forces Blue Team across two consecutive editions (2024 and 2025) of the world's largest live-fire cyber defense exercise.

2025 →  ·  2024 →

5+ YEARS

Enterprise-Scale Security Experience

Currently working as an L3 Incident Response analyst in a large-scale enterprise banking environment. Previously worked at an international DFIR software company.