Türkiye'nin Açık Kaynak
Tehdit İstihbarat Platformu
Turkey's Open Source
Threat Intelligence Platform
SiberKapan, Türkiye'e yönelik siber tehditleri izlemek ve paylaşmak için geliştirilmiş açık kaynak bir tehdit istihbarat platformudur. Kaynak kodu ve dokümantasyon GitHub'ta mevcuttur. Global kapsam iddiasında bulunmuyoruz; Türkiye'ye özgü saldırı örüntülerini yerel olarak gözlemleyerek FortiGate başta olmak üzere güvenlik sistemlerine entegre ediyoruz. SiberKapan is an open-source threat intelligence platform developed to monitor and share cyber threats targeting Turkey. We do not claim global coverage; instead, we observe Turkey-specific attack patterns locally and integrate them into security systems, primarily FortiGate.
Cumhurbaşkanlığı Siber Güvenlik Kümesi Üyesi Member of the Presidential Cybersecurity Cluster
SiberKapan, Türkiye Cumhurbaşkanlığı Dijital Dönüşüm Ofisi bünyesindeki Siber Güvenlik Kümesi'ne kabul edilmiştir. Bu üyelik, platformun Türkiye siber güvenlik ekosistemindeki kurumsal konumunu ve güvenilirliğini teyit etmektedir. SiberKapan has been accepted into the Cybersecurity Cluster under Turkey's Presidential Digital Transformation Office. This membership confirms the platform's institutional standing and credibility within Turkey's cybersecurity ecosystem.
Siber tehditler giderek daha karmaşık ve hedefli hale gelirken, küçük ve orta ölçekli kurumlar ticari tehdit istihbarat servislerine erişmekte zorlanmaktadır. SiberKapan, bu boşluğu doldurmak için tasarlanmıştır. As cyber threats grow increasingly complex and targeted, small and medium-sized organizations struggle to access commercial threat intelligence services. SiberKapan was built to fill this gap.
Platformumuz; honeypot ağlarından toplanan gerçek saldırgan verilerini, global açık kaynak feed'lerle birleştirerek FortiGate başta olmak üzere tüm güvenlik sistemleriyle doğrudan entegre olabilen, ücretsiz ve erişilebilir bir tehdit istihbaratı sunmaktadır. Our platform combines real attacker data collected from honeypot networks with global open-source feeds, delivering free and accessible threat intelligence that integrates directly with FortiGate and other security systems.
Temel amacımız, Türkiye'deki kurum ve kuruluşların siber altyapılarını daha etkin koruyabilmesi için gerekli tehdit verilerini açık, güvenilir ve sürekli güncel biçimde sağlamaktır. Our core goal is to provide the threat data that organizations across Turkey need to better protect their digital infrastructure — openly, reliably, and continuously updated.
Siber güvenlik, gizlilik üzerine değil güven üzerine inşa edilmelidir. SiberKapan'ın tehdit verilerini nasıl topladığı, nasıl doğruladığı ve nasıl yayınladığı tamamen şeffaf biçimde görülebilir olmalıdır. Bu nedenle platform sıfırdan açık kaynak felsefesiyle tasarlandı. Cybersecurity should be built on trust, not obscurity. How SiberKapan collects, validates, and publishes threat data should be fully transparent. That is why the platform was designed from the ground up with an open-source philosophy.
Ticari tehdit istihbarat servisleri yıllık binlerce dolar lisans ücreti talep ederken, küçük ve orta ölçekli kurumlar bu verilere erişememektedir. SiberKapan, aynı kalitedeki tehdit verisini herkesin kullanabileceği bir formatta sunarak bu eşitsizliği ortadan kaldırmayı hedeflemektedir. While commercial threat intelligence services charge thousands of dollars in annual licensing fees, smaller organizations are left without access. SiberKapan aims to eliminate this inequality by delivering the same quality threat data in a format anyone can use.
Açık kaynak model aynı zamanda daha hızlı gelişim anlamına gelir. Topluluk üyeleri hata bildirebilir, yeni entegrasyonlar önerebilir ve feed kalitesini birlikte iyileştirebilir. The open-source model also means faster development. Community members can report issues, propose new integrations, and collectively improve feed quality.
SiberKapan'ı diğer tehdit istihbarat platformlarından ayıran en önemli özellik, verinin büyük çoğunluğunun sahadan gelmesidir. FortiGate kullanan güvenlik profesyonelleri, Automation Stitch aracılığıyla kendi ağlarında tespit ettikleri saldırgan IP'leri doğrudan platforma iletebilmektedir. What sets SiberKapan apart from other threat intelligence platforms is that the majority of its data comes directly from the field. Security professionals using FortiGate can submit attacker IPs detected in their own networks directly to the platform via Automation Stitch.
