I am a cybersecurity analyst focused on cyber threat intelligence, takedown operations, OSINT automation, malicious infrastructure tracking, and threat data engineering.
My current work sits at the intersection of CTI operations, infrastructure analysis, and workflow automation. I work on validating phishing and malicious infrastructure, coordinating takedown actions, collecting evidence, and building automation pipelines that reduce repetitive analyst workload.
I am especially interested in building systems that help analysts turn noisy external data into structured, enriched, and actionable intelligence.
- Threat data collection and enrichment pipelines
- Passive OSINT collection for malicious infrastructure discovery
- Phishing, scam, and rogue-domain takedown workflows
- API security and shadow endpoint discovery
- CTI automation with Python, Go, Bash, and n8n
- Intelligence reporting with confidence labels, source boundaries, and structured analysis
- Cyber, geopolitical, and hybrid-threat intelligence workflows
SilentRoute is a passive API reconnaissance CLI that discovers shadow and undocumented API endpoints without sending traffic to the target.
It gathers OSINT from certificate logs, archives, public code search, JavaScript assets, and security databases, then turns the findings into a confidence-ranked endpoint graph and Postman collection for API security testing.
Focus areas: API security, passive reconnaissance, OSINT, endpoint graphing, analyst-ready exports.
apimapper is a Go-based security research CLI designed to orchestrate a reproducible API discovery pipeline across tools such as subfinder, httpx, ffuf, kiterunner, mitmproxy, and mitmproxy2swagger.
The goal is to make API reconnaissance reproducible, resumable, and exportable as normalized OpenAPI/Postman artifacts.
Focus areas: Go, API recon, automation, OpenAPI, Postman, security testing workflows.
geoCTI is an intelligence workflow that collects cyber, geopolitical, hybrid-threat, podcast, and YouTube sources, scores them for relevance, and generates structured analytical drafts using local LLMs.
It transforms raw RSS and news material into publishable analytical outputs with SAT-style reasoning, confidence labels, actor mapping, indicators, and deployment automation.
Focus areas: CTI automation, geopolitical intelligence, source scoring, local LLMs, structured reporting.
The Podcast Pipeline extends geoCTI by transforming published intelligence analysis into structured episode briefing packs.
Instead of generating scripts directly from blog posts, it preserves facts, hypotheses, CTI signals, and source boundaries so each episode can become more narrative while staying analytically grounded.
Focus areas: intelligence communication, briefing design, analytical structure, source discipline.
- Threat intelligence collection and enrichment
- SOCMINT and dark web investigations
- Malicious infrastructure tracking
- Phishing and rogue-domain investigation
- Cryptocurrency tracing basics
- Evidence collection and takedown documentation
- API security testing
- Web and mobile application security
- Static and dynamic analysis
- SSL pinning bypass research
- Network traffic analysis
- Red/blue team lab operations
- Python, Go, Bash
- n8n workflow automation
- Web scraping and structured data collection
- Linux-based automation
- Elasticsearch, Suricata, Velociraptor
- PostgreSQL-backed reporting and audit trails
I am currently shaping my work around threat data infrastructure and analyst enablement.
My long-term goal is to build systems that support threat intelligence teams by:
- collecting external threat data reliably,
- enriching and normalizing indicators,
- reducing false positives,
- preserving source context,
- exposing useful monitoring metrics,
- and helping analysts move faster without sacrificing analytical quality.
I publish cyber threat intelligence, geopolitical intelligence, and automation-focused research at:
Blog: 5ilent5pring.org
Priority areas:
- Cyber Threat Intelligence
- Intelligence analysis methodology
- Malware and infrastructure analysis
- API security
- Digital forensics and incident response
- Geopolitics, irregular warfare, and hybrid threats
- Blog: 5ilent5pring.org
- GitHub: github.com/5ilent5pring
- X/Twitter: @cybercaretta
- LinkedIn: sertac-akman