~/whoami

Ahmet Payaslıoğlu

Senior Incident Responder (L3) · Threat Hunter · DFIR & Detection Engineering

I have 5+ years of hands-on experience across SOC operations, incident response, digital forensics, threat detection engineering, cyber threat intelligence and malware analysis. Including the internships, projects and research from my student years, my total exposure to the field exceeds 8 years. This page is a personal portfolio — a place to share my professional background and the consulting & training topics I can take on.

Ahmet Payaslıoğlu

Areas of Expertise

The full lifecycle of blue team operations — collection, detection, response, hunting and reporting.

[01]

SOC & Incident Response

L1/L2/L3 incident response lifecycle: detection, triage, scoping, containment and escalation.

[02]

Digital Forensics (DFIR)

Deep forensic analysis across Windows, Linux, macOS and ESXi; root cause and compromise assessment.

[03]

Detection Engineering

Behavior-based detection rules with YARA, Sigma and OSQuery; SIEM and EDR rule development, MITRE ATT&CK mapping.

[04]

Threat Hunting

Hypothesis-driven proactive hunting; APT TTP modeling and telemetry analysis.

[05]

Malware Analysis

Static and dynamic malware analysis; family classification, IoC extraction, behavior reporting.

[06]

Purple Team

Bridge between red and blue teams; validating detection capability against real attack scenarios.

[07]

Threat Intelligence

Tracking CTI sources and translating them into actionable defensive measures.

[08]

Compromise Assessment

Deep scans of suspect environments; attack chain reconstruction and findings report.

Highlights

FBI / CISA

Published YARA Rule

A YARA detection rule I authored was referenced and published by the FBI and CISA in public threat advisories.

View CISA advisory →

NATO LOCKED SHIELDS

Locked Shields 2024 & 2025

Served as a Threat Hunter on the Turkish Armed Forces Blue Team across two consecutive editions (2024 and 2025) of the world's largest live-fire cyber defense exercise.

2025 →  ·  2024 →

5+ YEARS

Enterprise-Scale Security Experience

Currently working as an L3 Incident Response analyst in a large-scale enterprise banking environment. Previously worked at an international DFIR software company.