Bu model sayesinde Türkiye'deki bir kuruma saldıran IP adresi, SiberKapan'ın doğrulama ve skorlama motorundan geçerek dakikalar içinde platformu kullanan tüm kurumların blocklist'ine yansıyabilmektedir. Through this model, an IP address attacking an organization in Turkey passes through SiberKapan's validation and scoring engine and can reach the blocklist of all organizations using the platform within minutes.
Platforma katkıda bulunmak için kayıt olmanız yeterlidir. Doğrulanmış üyeler API key alarak webhook entegrasyonu kurabilir, honeypot verisi paylaşabilir ve toplu IP bildirimi yapabilir. All you need to contribute is to register. Verified members receive an API key to set up webhook integrations, share honeypot data, and submit bulk IP reports.
Proje Fikrinin DoğuşuProject Inception
FortiGate yönetim deneyimlerinden edinilen gözlemler doğrultusunda, Türkiye'ye özgü bir tehdit istihbarat platformu ihtiyacı tespit edildi.Based on observations gathered through FortiGate management experience, the need for a Turkey-specific threat intelligence platform was identified.
Cumhurbaşkanlığı Siber Güvenlik Kümesi ÜyeliğiPresidential Cybersecurity Cluster Membership
SiberKapan, Türkiye Cumhurbaşkanlığı Dijital Dönüşüm Ofisi Siber Güvenlik Kümesi'ne kabul edildi.SiberKapan was accepted into the Cybersecurity Cluster of Turkey's Presidential Digital Transformation Office.
Platform v2 Yayına GirdiPlatform v2 Launched
Yeniden yazılan platform; FortiGate webhook entegrasyonu, BGP zenginleştirme, RSS feed ve canlı IOC listesiyle yayına alındı. 46.000+ IP kaydı ile hizmete girdi.The rebuilt platform launched with FortiGate webhook integration, BGP enrichment, RSS feeds, and live IOC lists — starting with 46,000+ IP records.
Honeypot Ağı EntegrasyonuHoneypot Network Integration
HoneypotKapan, SSH, Telnet, RDP ve FTP başta olmak üzere 10 servisi taklit eden honeypot sensörleriyle devreye alındı. Gerçek zamanlı yakalanan saldırgan verisi otomatik olarak platforma akmaktadır.HoneypotKapan went live with honeypot sensors emulating 10 services including SSH, Telnet, RDP, and FTP. Attacker data captured in real time flows automatically into the platform.
AbuseIPDB Doğrulanmış Webmaster StatüsüAbuseIPDB Verified Webmaster Status
SiberKapan, AbuseIPDB tarafından doğrulanmış webmaster statüsü kazandı ve resmi Contributor rozetine kavuştu. Platform artık AbuseIPDB ile iki yönlü veri akışı (otomatik raporlama + karşılaştırmalı doğrulama) yürütmektedir.SiberKapan achieved verified webmaster status on AbuseIPDB and earned the official Contributor badge. The platform now runs a two-way data flow with AbuseIPDB — automated reporting plus comparative validation.
Nginx Watcher Agent'ı Yayına GirdiNginx Watcher Agent Launched
Açık kaynak Nginx Watcher agent'ı devreye alındı — nginx access log'larından 404/auth/rate flood, exploit path imzaları ve scanner User-Agent'larını tespit ederek SiberKapan'a otomatik bildiriyor. Tek komutla kurulabilen, sıfır harici bağımlılıklı bir Python servisi.The open-source Nginx Watcher agent went live — detecting 404/auth/rate floods, exploit path signatures, and scanner User-Agents from nginx access logs and reporting automatically to SiberKapan. A zero-dependency Python service installable with a single command.
MISP Resmi Varsayılan Feed Listesine Kabul EdildiAccepted into MISP's Official Default Feed List
SiberKapan'ın MISP feed entegrasyonu, MISP projesinin kurucusu Andras Iklody tarafından onaylanarak resmi varsayılan feed listesine (defaults.json) eklendi. Bu, platformun aldığı en güçlü üçüncü taraf doğrulamasıdır.SiberKapan's MISP feed integration was approved by MISP founder Andras Iklody and added to the project's official default feed list (defaults.json) — the strongest third-party validation the platform has received to date.
Açık Kaynak Topluluk Listelerine KatılımJoining Open-Source Community Lists
Global awesome-threat-intelligence kaynak listesine eklenme başvurusu değerlendirme sürecindedir.Application for inclusion in the global awesome-threat-intelligence resource list is under review.
Oktay A.
15 yılı aşkın ağ ve sistem yönetimi deneyimiyle özellikle FortiGate platformunda uzmanlaşmış siber güvenlik profesyoneli. ADEA Sistem'in kurucusu, SiberKapan ve Alertalk platformlarının mimarı. Cumhurbaşkanlığı Siber Güvenlik Kümesi üyesi. A cybersecurity professional with over 15 years of network and system administration experience, specializing in the FortiGate platform. Founder of ADEA Sistem, architect of SiberKapan and Alertalk. Member of Turkey's Presidential Cybersecurity Cluster.