Skip to content
View 5ilent5pring's full-sized avatar

Block or report 5ilent5pring

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
5ilent5pring/README.md

Hi, I'm Sertaç Akman 👋

I am a cybersecurity analyst focused on cyber threat intelligence, takedown operations, OSINT automation, malicious infrastructure tracking, and threat data engineering.

My current work sits at the intersection of CTI operations, infrastructure analysis, and workflow automation. I work on validating phishing and malicious infrastructure, coordinating takedown actions, collecting evidence, and building automation pipelines that reduce repetitive analyst workload.

I am especially interested in building systems that help analysts turn noisy external data into structured, enriched, and actionable intelligence.


Current Focus

  • Threat data collection and enrichment pipelines
  • Passive OSINT collection for malicious infrastructure discovery
  • Phishing, scam, and rogue-domain takedown workflows
  • API security and shadow endpoint discovery
  • CTI automation with Python, Go, Bash, and n8n
  • Intelligence reporting with confidence labels, source boundaries, and structured analysis
  • Cyber, geopolitical, and hybrid-threat intelligence workflows

Selected Projects

SilentRoute

SilentRoute is a passive API reconnaissance CLI that discovers shadow and undocumented API endpoints without sending traffic to the target.

It gathers OSINT from certificate logs, archives, public code search, JavaScript assets, and security databases, then turns the findings into a confidence-ranked endpoint graph and Postman collection for API security testing.

Focus areas: API security, passive reconnaissance, OSINT, endpoint graphing, analyst-ready exports.


apimapper

apimapper is a Go-based security research CLI designed to orchestrate a reproducible API discovery pipeline across tools such as subfinder, httpx, ffuf, kiterunner, mitmproxy, and mitmproxy2swagger.

The goal is to make API reconnaissance reproducible, resumable, and exportable as normalized OpenAPI/Postman artifacts.

Focus areas: Go, API recon, automation, OpenAPI, Postman, security testing workflows.


geoCTI

geoCTI is an intelligence workflow that collects cyber, geopolitical, hybrid-threat, podcast, and YouTube sources, scores them for relevance, and generates structured analytical drafts using local LLMs.

It transforms raw RSS and news material into publishable analytical outputs with SAT-style reasoning, confidence labels, actor mapping, indicators, and deployment automation.

Focus areas: CTI automation, geopolitical intelligence, source scoring, local LLMs, structured reporting.


Podcast Pipeline

The Podcast Pipeline extends geoCTI by transforming published intelligence analysis into structured episode briefing packs.

Instead of generating scripts directly from blog posts, it preserves facts, hypotheses, CTI signals, and source boundaries so each episode can become more narrative while staying analytically grounded.

Focus areas: intelligence communication, briefing design, analytical structure, source discipline.


Technical Areas

Cyber Threat Intelligence & OSINT

  • Threat intelligence collection and enrichment
  • SOCMINT and dark web investigations
  • Malicious infrastructure tracking
  • Phishing and rogue-domain investigation
  • Cryptocurrency tracing basics
  • Evidence collection and takedown documentation

Security Engineering

  • API security testing
  • Web and mobile application security
  • Static and dynamic analysis
  • SSL pinning bypass research
  • Network traffic analysis
  • Red/blue team lab operations

Infrastructure & Automation

  • Python, Go, Bash
  • n8n workflow automation
  • Web scraping and structured data collection
  • Linux-based automation
  • Elasticsearch, Suricata, Velociraptor
  • PostgreSQL-backed reporting and audit trails

What I Am Building Toward

I am currently shaping my work around threat data infrastructure and analyst enablement.

My long-term goal is to build systems that support threat intelligence teams by:

  • collecting external threat data reliably,
  • enriching and normalizing indicators,
  • reducing false positives,
  • preserving source context,
  • exposing useful monitoring metrics,
  • and helping analysts move faster without sacrificing analytical quality.

Writing

I publish cyber threat intelligence, geopolitical intelligence, and automation-focused research at:

Blog: 5ilent5pring.org


Reading & Research Interests

Priority areas:

  • Cyber Threat Intelligence
  • Intelligence analysis methodology
  • Malware and infrastructure analysis
  • API security
  • Digital forensics and incident response
  • Geopolitics, irregular warfare, and hybrid threats

Contact


Profile views

Popular repositories Loading

  1. go-noob go-noob Public template

    Basic golang scripts for beginners and everybody

    Go

  2. go-defense go-defense Public

    go scripts for blue teams

    Go

  3. crAPI crAPI Public

    Forked from OWASP/crAPI

    completely ridiculous API (crAPI)

    Java

  4. MalwareDB MalwareDB Public

    Forked from gmh5225/MalwareDB

    Repository full of malware :D

  5. Mass-Hacker-Arsenal Mass-Hacker-Arsenal Public

    Forked from EgeBalci/Mass-Hacker-Arsenal

    Massive arsenal of hacker tools...

    Shell

  6. malware-ioc malware-ioc Public

    Forked from prodaft/malware-ioc

    This repository contains indicators of compromise (IOCs) of our various investigations.

    Python